General Info

URL

https://github.com/ytisf/theZoo/blob/master/malware/Binaries/Ransomware.TeslaCrypt/Ransomware.TeslaCrypt.zip?raw=true

Full analysis
https://app.any.run/tasks/97ce8aa6-5b9d-4d3b-9972-47534fc545b0
Verdict
Malicious activity
Analysis date
14/01/2022, 21:31:49
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

evasion

trojan

ransomware

teslacrypt

stealer

Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 11.0.9600.19596 KB4534251
  • Adobe Acrobat Reader DC (20.013.20064)
  • Adobe Flash Player 32 ActiveX (32.0.0.453)
  • Adobe Flash Player 32 NPAPI (32.0.0.453)
  • Adobe Flash Player 32 PPAPI (32.0.0.453)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.74)
  • FileZilla Client 3.51.0 (3.51.0)
  • Google Chrome (86.0.4240.198)
  • Google Update Helper (1.3.36.31)
  • Java 8 Update 271 (8.0.2710.9)
  • Java Auto Updater (2.8.271.9)
  • Microsoft .NET Framework 4.5.2 (4.5.51209)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 83.0 (x86 en-US) (83.0)
  • Mozilla Maintenance Service (83.0.0.7621)
  • Notepad++ (32-bit x86) (7.9.1)
  • Opera 12.15 (12.15.1748)
  • QGA (2.14.33)
  • Skype version 8.29 (8.29)
  • VLC media player (3.0.11)
  • WinRAR 5.91 (32-bit) (5.91.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Hyphenation Parent Package English
  • IE Spelling Parent Package English
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • InternetExplorer Package TopLevel
  • KB2479943
  • KB2491683
  • KB2506212
  • KB2506928
  • KB2532531
  • KB2533552
  • KB2533623
  • KB2534111
  • KB2545698
  • KB2547666
  • KB2552343
  • KB2560656
  • KB2564958
  • KB2574819
  • KB2579686
  • KB2585542
  • KB2604115
  • KB2620704
  • KB2621440
  • KB2631813
  • KB2639308
  • KB2640148
  • KB2653956
  • KB2654428
  • KB2656356
  • KB2660075
  • KB2667402
  • KB2676562
  • KB2685811
  • KB2685813
  • KB2685939
  • KB2690533
  • KB2698365
  • KB2705219
  • KB2719857
  • KB2726535
  • KB2727528
  • KB2729094
  • KB2729452
  • KB2731771
  • KB2732059
  • KB2736422
  • KB2742599
  • KB2750841
  • KB2758857
  • KB2761217
  • KB2770660
  • KB2773072
  • KB2786081
  • KB2789645
  • KB2799926
  • KB2800095
  • KB2807986
  • KB2808679
  • KB2813347
  • KB2813430
  • KB2820331
  • KB2834140
  • KB2836942
  • KB2836943
  • KB2840631
  • KB2843630
  • KB2847927
  • KB2852386
  • KB2853952
  • KB2857650
  • KB2861698
  • KB2862152
  • KB2862330
  • KB2862335
  • KB2864202
  • KB2868038
  • KB2871997
  • KB2872035
  • KB2884256
  • KB2891804
  • KB2893294
  • KB2893519
  • KB2894844
  • KB2900986
  • KB2908783
  • KB2911501
  • KB2912390
  • KB2918077
  • KB2919469
  • KB2923545
  • KB2931356
  • KB2937610
  • KB2943357
  • KB2952664
  • KB2968294
  • KB2970228
  • KB2972100
  • KB2972211
  • KB2973112
  • KB2973201
  • KB2977292
  • KB2978120
  • KB2978742
  • KB2984972
  • KB2984976
  • KB2984976 SP1
  • KB2985461
  • KB2991963
  • KB2992611
  • KB2999226
  • KB3004375
  • KB3006121
  • KB3006137
  • KB3010788
  • KB3011780
  • KB3013531
  • KB3019978
  • KB3020370
  • KB3020388
  • KB3021674
  • KB3021917
  • KB3022777
  • KB3023215
  • KB3030377
  • KB3031432
  • KB3035126
  • KB3037574
  • KB3042058
  • KB3045685
  • KB3046017
  • KB3046269
  • KB3054476
  • KB3055642
  • KB3059317
  • KB3060716
  • KB3061518
  • KB3067903
  • KB3068708
  • KB3071756
  • KB3072305
  • KB3074543
  • KB3075226
  • KB3078667
  • KB3080149
  • KB3086255
  • KB3092601
  • KB3093513
  • KB3097989
  • KB3101722
  • KB3102429
  • KB3102810
  • KB3107998
  • KB3108371
  • KB3108664
  • KB3109103
  • KB3109560
  • KB3110329
  • KB3115858
  • KB3118401
  • KB3122648
  • KB3123479
  • KB3126587
  • KB3127220
  • KB3133977
  • KB3137061
  • KB3138378
  • KB3138612
  • KB3138910
  • KB3139398
  • KB3139914
  • KB3140245
  • KB3147071
  • KB3150220
  • KB3150513
  • KB3155178
  • KB3156016
  • KB3159398
  • KB3161102
  • KB3161949
  • KB3170735
  • KB3172605
  • KB3179573
  • KB3184143
  • KB3185319
  • KB4019990
  • KB4040980
  • KB4474419
  • KB4490628
  • KB4524752
  • KB4532945
  • KB4536952
  • KB4567409
  • KB958488
  • KB976902
  • KB982018
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • Package 21 for KB2984976
  • Package 38 for KB2984976
  • Package 45 for KB2984976
  • Package 59 for KB2984976
  • Package 7 for KB2984976
  • Package 76 for KB2984976
  • PlatformUpdate Win7 SRV08R2 Package TopLevel
  • ProfessionalEdition
  • RDP BlueIP Package TopLevel
  • RDP WinIP Package TopLevel
  • RollupFix
  • UltimateEdition
  • WUClient SelfUpdate ActiveX
  • WUClient SelfUpdate Aux TopLevel
  • WUClient SelfUpdate Core TopLevel
  • WinMan WinIP Package TopLevel

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 3948)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
  • jparrvs.exe (PID: 2948)
  • jparrvs.exe (PID: 2672)
Drops executable file immediately after starts
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
Changes the autorun value in the registry
  • jparrvs.exe (PID: 2672)
Deletes shadow copies
  • jparrvs.exe (PID: 2672)
Stealing of credential data
  • jparrvs.exe (PID: 2672)
Renames files like Ransomware
  • jparrvs.exe (PID: 2672)
Executable content was dropped or overwritten
  • firefox.exe (PID: 4004)
  • WinRAR.exe (PID: 2400)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
Drops a file that was compiled in debug mode
  • firefox.exe (PID: 4004)
Checks supported languages
  • WinRAR.exe (PID: 2400)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 3948)
  • jparrvs.exe (PID: 2672)
  • jparrvs.exe (PID: 2948)
  • cmd.exe (PID: 2320)
Application launched itself
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 3948)
  • jparrvs.exe (PID: 2948)
Drops a file with too old compile date
  • WinRAR.exe (PID: 2400)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
Reads the computer name
  • WinRAR.exe (PID: 2400)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
  • jparrvs.exe (PID: 2672)
Starts itself from another location
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
Starts CMD.EXE for commands execution
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
Creates files in the user directory
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 2700)
  • jparrvs.exe (PID: 2672)
Checks for external IP
  • jparrvs.exe (PID: 2672)
Creates files in the program directory
  • jparrvs.exe (PID: 2672)
Creates files like Ransomware instruction
  • jparrvs.exe (PID: 2672)
Drops a file with a compile date too recent
  • jparrvs.exe (PID: 2672)
Executed as Windows Service
  • vssvc.exe (PID: 3948)
Checks supported languages
  • firefox.exe (PID: 3584)
  • firefox.exe (PID: 4004)
  • firefox.exe (PID: 2776)
  • firefox.exe (PID: 2280)
  • firefox.exe (PID: 1156)
  • firefox.exe (PID: 3608)
  • firefox.exe (PID: 3868)
  • vssadmin.exe (PID: 2188)
  • vssvc.exe (PID: 3948)
Reads the computer name
  • firefox.exe (PID: 4004)
  • firefox.exe (PID: 1156)
  • firefox.exe (PID: 2776)
  • firefox.exe (PID: 3608)
  • firefox.exe (PID: 2280)
  • firefox.exe (PID: 3868)
  • vssadmin.exe (PID: 2188)
  • vssvc.exe (PID: 3948)
Creates files in the program directory
  • firefox.exe (PID: 4004)
Application launched itself
  • firefox.exe (PID: 3584)
  • firefox.exe (PID: 4004)
Reads CPU info
  • firefox.exe (PID: 4004)
Checks Windows Trust Settings
  • firefox.exe (PID: 4004)
Reads the date of Windows installation
  • firefox.exe (PID: 4004)
Manual execution by user
  • WinRAR.exe (PID: 2400)
  • E906FA3D51E86A61741B3499145A114E9BFB7C56.exe (PID: 3948)
Creates files in the user directory
  • firefox.exe (PID: 4004)
Dropped object may contain Bitcoin addresses
  • jparrvs.exe (PID: 2672)
Dropped object may contain TOR URL's
  • jparrvs.exe (PID: 2672)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
60
Monitored processes
15
Malicious processes
2
Suspicious processes
2

Behavior graph

+
start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe e906fa3d51e86a61741b3499145a114e9bfb7c56.exe no specs e906fa3d51e86a61741b3499145a114e9bfb7c56.exe jparrvs.exe no specs cmd.exe no specs jparrvs.exe vssadmin.exe vssvc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3584
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" "https://github.com/ytisf/theZoo/blob/master/malware/Binaries/Ransomware.TeslaCrypt/Ransomware.TeslaCrypt.zip?raw=true"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\advapi32.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\rpcrt4.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msctf.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dbghelp.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\wintrust.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll

PID
4004
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" https://github.com/ytisf/theZoo/blob/master/malware/Binaries/Ransomware.TeslaCrypt/Ransomware.TeslaCrypt.zip?raw=true
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\dxgi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\oleaut32.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\kbdus.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\sechost.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\imm32.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\usp10.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\version.dll
c:\windows\system32\lpk.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\dbghelp.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\wintrust.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\gdi32.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\ws2_32.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\psapi.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbemcomn2.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\samlib.dll
c:\windows\system32\mscms.dll
c:\windows\system32\samcli.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wpc.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\audioses.dll
c:\windows\system32\propsys.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\normaliz.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\winhttp.dll
c:\program files\mozilla firefox\nssckbi.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\imageres.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msisip.dll
c:\windows\system32\cscui.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\windowspowershell\v1.0\pwrshsip.dll
c:\windows\system32\slc.dll
c:\windows\system32\wshext.dll
c:\windows\system32\urlmon.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\msmpeg2adec.dll
c:\windows\system32\mf.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\dxva2.dll

PID
2776
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4004.0.747823453\2024456920" -parentBuildID 20201112153044 -prefsHandle 1092 -prefMapHandle 808 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4004 "\\.\pipe\gecko-crash-server-pipe.4004" 1176 gpu
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\dxva2.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\wship6.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\atl.dll
c:\windows\system32\mf.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\evr.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\rpcrt4.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\sechost.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\iphlpapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\d3d11.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\devobj.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\windows\system32\lpk.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\windows\system32\ws2_32.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\profapi.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dnsapi.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\userenv.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\avrt.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\setupapi.dll

PID
2280
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4004.6.3089490\740757383" -childID 1 -isForBrowser -prefsHandle 3000 -prefMapHandle 2996 -prefsLen 181 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4004 "\\.\pipe\gecko-crash-server-pipe.4004" 3012 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wship6.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\wevtapi.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\usp10.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\clbcatq.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\samcli.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\lpk.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\rpcrt4.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\windows\system32\nsi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wpc.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\windows\system32\mswsock.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dwrite.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\avrt.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\wintrust.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\ole32.dll
c:\windows\system32\wshtcpip.dll

PID
3608
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4004.13.931894775\1537001399" -childID 2 -isForBrowser -prefsHandle 1728 -prefMapHandle 2084 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4004 "\\.\pipe\gecko-crash-server-pipe.4004" 2052 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imm32.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\windows\system32\dbghelp.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\samcli.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\user32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samlib.dll
c:\program files\mozilla firefox\freebl3.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\wintrust.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\windows\system32\winmm.dll
c:\windows\system32\usp10.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\clbcatq.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\mozilla firefox\softokn3.dll
c:\windows\system32\advapi32.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\netutils.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\avrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\napinsp.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\winnsi.dll

PID
1156
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4004.20.1721627263\356573178" -childID 3 -isForBrowser -prefsHandle 3524 -prefMapHandle 2116 -prefsLen 7399 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4004 "\\.\pipe\gecko-crash-server-pipe.4004" 3512 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\winnsi.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wintrust.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\ntmarta.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wldap32.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msctf.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\nlaapi.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dbghelp.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\windows\system32\pnrpnsp.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\cfgmgr32.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\iphlpapi.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\avrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wshtcpip.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\lpk.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
3868
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4004.27.56539703\1629860482" -childID 4 -isForBrowser -prefsHandle 3760 -prefMapHandle 3736 -prefsLen 7470 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4004 "\\.\pipe\gecko-crash-server-pipe.4004" 3772 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
83.0
Modules
Image
c:\windows\system32\nlaapi.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\sechost.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\userenv.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\oleaut32.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ole32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\setupapi.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\lpk.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\windows\system32\d3d11.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\windows\system32\winnsi.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\windows\system32\winmm.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\devobj.dll
c:\program files\mozilla firefox\d3dcompiler_47.dll

PID
2400
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ransomware.TeslaCrypt.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.91.0
Modules
Image
c:\windows\system32\cryptbase.dll
c:\windows\system32\msctf.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\usp10.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\devobj.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\imageres.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\samlib.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\cscui.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\winsta.dll
c:\windows\system32\samcli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\duser.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dui70.dll
c:\windows\system32\secur32.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\slc.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\profapi.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\drprov.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wmvcore.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptsp.dll

PID
3948
CMD
"C:\Users\admin\Desktop\E906FA3D51E86A61741B3499145A114E9BFB7C56.exe"
Path
C:\Users\admin\Desktop\E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
12
Version:
Company
Description
Version
Modules
Image
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\quartz.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\users\admin\desktop\e906fa3d51e86a61741b3499145a114e9bfb7c56.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\sechost.dll

PID
2700
CMD
C:\Users\admin\Desktop\E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
Path
C:\Users\admin\Desktop\E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
Indicators
Parent process
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Description
Version
Modules
Image
c:\windows\system32\kernel32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\usp10.dll
c:\users\admin\desktop\e906fa3d51e86a61741b3499145a114e9bfb7c56.exe
c:\windows\system32\imm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\version.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\quartz.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ole32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\users\admin\appdata\roaming\jparrvs.exe
c:\windows\system32\devobj.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\secur32.dll

PID
2948
CMD
C:\Users\admin\AppData\Roaming\jparrvs.exe
Path
C:\Users\admin\AppData\Roaming\jparrvs.exe
Indicators
No indicators
Parent process
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
User
admin
Integrity Level
MEDIUM
Exit code
12
Version:
Company
Description
Version
Modules
Image
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\quartz.dll
c:\users\admin\appdata\roaming\jparrvs.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\usp10.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winmm.dll

PID
2320
CMD
"C:\Windows\system32\cmd.exe" /c del C:\Users\admin\Desktop\E906FA~1.EXE >> NUL
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\cmd.exe
c:\windows\system32\winbrand.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll

PID
2672
CMD
C:\Users\admin\AppData\Roaming\jparrvs.exe
Path
C:\Users\admin\AppData\Roaming\jparrvs.exe
Indicators
Parent process
jparrvs.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\userenv.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\winmm.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\roaming\jparrvs.exe
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\quartz.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\webio.dll
c:\windows\system32\wship6.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\slc.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\iconcodecservice.dll

PID
2188
CMD
"C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet
Path
C:\Windows\System32\vssadmin.exe
Indicators
Parent process
jparrvs.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Command Line Interface for Microsoft� Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\atl.dll
c:\windows\system32\lpk.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll

PID
3948
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft� Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\resutils.dll
c:\windows\system32\authz.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\vssvc.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\es.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\samcli.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\devobj.dll
c:\windows\system32\samlib.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\version.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\atl.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\mfcsubs.dll

Registry activity

Total events
10872
Read events
0
Write events
130
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3584
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
A8AC032550000000
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Browser
AAB3032550000000
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
C:\Program Files\Mozilla Firefox|DisableTelemetry
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash
97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
C:\Program Files\Mozilla Firefox\firefox.exe
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
C:\Program Files\Mozilla Firefox|ServicesSettingsServer
https://firefox.settings.services.mozilla.com/v1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
0
4004
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
LanguageList
en-US
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
4004
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\WinRAR\WinRAR.exe
WinRAR archiver
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadNetworkName
Network 4
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
5A2C70298E09D801
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionReason
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionReason
1
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecision
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecision
0
4004
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
5A2C70298E09D801
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
2400
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
LanguageList
en-US
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
2
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
1
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\Ransomware.TeslaCrypt.zip
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface
ShowPassword
0
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD9FFFFFFA300000099030000A6020000
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000840101000000000039000000B40200000000000001000000
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000700101000000000016000000640000000000000003000000
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000008601010000000000160000002A0000000000000002000000
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
2400
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
2700
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
2700
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
2700
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
2700
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
msconfig
C:\Users\admin\AppData\Roaming\jparrvs.exe
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000003C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A864B0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
5A2C70298E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecision
0
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDetectedUrl
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionReason
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
5D8B3D3B8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
2D9E503B8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
5D8B3D3B8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecision
0
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadNetworkName
Network 4
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
2D9E503B8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionReason
1
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Control Panel\Desktop
WallpaperStyle
0
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
WpadDecisionTime
91403D3E8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
WpadDecisionTime
91403D3E8E09D801
2672
jparrvs.exe
write
HKEY_CURRENT_USER\Control Panel\Desktop
TileWallpaper
0

Files activity

Executable files
6
Suspicious files
205
Text files
492
Unknown types
27

Dropped files

PID
Process
Filename
Type
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.tmp
executable
MD5: 2c7a3b4c1883fae5d8a71cd43a5a20af
SHA256: df721c9e00dc2557c7d4c464168e83367fdcb9690ff6d51ba51eb71a21e9ac79
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1.1\gmpopenh264.dll.tmp
executable
MD5: d23f706f2eacc190f2d4b75b041670d5
SHA256: ced08ce5bc45dbe505fa94b3a4268c0830ccda016a23c0acb16dd7268cfa7a65
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll
executable
MD5: 2c7a3b4c1883fae5d8a71cd43a5a20af
SHA256: df721c9e00dc2557c7d4c464168e83367fdcb9690ff6d51ba51eb71a21e9ac79
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1.1\gmpopenh264.dll
executable
MD5: d23f706f2eacc190f2d4b75b041670d5
SHA256: ced08ce5bc45dbe505fa94b3a4268c0830ccda016a23c0acb16dd7268cfa7a65
2400
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRb2400.9127\E906FA3D51E86A61741B3499145A114E9BFB7C56
executable
MD5: 6d3d62a4cff19b4f2cc7ce9027c33be8
SHA256: afaba2400552c7032a5c4c6e6151df374d0e98dc67204066281e30e6699dbd18
2700
E906FA3D51E86A61741B3499145A114E9BFB7C56.exe
C:\Users\admin\AppData\Roaming\jparrvs.exe
executable
MD5: 6d3d62a4cff19b4f2cc7ce9027c33be8
SHA256: afaba2400552c7032a5c4c6e6151df374d0e98dc67204066281e30e6699dbd18
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: dc8cda8f4d5bf3f0cc74e62907e6c771
SHA256: 200b4ba11ad4aba980e44f321ab001a6baa6712aeedd80408f83ceb2fbb7acf4
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
text
MD5: dc8cda8f4d5bf3f0cc74e62907e6c771
SHA256: 200b4ba11ad4aba980e44f321ab001a6baa6712aeedd80408f83ceb2fbb7acf4
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.lib
obj
MD5: cd73bf55e2cf0f1caa5f1a469d75d9dc
SHA256: 48cd8b46c785ea848e2056525b7f8c28b5c164888bf7145db5b9ade91a71f7f2
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.sig.tmp
pi2
MD5: 92c7eba077938ef66cc7bd90619919e2
SHA256: ca5396df5db329682a778099ec40ce9c81846a97cfcb99b75a6013d19df1fe2e
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\LICENSE.txt.tmp
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.sig
pi2
MD5: 92c7eba077938ef66cc7bd90619919e2
SHA256: ca5396df5db329682a778099ec40ce9c81846a97cfcb99b75a6013d19df1fe2e
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\manifest.json.tmp
binary
MD5: b3d1c25ba27fc580d497ee7936fed44e
SHA256: 20aac87259d3a34207dedf0c1a6832890e73f18aab557d7ea593e889da6ac15a
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.lib.tmp
obj
MD5: cd73bf55e2cf0f1caa5f1a469d75d9dc
SHA256: 48cd8b46c785ea848e2056525b7f8c28b5c164888bf7145db5b9ade91a71f7f2
4004
firefox.exe
C:\Users\admin\AppData\Local\Temp\tmpaddon-a347d4
compressed
MD5: ca728e84cc4daebbed5bafb35e3df9df
SHA256: 8eeb72ff641c26eb563f6a0fdb1b3fe67f0f9b17be4c4f96a83304590ec99a83
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\LICENSE.txt
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
4004
firefox.exe
C:\Users\admin\AppData\Local\Temp\tmpaddon
compressed
MD5: 29ddfd36f79eaae39627110a00ff8370
SHA256: 600552de4de554364152ed426d02264e97d76ae1f33afb1d845a0d25e5e5ba33
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1582.2\manifest.json
binary
MD5: b3d1c25ba27fc580d497ee7936fed44e
SHA256: 20aac87259d3a34207dedf0c1a6832890e73f18aab557d7ea593e889da6ac15a
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1.1\gmpopenh264.info.tmp
text
MD5: 3d33cdc0b3d281e67dd52e14435dd04f
SHA256: f526e9f98841d987606efeaff7f3e017ba9fd516c4be83890c7f9a093ea4c47b
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1.1\gmpopenh264.info
text
MD5: 3d33cdc0b3d281e67dd52e14435dd04f
SHA256: f526e9f98841d987606efeaff7f3e017ba9fd516c4be83890c7f9a093ea4c47b
2672
jparrvs.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.ecc
––
MD5:  ––
SHA256:  ––
2672
jparrvs.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping.tmp
text
MD5: 8f799ea0c380e45442fbd9dec3e54202
SHA256: 8597b6b693581eb305353bb6806efd572d6deba2dbe389e4d8d19662056251f2
4004
firefox.exe
C:\ProgramData\Mozilla\profile_count_308046B0AF4A39CB.json
binary
MD5: 58728d2e9d553bb2369bdb4a618acae5
SHA256: 7ebc652a4b5b43608f61ac1057c51ec2ec1c8e33bbeb130794e15af72beb42e8
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.tmp
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.tmp
binary
MD5: 735c0da4a5ec45e899aab328c74328a8
SHA256: a104aff66199905c0a136149d09d8cd37916ff4aa56693d697719a4de4f78c76
2672
jparrvs.exe
C:\Users\admin\Desktop\HELP_RESTORE_FILES.bmp
image
MD5: c78519ef32aab0c0cb38e8a937bcd733
SHA256: 8bd197069fbd243014bde541a130d1b59e89c06ad2ded29d56210f27dfa76ae3
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping
text
MD5: 8f799ea0c380e45442fbd9dec3e54202
SHA256: 8597b6b693581eb305353bb6806efd572d6deba2dbe389e4d8d19662056251f2
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
binary
MD5: 735c0da4a5ec45e899aab328c74328a8
SHA256: a104aff66199905c0a136149d09d8cd37916ff4aa56693d697719a4de4f78c76
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db
sqlite
MD5: 24a1f1d8583fb770e74456ecbd9f28b5
SHA256: d769e74025c69bd703b57e0c3efabe7e9d99736135bf501253ebe7483fd940c2
2672
jparrvs.exe
C:\Users\Public\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\log.html
text
MD5: 2a3542232a39ef525dad2c203455bea4
SHA256: f437aa143be03ffde8cfe8d3407045d22c131f9c20e983640587e34758798b79
2672
jparrvs.exe
C:\Users\Public\Videos\Sample Videos\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Desktop\CryptoLocker.lnk
lnk
MD5: 28d42bc7f56b82f1f55d922bb571f47a
SHA256: f7a84647e9c4555a30fd714a712e4ba726ccbff7177ca45a23b44c01a79f08db
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db-journal
binary
MD5: b290b654351a44e60e0bc87504805c9c
SHA256: ad2184dac3765661eeb8f5e1f5478f92ecfb3cd5ced8123e294f03b5e3e59652
2672
jparrvs.exe
C:\Users\Public\Recorded TV\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Recorded TV\Sample Media\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.ecc
binary
MD5: 76cebdc4d5b137d2c53a52bea1bc590e
SHA256: 16183c42909f8623f73216525f68cacd83e38f3854bc48aac229303c72c83472
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
binary
MD5: 76cebdc4d5b137d2c53a52bea1bc590e
SHA256: 16183c42909f8623f73216525f68cacd83e38f3854bc48aac229303c72c83472
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.ecc
binary
MD5: fa3007bb8d81ba51bf0c9ad3df238678
SHA256: bfb8a49709325bacb4c9aa27ff3f5a52864e8d763710ce760330a19cd127e101
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
binary
MD5: fa3007bb8d81ba51bf0c9ad3df238678
SHA256: bfb8a49709325bacb4c9aa27ff3f5a52864e8d763710ce760330a19cd127e101
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.ecc
binary
MD5: 33da6d45cf2085757a23094dc17629b9
SHA256: 23b7ac4061c491567da41326572d2a62834601adfc9b0d078d76f393ed75e833
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.ecc
binary
MD5: 65e435032d949263ec9080dc00ae59e9
SHA256: e9bbc1694153f1c4a3b441f2cbd97c8358c393415039156e590efb82847ee6d9
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
binary
MD5: e434173c8f53f00d6f0030adb5cc5de2
SHA256: cd803f555f2aadffb5c44c5db489de4f596183082ad545ed7a5f25c604b4c787
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
binary
MD5: 65e435032d949263ec9080dc00ae59e9
SHA256: e9bbc1694153f1c4a3b441f2cbd97c8358c393415039156e590efb82847ee6d9
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
binary
MD5: 33da6d45cf2085757a23094dc17629b9
SHA256: 23b7ac4061c491567da41326572d2a62834601adfc9b0d078d76f393ed75e833
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.ecc
binary
MD5: e434173c8f53f00d6f0030adb5cc5de2
SHA256: cd803f555f2aadffb5c44c5db489de4f596183082ad545ed7a5f25c604b4c787
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.ecc
binary
MD5: 8ed30d1c90c575094783957de2d5e8de
SHA256: 90b0d4bf14bf34983f58cedc12938964320bc1e9b8377ece815089a8f2fb6f9b
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.ecc
binary
MD5: 345adbbda4c2334156d57e09b5a80baa
SHA256: 77d2bc8794cf4013fa73c0e788e9ae865a395b0a24f6b52d8fa53a6b34bad2ce
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
binary
MD5: 345adbbda4c2334156d57e09b5a80baa
SHA256: 77d2bc8794cf4013fa73c0e788e9ae865a395b0a24f6b52d8fa53a6b34bad2ce
2672
jparrvs.exe
C:\Users\Public\Music\Sample Music\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.ecc
binary
MD5: 2e6a213f82b0af70c13e0cce8373ef64
SHA256: e3c951f35288d36b704c4e75a38be4ab249d575e2d25959d8c661c97fabf3915
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
binary
MD5: 2e6a213f82b0af70c13e0cce8373ef64
SHA256: e3c951f35288d36b704c4e75a38be4ab249d575e2d25959d8c661c97fabf3915
2672
jparrvs.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
binary
MD5: 8ed30d1c90c575094783957de2d5e8de
SHA256: 90b0d4bf14bf34983f58cedc12938964320bc1e9b8377ece815089a8f2fb6f9b
2672
jparrvs.exe
C:\Users\Public\Downloads\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Pictures\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Libraries\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Oracle\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Videos\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Skype\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Music\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Oracle\Java\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Mozilla\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\update-config.json.ecc
binary
MD5: 4a15ef9ef1eb2ec6d45ccb7c4a26f4e4
SHA256: 09d2dcb90e7db6ceb59827c812cc13b2ba63ef81ccbf353f5fbd2319f3f2aaea
2672
jparrvs.exe
C:\ProgramData\MOZILLA\PROFILE_COUNT_308046B0AF4A39CB.JSON
binary
MD5: 7ca44b603d47ee11949973d916adadef
SHA256: 12f1ef07bc96994af84cceb3548ede04119dea478a72c6d48de1087fb16e7c9d
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\update-config.json
binary
MD5: 4a15ef9ef1eb2ec6d45ccb7c4a26f4e4
SHA256: 09d2dcb90e7db6ceb59827c812cc13b2ba63ef81ccbf353f5fbd2319f3f2aaea
2672
jparrvs.exe
C:\ProgramData\Mozilla\profile_count_308046B0AF4A39CB.json.ecc
binary
MD5: 7ca44b603d47ee11949973d916adadef
SHA256: 12f1ef07bc96994af84cceb3548ede04119dea478a72c6d48de1087fb16e7c9d
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_msedge.exe_fb958cd98e2b2de021216861839af1d38727312f_0b1296d7\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\Windows\DRM\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\Windows\DRM\Cache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\RAC\PublishedData\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\DeviceSync\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\RAC\Temp\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\User Account Pictures\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\eHome\logs\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Favorites\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Microsoft\eHome\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\Public\Documents\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\Setup\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\ARM\Reader_15.007.20033\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\Temp\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\ARM\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Saved Games\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Pictures\joinedresult.jpg.ecc
binary
MD5: 969ae412a52ef2022737cda445959b1d
SHA256: 5e8f204a974fc2248b89bfa7eaf40ad0c8f7638afe2809cc490baae0e68bc70d
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\ProgramData\Adobe\ARM\Reader_20.013.20064\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Pictures\riverbeach.png.ecc
vc
MD5: 27341e8d584f499ad58925442f53b242
SHA256: 31ab764fa007478ab2acb5c29e2744147508baed51b1c8961d2083eb17d82b18
2672
jparrvs.exe
C:\Users\admin\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Pictures\riverbeach.png
vc
MD5: 27341e8d584f499ad58925442f53b242
SHA256: 31ab764fa007478ab2acb5c29e2744147508baed51b1c8961d2083eb17d82b18
2672
jparrvs.exe
C:\Users\admin\Pictures\januarymac.jpg.ecc
binary
MD5: c384c6071b78b1f78fc2fc312b2151e5
SHA256: 552499db05cd5755f0539fc1c063e1b0941b40c8a687bb23621fb018ad95b3b4
2672
jparrvs.exe
C:\Users\admin\Searches\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Pictures\joinedresult.jpg
binary
MD5: 969ae412a52ef2022737cda445959b1d
SHA256: 5e8f204a974fc2248b89bfa7eaf40ad0c8f7638afe2809cc490baae0e68bc70d
2672
jparrvs.exe
C:\Users\admin\Pictures\januarymac.jpg
binary
MD5: c384c6071b78b1f78fc2fc312b2151e5
SHA256: 552499db05cd5755f0539fc1c063e1b0941b40c8a687bb23621fb018ad95b3b4
2672
jparrvs.exe
C:\Users\admin\Favorites\MSN Websites\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Local\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Favorites\Windows Live\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Favorites\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Downloads\readinground.jpg.ecc
binary
MD5: 3d11f8c821df464e44b5ee9f3079dbf0
SHA256: d52760a20f5fbed43823d45084d96b5eeb865b77dfa1ebd18b6058d7aec6b7f6
2672
jparrvs.exe
C:\Users\admin\Favorites\Links for United States\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Links\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Downloads\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Downloads\simplyhold.png.ecc
binary
MD5: 211a915293d195e43297376a0ad50389
SHA256: 21f07fd03b34be0965a080bbffbe85178d44a818202d62220b050a3887d792a1
2672
jparrvs.exe
C:\Users\admin\Favorites\Microsoft Websites\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Downloads\welcomechoice.jpg.ecc
binary
MD5: 439793f95697e6669943f493c337e4c4
SHA256: 8dd63207aab793ca6e15c8d1635de58f0ee3e6d277407383a67d2b4dff0843fb
2672
jparrvs.exe
C:\Users\admin\Downloads\simplyhold.png
binary
MD5: 211a915293d195e43297376a0ad50389
SHA256: 21f07fd03b34be0965a080bbffbe85178d44a818202d62220b050a3887d792a1
2672
jparrvs.exe
C:\Users\admin\Documents\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Downloads\welcomechoice.jpg
binary
MD5: 439793f95697e6669943f493c337e4c4
SHA256: 8dd63207aab793ca6e15c8d1635de58f0ee3e6d277407383a67d2b4dff0843fb
2672
jparrvs.exe
C:\Users\admin\Downloads\politicalx.png.ecc
binary
MD5: 97fd75d02538448b6dacecf6e46c0ca4
SHA256: 60cb2db4a583ff0ae02cc5646b8a0f1af067fc418469a497b018dbc447070730
2672
jparrvs.exe
C:\Users\admin\Downloads\evaluationavailable.jpg
binary
MD5: 8f8a8c288a9805e36568434e656eab2a
SHA256: 754941081a75334db7ff9fedfe28acb1dfc7e902ec503e1461ffa075a6e38a3b
2672
jparrvs.exe
C:\Users\admin\Favorites\Links\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\weekshigh.rtf
binary
MD5: 26a9a59a8c6e072be01a7f03971b6692
SHA256: 6408a54604b30cec9ac2b6d0ffd31e400779e186f1cdf5e9130f29d83147a470
2672
jparrvs.exe
C:\Users\admin\Downloads\baycool.png
binary
MD5: 6c55ba15c9be727f64221f54d9c5a3cf
SHA256: 7eaf88b953016e8164e44366038ab6016b50bf5d108d00d85e650602a515c17a
2672
jparrvs.exe
C:\Users\admin\Downloads\readinground.jpg
binary
MD5: 3d11f8c821df464e44b5ee9f3079dbf0
SHA256: d52760a20f5fbed43823d45084d96b5eeb865b77dfa1ebd18b6058d7aec6b7f6
2672
jparrvs.exe
C:\Users\admin\Downloads\baycool.png.ecc
binary
MD5: 6c55ba15c9be727f64221f54d9c5a3cf
SHA256: 7eaf88b953016e8164e44366038ab6016b50bf5d108d00d85e650602a515c17a
2672
jparrvs.exe
C:\Users\admin\Documents\toagents.rtf.ecc
binary
MD5: dd2b31bc6a254f081e96848cf9d47a13
SHA256: d20c8c2c18eb5d2b3acf566b893349de5e2a39fb8d6a08865596a8287dbe194a
2672
jparrvs.exe
C:\Users\admin\Downloads\evaluationavailable.jpg.ecc
binary
MD5: 8f8a8c288a9805e36568434e656eab2a
SHA256: 754941081a75334db7ff9fedfe28acb1dfc7e902ec503e1461ffa075a6e38a3b
2672
jparrvs.exe
C:\Users\admin\Downloads\politicalx.png
binary
MD5: 97fd75d02538448b6dacecf6e46c0ca4
SHA256: 60cb2db4a583ff0ae02cc5646b8a0f1af067fc418469a497b018dbc447070730
2672
jparrvs.exe
C:\Users\admin\Documents\pothink.rtf.ecc
gpg
MD5: ba1c65fd34d1ea2a1d252711d053493b
SHA256: 7ba9773ef5448bf1e0a12e01a03e3272d7b5f4de69aeee27e3bb5898b92ec476
2672
jparrvs.exe
C:\Users\admin\Documents\toagents.rtf
binary
MD5: dd2b31bc6a254f081e96848cf9d47a13
SHA256: d20c8c2c18eb5d2b3acf566b893349de5e2a39fb8d6a08865596a8287dbe194a
2672
jparrvs.exe
C:\Users\admin\Documents\pothink.rtf
gpg
MD5: ba1c65fd34d1ea2a1d252711d053493b
SHA256: 7ba9773ef5448bf1e0a12e01a03e3272d7b5f4de69aeee27e3bb5898b92ec476
2672
jparrvs.exe
C:\Users\admin\Documents\weekshigh.rtf.ecc
binary
MD5: 26a9a59a8c6e072be01a7f03971b6692
SHA256: 6408a54604b30cec9ac2b6d0ffd31e400779e186f1cdf5e9130f29d83147a470
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.ecc
binary
MD5: 47a8929e1600877855d89c37f8d7a7c1
SHA256: 7aed83e5cb0ccb32970c117920b198b18a8a3977297149c996026ea3da2b9259
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
binary
MD5: 3c82c56b6c934eb3f4a6f23becca5a6f
SHA256: 509f2545a00667460d3dd8f136e766bae1a42089b59b8a46ce4870e0f6957ee6
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.ecc
binary
MD5: 3c82c56b6c934eb3f4a6f23becca5a6f
SHA256: 509f2545a00667460d3dd8f136e766bae1a42089b59b8a46ce4870e0f6957ee6
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
binary
MD5: 47a8929e1600877855d89c37f8d7a7c1
SHA256: 7aed83e5cb0ccb32970c117920b198b18a8a3977297149c996026ea3da2b9259
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
binary
MD5: 150b118092a67fcb611996a7e94dc3e1
SHA256: 3c202c61b11be38176989ecd4fd5092f638d57cf1528e274498db321c616a56f
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.ecc
binary
MD5: 150b118092a67fcb611996a7e94dc3e1
SHA256: 3c202c61b11be38176989ecd4fd5092f638d57cf1528e274498db321c616a56f
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.ecc
binary
MD5: 2a108c05ce9b695f559e0ff9023483e8
SHA256: 054986236c6f8a3974e99853d818df51aaed183f03adcf51d03a44df5205df0b
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
binary
MD5: 2a108c05ce9b695f559e0ff9023483e8
SHA256: 054986236c6f8a3974e99853d818df51aaed183f03adcf51d03a44df5205df0b
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 031410e93170f1dcd6900fe247826854
SHA256: b55a7f5f95977acd061813b1242b3b9524ab9cb246483862bcd4a7bbb0426d1b
2672
jparrvs.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 031410e93170f1dcd6900fe247826854
SHA256: b55a7f5f95977acd061813b1242b3b9524ab9cb246483862bcd4a7bbb0426d1b
2672
jparrvs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\OneNote Notebooks\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\lotwill.rtf.ecc
binary
MD5: 1892ff283d9e91af66488c2f26e6400e
SHA256: ed8c96528e917e97545066e481ed85d79936b24fb74ddd1fb2177194d4f9d7ac
2672
jparrvs.exe
C:\Users\admin\Music\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\lowesthost.rtf
binary
MD5: 9b6460b57a2c49c06428a062edf9a43c
SHA256: f02cd660a57cc62fc07371cd021bf25d86642ba74c5b1b7ca593b4dcbbcd765f
2672
jparrvs.exe
C:\Users\admin\Pictures\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Documents\lowesthost.rtf.ecc
binary
MD5: 9b6460b57a2c49c06428a062edf9a43c
SHA256: f02cd660a57cc62fc07371cd021bf25d86642ba74c5b1b7ca593b4dcbbcd765f
2672
jparrvs.exe
C:\Users\admin\Videos\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Desktop\placesmorning.rtf
binary
MD5: afb0a84057d5371820d4fa6a99f8feab
SHA256: 5ea634e9775a291caf9392d7787c538d2b9b0fba945c30eeab513821f0b2d7ea
2672
jparrvs.exe
C:\Users\admin\Documents\lotwill.rtf
binary
MD5: 1892ff283d9e91af66488c2f26e6400e
SHA256: ed8c96528e917e97545066e481ed85d79936b24fb74ddd1fb2177194d4f9d7ac
2672
jparrvs.exe
C:\Users\admin\Desktop\sexanswers.jpg
binary
MD5: bb632264d798e9c50175996df098747b
SHA256: 6a36e03f713944c0d987bc971e4f9922a81ae7a3d6903e9c4d3dca84e726982c
2672
jparrvs.exe
C:\Users\admin\Desktop\placesmorning.rtf.ecc
binary
MD5: afb0a84057d5371820d4fa6a99f8feab
SHA256: 5ea634e9775a291caf9392d7787c538d2b9b0fba945c30eeab513821f0b2d7ea
2672
jparrvs.exe
C:\Users\admin\Desktop\menumonth.rtf
binary
MD5: f65516f5d54fea11df84df3f15613d1a
SHA256: 67b8bc8bf6d10f4b9b55356a7b301f7c741a1b6e72b86d0d915c2bca84785175
2672
jparrvs.exe
C:\Users\admin\Desktop\devicesattention.jpg.ecc
binary
MD5: 72255423a954ac670ecd1fde9863bfca
SHA256: 6a0d5ca7b2fac2fe0c698047b8f6981ac75aa1602ced1739ea2e888d8180b88a
2672
jparrvs.exe
C:\Users\admin\Desktop\higherfollow.rtf
binary
MD5: 9f6ba2e7057053d96579ee1704067574
SHA256: e9f388aeefdd9ab9c0b59107bd4db1b003fc9bae8cdf98bf9c5df9b9c56f88ea
2672
jparrvs.exe
C:\Users\admin\Desktop\devicesattention.jpg
binary
MD5: 72255423a954ac670ecd1fde9863bfca
SHA256: 6a0d5ca7b2fac2fe0c698047b8f6981ac75aa1602ced1739ea2e888d8180b88a
2672
jparrvs.exe
C:\Users\admin\Desktop\menumonth.rtf.ecc
binary
MD5: f65516f5d54fea11df84df3f15613d1a
SHA256: 67b8bc8bf6d10f4b9b55356a7b301f7c741a1b6e72b86d0d915c2bca84785175
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Desktop\sexanswers.jpg.ecc
binary
MD5: bb632264d798e9c50175996df098747b
SHA256: 6a36e03f713944c0d987bc971e4f9922a81ae7a3d6903e9c4d3dca84e726982c
2672
jparrvs.exe
C:\Users\admin\Desktop\chaptersite.jpg
binary
MD5: 6858c385d198254e2427286d5075893a
SHA256: 132d45ac97e8cd9be887f88e6929ddb98593e94a0324b1dbf64da00f6b4bfbe8
2672
jparrvs.exe
C:\Users\admin\Desktop\higherfollow.rtf.ecc
binary
MD5: 9f6ba2e7057053d96579ee1704067574
SHA256: e9f388aeefdd9ab9c0b59107bd4db1b003fc9bae8cdf98bf9c5df9b9c56f88ea
2672
jparrvs.exe
C:\Users\admin\Desktop\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Desktop\chaptersite.jpg.ecc
binary
MD5: 6858c385d198254e2427286d5075893a
SHA256: 132d45ac97e8cd9be887f88e6929ddb98593e94a0324b1dbf64da00f6b4bfbe8
2672
jparrvs.exe
C:\Users\admin\AppData\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\uTorrent\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\Contacts\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\security\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\tmp\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\tmp\si\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\log\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Mozilla\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{ce348e4c-7d33-445e-89f9-60108c51bcaf}\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\YYEFSHZD\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\UB07H30W\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{340d53f3-8e15-4bee-bf07-fcd13f403727}\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\EmieSiteList\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\logo_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}_en-US_100_gray.png.ecc
binary
MD5: 51bbc3084b64e186c8fb084c02e6f6fb
SHA256: 0e86b1bfd8a3fc25bc27bebf4ce0fba105d3a515e07d73985a881326ac3a2802
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Windows\AppCache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Windows\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Windows\AppCache\P5S0AQFP\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\EmieUserList\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\FWSTRUSW\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\CYFV42NM\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\DOTBATAV\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\7RYGIJPD\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\logo_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}_en-US_100_gray.png
binary
MD5: 51bbc3084b64e186c8fb084c02e6f6fb
SHA256: 0e86b1bfd8a3fc25bc27bebf4ce0fba105d3a515e07d73985a881326ac3a2802
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\Q77WVJ6S\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\CYUQ4FPV\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\2EVQAL7B\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\FO6DYIE7\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\R0AQPIW5\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\445RX31X\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\header\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\H1YLPPW7\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\JCEJCZCZ\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\0U1LC3VF\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3WZRIU9Y\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\visualprofiler\settings.json.ecc
binary
MD5: a9f4c9c7b1e63571d861dd04ce200017
SHA256: 9195cd2743271776486da7d6234eafeb298894ffc673500e7eb087c890ccfd1a
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\memory\settings.json.ecc
gpg
MD5: e1e34e19bd81fa75a0a76ffa898aefd5
SHA256: 861379512a146d126fd144e03a3ad1c2b6ad90bb1fd72070a1b44edd07c419a4
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\header\MyCode.json.ecc
binary
MD5: 9a410021e3b4bed5522d939a81b6ce5e
SHA256: 30048f61955dde55c1ae7b0b2b6b91ebb8e45461b0012c7da06db7a50aa4f0a9
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\visualprofiler\settings.json
binary
MD5: a9f4c9c7b1e63571d861dd04ce200017
SHA256: 9195cd2743271776486da7d6234eafeb298894ffc673500e7eb087c890ccfd1a
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\memory\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\debugger\settings.json.ecc
binary
MD5: 50617885a96ccd757351e54f8bf05728
SHA256: ee2b568974dd96235907f7351d866e17fc8b1b5916ce7a05c44292c7049035ad
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\visualprofiler\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\debugger\settings.json
binary
MD5: 50617885a96ccd757351e54f8bf05728
SHA256: ee2b568974dd96235907f7351d866e17fc8b1b5916ce7a05c44292c7049035ad
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\debugger\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\header\MyCode.json
binary
MD5: 9a410021e3b4bed5522d939a81b6ce5e
SHA256: 30048f61955dde55c1ae7b0b2b6b91ebb8e45461b0012c7da06db7a50aa4f0a9
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\F12\perftools\memory\settings.json
gpg
MD5: e1e34e19bd81fa75a0a76ffa898aefd5
SHA256: 861379512a146d126fd144e03a3ad1c2b6ad90bb1fd72070a1b44edd07c419a4
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\tr_TR\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\sk_SK\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\uk_UA\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\sl_SI\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\si_LK\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\sv_SE\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ta_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pt_BR\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pl_PL\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ru_RU\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\nn_NO\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\te_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\mr_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ro_RO\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pa_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pt_PT\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\nl_NL\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\my_MM\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ml_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\hr_HR\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\or_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\nb_NO\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\gu_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\hi_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\he_IL\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\id_ID\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\kn_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\lv_LV\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\km_KH\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\hu_HU\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\it_IT\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\lo_LA\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\lt_LT\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\fr_FR\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\de_DE\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\es_ES\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_CA\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\all\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_GB\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\da_DK\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\et_EE\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\bg_BG\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\de_CH\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ca_ES\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ar_AE\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_US\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\bn_IN\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\cs_CZ\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\el_GR\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cookie\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Search\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\03f5b075-6b94-451c-a104-d2e608581734\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\assets\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\DesktopNotification\NotificationsDB\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 1bbfbfd3bf11e32ba4dfa3f59dba07cd
SHA256: 60b21c92dc863cfcfcc36eb5bb6b6fc882ca31c4f2ab1753c835ff8b2dbdac46
2672
jparrvs.exe
C:\Users\admin\.oracle_jre_usage\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 1bbfbfd3bf11e32ba4dfa3f59dba07cd
SHA256: 60b21c92dc863cfcfcc36eb5bb6b6fc882ca31c4f2ab1753c835ff8b2dbdac46
2672
jparrvs.exe
C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\DesktopNotification\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\1033\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0101-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0100-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-041F-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 54c5e852bde2320643f6523ae3f9aca6
SHA256: 94258d5e7898b3f074ad782c4f524ff21419c368be012766941642fb4cfce26d
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00BA-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0C0A-0000-0000000FF1CE}-C\3082\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-041F-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 54c5e852bde2320643f6523ae3f9aca6
SHA256: 94258d5e7898b3f074ad782c4f524ff21419c368be012766941642fb4cfce26d
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0C0A-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: d473dc159ad46923e85121ec08b638a8
SHA256: ccd6b294ca5f9006b623ef7dee87fba5a401a9d2dafcd453ac3611ba66953002
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0C0A-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: d473dc159ad46923e85121ec08b638a8
SHA256: ccd6b294ca5f9006b623ef7dee87fba5a401a9d2dafcd453ac3611ba66953002
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-041F-0000-0000000FF1CE}-C\1055\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 2d23c08d28eff4e6b0eb6c02de18343a
SHA256: 91775f80a86a1caf09ece47c563ec71ed276a2a87d98aaaa4efe19077b66070b
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0419-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: e46a00e86caa293238817039f9bf00e5
SHA256: 9346c1c41f4913658ddad52c4624d2f17e766b8f7790cb0fd9869bac6d9f0a7d
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 2d23c08d28eff4e6b0eb6c02de18343a
SHA256: 91775f80a86a1caf09ece47c563ec71ed276a2a87d98aaaa4efe19077b66070b
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0419-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: e46a00e86caa293238817039f9bf00e5
SHA256: 9346c1c41f4913658ddad52c4624d2f17e766b8f7790cb0fd9869bac6d9f0a7d
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\1046\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 8f288215de001c261f9dc8c4034440ca
SHA256: 86a327258249072070064a34b47717b4619165694f871e9a866495099cddea23
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0419-0000-0000000FF1CE}-C\1049\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\1042\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 455a46337507bbb10887aaba757a9aa5
SHA256: 2e21c08352226e5936c71700ae1e7a89c14f03d09cf8b695aa81ec8453fcc25b
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\1041\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: ce98f997fdf9e2c87ac6fab8090ad174
SHA256: 1ad6100004f9c95c0ec14bf68a19cc8e3d8f24cd8bf3d79d96ef8bf40e05bbe9
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 8f288215de001c261f9dc8c4034440ca
SHA256: 86a327258249072070064a34b47717b4619165694f871e9a866495099cddea23
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: ae874431f800685d82d122a320c430d0
SHA256: 5bbf30f293c27139f974ebeb1a810a68b602b53ea756f149adf6d8d31eee55d5
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 455a46337507bbb10887aaba757a9aa5
SHA256: 2e21c08352226e5936c71700ae1e7a89c14f03d09cf8b695aa81ec8453fcc25b
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\1036\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\1040\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: 9f5764beacd688eec7a7ef64ec991180
SHA256: eb5f0ee44f3bc5cc6ce3e3b8c9d7ffac51ae7e1f58652f602380d5bdca1ab9ca
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: ce98f997fdf9e2c87ac6fab8090ad174
SHA256: 1ad6100004f9c95c0ec14bf68a19cc8e3d8f24cd8bf3d79d96ef8bf40e05bbe9
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
binary
MD5: ae874431f800685d82d122a320c430d0
SHA256: 5bbf30f293c27139f974ebeb1a810a68b602b53ea756f149adf6d8d31eee55d5
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ecc
binary
MD5: 9f5764beacd688eec7a7ef64ec991180
SHA256: eb5f0ee44f3bc5cc6ce3e3b8c9d7ffac51ae7e1f58652f602380d5bdca1ab9ca
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\1031\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.eu\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.gl\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\ip[1].htm
text
MD5: e885859f0f699b701f53f713c0ac001c
SHA256: 017dd2d97e51f79998ff0257a61f7ee33a8ac3e93e345854f94d1b90258748b2
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0419-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0044-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.ca\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0419-0000-0000000FF1CE}-C\Proof.de\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.pt-br\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\Proof.tr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.es\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0416-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0419-0000-0000000FF1CE}-C\Proof.ru\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0416-0000-0000000FF1CE}-C\Proof.pt-br\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0416-0000-0000000FF1CE}-C\Proof.es\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0419-0000-0000000FF1CE}-C\Proof.uk\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\Proof.de\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0411-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0410-0000-0000000FF1CE}-C\Proof.it\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0410-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0410-0000-0000000FF1CE}-C\Proof.de\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0412-0000-0000000FF1CE}-C\Proof.ko\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.de\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0410-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0412-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.ar\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0411-0000-0000000FF1CE}-C\Proof.ja\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.es\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-040C-0000-0000000FF1CE}-C\Proof.nl\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0407-0000-0000000FF1CE}-C\Proof.de\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0407-0000-0000000FF1CE}-C\Proof.it\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0407-0000-0000000FF1CE}-C\Proof.fr\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-002C-0407-0000-0000000FF1CE}-C\Proof.en\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001B-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-001A-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0019-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0018-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0017-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-041F-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0411-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0412-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0416-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0016-0C0A-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0419-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
2672
jparrvs.exe
C:\Users\admin\AppData\Roaming\key.dat
binary
MD5: c564af490efb9a89983ba709de1de9e0
SHA256: 2d2b75377343b3f47d30f9a9e27172de1a77e31fd418c1e5bbf8b4aaed134e48
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
2672
jparrvs.exe
C:\Users\admin\Documents\RECOVERY_KEY.TXT
text
MD5: 5d95561443c3f07815d652d0187e22e6
SHA256: 5085a7332adfcab1cc68d99ff9cd5bba5179aec36c058d9bd2a4eacf1278d8b3
2672
jparrvs.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\HELP_RESTORE_FILES.txt
text
MD5: fd50fd5938263664703347d04c53a9fe
SHA256: 31a3350339f11ea41008ce316d1e47f59fecd5cefebbe81c6e99292838a64571
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
binary
MD5: 4881ff76fa6d59d2b09d2177a757f238
SHA256: 77f9bceb57e489604ab0a0033d0fc0ed263891af5ff01cc78b95f5228600b3d7
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-facebook-digest256.vlpset
binary
MD5: 86b1acdbf1fc7201d0eb7c85ee75f5af
SHA256: a0f4c83316cd66525f663cd72a2dc8bd1b2aa2e40d599b8b6f334d61c5d03098
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
binary
MD5: 7724ca958578dd2c0073e8d612145790
SHA256: 8191fcb484edac9bcf264313d0efd587aad296ff670045d988a22dd18869d08d
4004
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
binary
MD5: bdb95af1e203e0c26133ec5ba1a71e90
SHA256: 9bad16ed09db5c1041e5d8edec1035c4cd554dd40e4a342b3c78cd0ec1426af1
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-facebook-digest256.sbstore
binary
MD5: 58fbc7f7687cc8798aea35b7066eb198
SHA256: 3a2035ad8446c71242daa9eaf3818b87f673d0429e4f5334621905b47a1c3df5
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-linkedin-digest256.vlpset
binary
MD5: 3303aa4bcb02d27f1a8b6aff30c1dd9c
SHA256: 6f33ccfcf9767b612657242c2819c325cfdf17b8d92224db588a886f7ec2d26e
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-twitter-digest256.vlpset
binary
MD5: 35d8fd43d868d7bba7041362eb8101b3
SHA256: 104c2467e4f7bc7cac0ce0e456d5abd8c192c2c8c44f7c9a38412a59abdd1772
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-linkedin-digest256.sbstore
binary
MD5: 3b11b562807fef504fe671ded4d0e8ce
SHA256: 9bf05adc119cdd219347572787a9b7e18308c4465a8f440c34c697b2f5cd479f
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-cryptomining-track-digest256.vlpset
binary
MD5: 7d532b89a987d92def1d7aabbaad62ab
SHA256: 7cb574be3e783d6876740dbca525d868677307a52dddd67ac84665ccfaae895e
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-tracking-protection-twitter-digest256.sbstore
binary
MD5: 373411cebf6e3bcb89d8bfa632409bf1
SHA256: c1d5b95b18ff02514bda0ec7865d9468c3a89e5c3ba2ebd3d4284fd8fcd463d4
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-fingerprinting-track-digest256.sbstore
binary
MD5: daa7abdb5ed1dbf8877f4028092e32f6
SHA256: b8f20b14ad5291b4528df859129b301f367a9885f417f9807821d5a386352530
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
binary
MD5: 22698b4cf784dbbae2d583f00491d43d
SHA256: 3849563088ae0677d61702a1310fde26de5ddd846d53037222d3efe012197bf5
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
binary
MD5: b9556d03aff392142ad5691d2f867310
SHA256: cfd3909b41c1ee3cbcb8b7d2b1378065e7d3b543fff1f2fb7a4f25c5ff41722c
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.vlpset
binary
MD5: 40165280ff1345b5241ec2a9d1da2af0
SHA256: f80bdd5341d8b1ee946e344e258ef2d35c3c0bb6b13eb7b3e6a77467dfa8b97f
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-fingerprinting-track-digest256.vlpset
binary
MD5: fa7667eeed0b53973506278ece958e62
SHA256: 0d55a21e6694fce19f366f9e5351a02d215d378541dbc38df68645b63b56d8bf
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.vlpset
binary
MD5: 0c0d67875bd75a0227c02dd8529ba01a
SHA256: 614be0169ec36e67223eb9645a98da66dbfde5dfbb89bb064f428aaeabdd9d97
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.vlpset
binary
MD5: 130b9ac2beec5ada274561105d81ae36
SHA256: 7d99fec08182a5b95d18d1569edaa2c60c2aafbd15a56d8882f22f3b395e6460
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.vlpset
binary
MD5: c2994d388f8780c87d35c352d9582985
SHA256: 7ed09f7d2bd632f70077a4ae4f2bd2f3fb654b03cd72652f51678b0c7d027f25
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.sbstore
binary
MD5: d5d6b4d59b4ae4e2de4b40d0da083571
SHA256: 000e3a78c72a210ca3b5417a3cdd294fbce2a31661601c9d594c75cf2800571c
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-cryptomining-track-digest256.sbstore
binary
MD5: d6c5c2e242df3ec5ff8e17dd8ee15f73
SHA256: f0c6512e42f2732b3aa401f9ab4df84c0a89c9755968b158796706a48b9f492a
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstore
binary
MD5: 9f6b331aa1e070dcfeed473e76ce56c3
SHA256: 7dbbea2dd387eeb85e1f56e02fc9989acde570cd43bfef2c2a827093ba87da6d
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.vlpset
binary
MD5: 7194b6bff691a056852a51e2e06ce8fe
SHA256: cbe2dc6abfe25bead60f4dfaf419fc0f441ff8a8dd4a2febf5553be1cbd90c49
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore
binary
MD5: dd0458514c9a922b45da6a8bebe47320
SHA256: d27d5b27030f4725249377951beb89e84a90a0e8241f0d5fd80ea59c1606e761
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\analytics-track-digest256.vlpset
binary
MD5: 1e1c0442f3fe16b185d5db74f0e91fce
SHA256: 43acc2d047c7988e9073ecf32ac619de0d080c45b061d441d1d671d305bb4f08
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google-trackwhite-digest256.vlpset
binary
MD5: e54e5b84194eee15e64d2a03f1136bb7
SHA256: 07707b589be3dba3bb0bdac67760a2b180ea3531e9d7976b73e4c1d8df9dbb1e
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.sbstore
binary
MD5: dd0458514c9a922b45da6a8bebe47320
SHA256: d27d5b27030f4725249377951beb89e84a90a0e8241f0d5fd80ea59c1606e761
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
binary
MD5: 92a93e4c81027f5788873296c6e2875b
SHA256: 4358b8f0af157cf2ef36a3a8bd152a528d32cfe98a2e0ae66207dbdb1d943efa
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.vlpset
binary
MD5: de0d88480c24350c59e1e9a3583de0d1
SHA256: 01ba9f0b913e04ed10bd7166796483dd4f72005f249d6ee68b12117be4b5d3c7
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.vlpset
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\content-track-digest256.sbstore
binary
MD5: 2be5027a476efb5fe011ae8257e6b428
SHA256: 26d0ef7103dbc0516add2da8029ca43567b98bda1ef8d8e4cda42f09aa9a4b36
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google-trackwhite-digest256.sbstore
binary
MD5: fec9bc354a7ee92c6feefe63e6b0fa26
SHA256: 258ef8e6994a09ffb54bd0d5afec97c13c31f2eefb7fe90a2a4c487c87817519
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\content-track-digest256.vlpset
binary
MD5: 897401403f6a9bbc2727bf8acfa8bbaf
SHA256: 75157865105c44c1220c337aeff723e7b2e4aef506ce7db00e2621d5ceaf45b8
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.vlpset
binary
MD5: c8663695a49bb5fb5a301d1a7233db6c
SHA256: 498d10d381ed91be12cff65292813bcccd676176bcf614534ab7ba0e5536306e
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\analytics-track-digest256.sbstore
binary
MD5: ae706abfaecfd90d67e5c965091e004e
SHA256: 13cbf8a5389a33a562e6dd10660f68e8964313536a109aa80acfd8838bf45e73
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache.bin
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.vlpset
binary
MD5: fcc9c2c9b611a3264b68ebe180eb4248
SHA256: 6ecd378a537eefe350b45cfa353741383f407d99d776bf23155a7825dc5dd2bc
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\ads-track-digest256.sbstore
binary
MD5: a03e51212ad01cfe7eb3a87c8ce51744
SHA256: 2328a7569ab3d1e0c8638282e09860c82db28edd1c1be75caad91fc7015e966c
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\ads-track-digest256.vlpset
binary
MD5: 38f55098ab1772e8a7b90a05cb33cfae
SHA256: fd44a8121e20cf102d8fd79d6ee45d55ccb0d92893907091bb7587ed3b274244
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-track-digest256.vlpset
binary
MD5: e1edde17e24b61c5b26d7b76ba039463
SHA256: c2c4612b7b9545751f37b302ee345abd0f22170c7cc2497320897b385d508b7f
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
binary
MD5: 0cbc03fc33bcab8a56bcbf1cc6931de5
SHA256: 2c3680e9b5de6c7d3e231af3945cc4b594e5ca36767412c491ad13ae31a841a6
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-track-digest256.sbstore
binary
MD5: 59d2d3a9ff42621ae974078bcaabd9bc
SHA256: 7371e8534c31c4bff73e340413d77c988593a0e559418b0f2a5b34b9c82dddd2
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.sbstore
binary
MD5: 519beb1b01fc355bb388f1f75be997fd
SHA256: ffe2d3077b81ae6f51b220c1c661b276c823fa67dad1d64fc5f17249fc54bdc0
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
binary
MD5: e4c0161f5c5527257f6063cef20fb010
SHA256: 6d10f61bf7744751e69c38b7b6873f54cafc4bf57e758a86b79db0a3ae98422e
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto-1.vlpset
––
MD5:  ––
SHA256:  ––
4004
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
binary
MD5: 355f1c82cfc562f3984f8af46b4f2d9f
SHA256: 34e27870f13f027bca44945b3f7c6b66c88d64ab04306f33977ca72500a12b2c
4004