Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Troldesh"
- * MalScore: 10.0
- * File Name: "Exes_c0f13af742d0ae1bd04715a5af96a169.jpg"
- * File Size: 1041584
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "8c49f3d3b3471c81f886b8d81a2ca71de06ef7000c080b200a46d8433ed3c2cb"
- * MD5: "c0f13af742d0ae1bd04715a5af96a169"
- * SHA1: "ee70dc9586ca2dd1397ac1149aaec39d430616a9"
- * SHA512: "4d04fb59b14f35f1a1343fc6a58622bd84e66868fa14a1ad0562894119c2a17ad20a1f5193a7cd4fcbd4617d676bdc7e3811c4d6d3604e51406899cb4cbe0f3a"
- * CRC32: "DDDFAEA0"
- * SSDEEP: "24576:uFi/7TbYcDa6BSSEkmfSRmjNr0HmO0g9miDnP9GArYJLq:uFq7TajSENNO79FDPzrYFq"
- * Process Execution:
- "Exes_c0f13af742d0ae1bd04715a5af96a169.jpg",
- "vssadmin.exe",
- "vssadmin.exe",
- "vssadmin.exe",
- "cmd.exe",
- "chcp.com"
- * Executed Commands:
- "C:\\Windows\\system32\\vssadmin.exe List Shadows",
- "C:\\Windows\\system32\\vssadmin.exe Delete Shadows /All /Quiet",
- "C:\\Windows\\system32\\cmd.exe",
- "chcp"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (9 unique times)",
- "Details":
- "IP": "127.0.0.1:53857"
- "IP": "139.162.35.90:9001"
- "IP": "131.188.40.189:443"
- "IP": "104.18.35.131:80"
- "IP": "51.75.144.68:443"
- "IP": "95.153.31.8:443"
- "IP": "176.9.39.218:9001"
- "IP": "104.16.155.36:80"
- "IP": "171.25.193.9:80"
- "Description": "Starts servers listening on 127.0.0.1:53857",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_c0f13af742d0ae1bd04715a5af96a169.jpg, pid: 1644, offset: 0x00000000, length: 0x000fe4b0"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://whatismyipaddress.com/"
- "url": "http://whatsmyip.net/"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rdata, entropy: 7.99, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x000d8a00, virtual_size: 0x000d89b6"
- "Description": "Looks up the external IP address",
- "Details":
- "domain": "whatismyipaddress.com"
- "Description": "Attempts to delete volume shadow copies",
- "Details":
- "Description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
- "Details":
- "regkeyval": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\sh1"
- "Description": "Installs Tor on the infected machine",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem"
- "data": "\"C:\\ProgramData\\Windows\\csrss.exe\""
- "Description": "Exhibits possible ransomware file modification behavior",
- "Details":
- "file_modifications": "Performs 317 file moves indicative of a potential file encryption process"
- "drops_unknown_mimetypes": "Drops 300 unknown file mime types which may be indicative of encrypted files being written back to disk"
- "appends_new_extension": "Appends a new file extension to multiple modified files"
- "new_appended_file_extension": ".crypted000007"
- "Description": "Collects information about installed applications",
- "Details":
- "Program": "Google Update Helper"
- "Program": "Microsoft Excel MUI 2013"
- "Program": "Microsoft Outlook MUI 2013"
- "Program": "Google Chrome"
- "Program": "Adobe Flash Player 29 NPAPI"
- "Program": "Adobe Flash Player 29 ActiveX"
- "Program": "Microsoft DCF MUI 2013"
- "Program": "Microsoft Access MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- "Program": "Adobe Acrobat Reader DC"
- "Program": "Microsoft Publisher MUI 2013"
- "Program": "Microsoft Office Shared MUI 2013"
- "Program": "Microsoft Office OSM MUI 2013"
- "Program": "Microsoft InfoPath MUI 2013"
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- "Program": "Microsoft Word MUI 2013"
- "Program": "Microsoft OneDrive"
- "Program": "Microsoft Groove MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- "Program": "Microsoft Office OSM UX MUI 2013"
- "Program": "Java Auto Updater"
- "Program": "Microsoft PowerPoint MUI 2013"
- "Program": "Microsoft Office Professional Plus 2013"
- "Program": "Adobe Refresh Manager"
- "Program": "Microsoft Office Proofing 2013"
- "Program": "Microsoft Lync MUI 2013"
- "Program": "Microsoft OneNote MUI 2013"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\ProgramData\\Windows\\"
- "Description": "Attempts to identify installed AV products by installation directory",
- "Details":
- "Description": "File has been identified by 43 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.32261320"
- "FireEye": "Generic.mg.c0f13af742d0ae1b"
- "McAfee": "GenericRXII-JX!C0F13AF742D0"
- "Cylance": "Unsafe"
- "Alibaba": "Trojan:Win32/Fsysna.adc7f4ed"
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- "Arcabit": "Trojan.Generic.D1EC44C8"
- "Invincea": "heuristic"
- "F-Prot": "W32/Emotet.TZ.gen!Eldorado"
- "Symantec": "Packed.Generic.459"
- "APEX": "Malicious"
- "Avast": "Win32:RansomX-gen Ransom"
- "Kaspersky": "Trojan.Win32.Fsysna.fowd"
- "BitDefender": "Trojan.GenericKD.32261320"
- "Paloalto": "generic.ml"
- "AegisLab": "Trojan.Win32.Malicious.4!c"
- "Endgame": "malicious (high confidence)"
- "Emsisoft": "Trojan-Ransom.Shade (A)"
- "DrWeb": "Trojan.DownLoader30.7829"
- "TrendMicro": "TROJ_FRS.VSNW0FH19"
- "McAfee-GW-Edition": "Artemis!Trojan"
- "Trapmine": "malicious.moderate.ml.score"
- "Sophos": "Mal/Generic-S"
- "Cyren": "W32/Emotet.TZ.gen!Eldorado"
- "Jiangmin": "NetTool.TorJok.ec"
- "Antiy-AVL": "Trojan/Win32.AGeneric"
- "Microsoft": "Trojan:Win32/Occamy.B"
- "ZoneAlarm": "Trojan.Win32.Fsysna.fowd"
- "GData": "Trojan.GenericKD.32261320"
- "AhnLab-V3": "Trojan/Win32.Kryptik.R287145"
- "Acronis": "suspicious"
- "VBA32": "Malware-Cryptor.Kirgudu"
- "Ad-Aware": "Trojan.GenericKD.32261320"
- "ESET-NOD32": "a variant of Win32/Kryptik.GLWT"
- "TrendMicro-HouseCall": "TrojanSpy.Win32.TRICKBOT.SMB.hp"
- "Rising": "Trojan.Generic@ML.100 (RDML:Iq1QrJvnG9elOOqgXA45cA)"
- "Ikarus": "Trojan.Win32.Crypt"
- "eGambit": "PE.Heur.InvalidSig"
- "Fortinet": "W32/Kryptik.GLWT!tr"
- "AVG": "Win32:RansomX-gen Ransom"
- "Cybereason": "malicious.586ca2"
- "Panda": "Trj/GdSda.A"
- "Qihoo-360": "Win32/Trojan.be7"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\ProgramData\\Windows\\csrss.exe"
- "Description": "Harvests information related to installed mail clients",
- "Details":
- "file": "C:\\Users\\user\\Documents\\Outlook Files\\Outlook.pst"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 212"
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 144"
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 193"
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 525"
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 130"
- "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 720"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "\\??\\PIPE\\wkssvc",
- "C:\\ProgramData\\Windows\\csrss.exe",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\lock",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdescs.new",
- "C:\\README1.txt",
- "C:\\README2.txt",
- "C:\\README3.txt",
- "C:\\README4.txt",
- "C:\\README5.txt",
- "C:\\README6.txt",
- "C:\\README7.txt",
- "C:\\README8.txt",
- "C:\\README9.txt",
- "C:\\README10.txt",
- "C:\\Users\\user\\Pictures\\Host.zip",
- "C:\\Users\\user\\Pictures\\+ICLjsuXHmoLQmwe3YbeQTTDnXQRB+MQMa+7x1+Tmtw=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.xls",
- "C:\\Users\\user\\Pictures\\XUWZgBgUx7W7YRekWw20TzV4JqUeh0DEaYClfkbAp5w=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.pptx",
- "C:\\Users\\user\\Pictures\\w5WAxTTA2lv2hjP3trp2dvJ4UeKR86pint9FN6s9acw=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.ppt",
- "C:\\Users\\user\\Pictures\\Rprw4mtGRk-YE18AIWWFfgmNEsW96TSFvm0TBGTuXW4=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.pdf",
- "C:\\Users\\user\\Pictures\\nDKhLxTFbQDplrli9edpx2O-ZvKEYIdPi97WkkhBcoE=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.jpg",
- "C:\\Users\\user\\Pictures\\ZqXo1fB1ENivjtRdX1s8YSWIVLzwLoLeLMnMOnvd4wg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.html",
- "C:\\Users\\user\\Pictures\\N+86aIQ7wD0uEhLD3ro+YyXZrFszSIR-7CDJvJivLAM=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.gif",
- "C:\\Users\\user\\Pictures\\q4PpLbBNhTxLytKO4JPXR68J0dCktPlGC6i8pYGzmXE=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\Host.doc",
- "C:\\Users\\user\\Pictures\\sPkOV-qLSPPq36JYmngayXeEOn8bxj3+SFFew6wn1K0=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\.xls",
- "C:\\Users\\user\\Pictures\\IXbwFLEfN-MRHeuiC3GQfw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\.jpg",
- "C:\\Users\\user\\Pictures\\IwYQTYLqfkPUYgdz0v2YrA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\.html",
- "C:\\Users\\user\\Pictures\\g0Ilecu-p9tMWnAb-v9oNg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\.doc",
- "C:\\Users\\user\\Pictures\\RLVuUd+Ze+DUTePQ-AcUtg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\Pictures\\.bmp",
- "C:\\Users\\user\\Pictures\\8gxBeg7VWTcHDE8L63QoAQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\userDefinedLang-markdown.default.modern.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\mvEWxuwyACt7oxp4dviicHKk4YGED9MYHTPcDdZ4H2O10NQiwrAULPmu2qKueIHA7P43JxKj9BFsht+gTYisU4BxWJyI9FZsbr6DLjb+DxU9V7DnvkKfOUdc6poMoNr-.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Zenburn.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\M2OY8M10cHUk+cbfKKDbXyP6ywkkrtTulBq8LbYUAs4=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\vim Dark Blue.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\F++hNFHXorvDYGxfsTHrCqt8aXQYzaLeBEYxJYotlJcllrxPXe4w0o17ZdfBSyAB.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Vibrant Ink.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Lcos3MO+-dc0Bhn7djG7aqgQrIt3n6a3FJ4vpe2HvxI=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Twilight.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\-2xRNXN9N-ziPt3+GgcFRWygXLbyOM9TwkHAO2Udsic=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\d-ZlhwRoxcNHdfIZbs5RaC9jFhnRFFEypIGxi-qT8nc=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized-light.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\S5hsQFR9RpadDexqy5h+ciTk-RYmAKDv3opFdoxUo1uDp3CJOEXg0eO5DZRvRD0P.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Ruby Blue.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\PAEcAh4rmu6yUeAhARVDb98LHHz4prlzPngpIpr3Sbo=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Plastic Code Wrap.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\0knyxG-gwy4XshQcJLA19mcZAonxE67yp1s0Xc-MD2vHYoTI0PyEx9q2eXfh90re.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Obsidian.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\z-OPfGNukhrwyo9xg-0T6ajxQBe7w4Y4qnLXt-syaHk=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Navajo.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\D3hK2SW28eTMT0FdfBRpD+3DKhauozFfUdMRm4TInVQ=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\MossyLawn.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\RBzoHvtBbUdrC0KtIJSHZsdw1WRFGEE-LEHR5JfuhXg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Monokai.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\F+dtZB8+ARURa+sS3CYYGNmaWgTKyWwYmD6huLTIYwg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Mono Industrial.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\vESkTWsPei7paLTSxkNBrwqIdkfGVyevfaecIy4MYfNcIzeIbBPVsA4nJtlh-czN.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\khaki.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\bATOmcRR-K-O9GzTO1QXrHBoquNqo1E0ot2fwJWJdQQ=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\HotFudgeSundae.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\+tos7nTl9+6ih0E9YWQu+h7vf82akI2fnppdV3PYKndVJcbRN-6OpK+z7BIg8zJw.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Hello Kitty.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\u4zGbtFLlrk+2sfHdT1otbEYCPN+Bw8Q1zyPZkEGoZ8=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Deep Black.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\RGrjfPMSbrx3tNy73X113dntE57uW6-LTCxFwmAK-mY=.C30C4DA81AE308962B9A.crypted000007",
- "\\Device\\NamedPipe",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Choco.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\ULClB4EcWCPhefppcT+NnzAwGDkV1KVejW9DMqPAigw=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Black board.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\kp24q5iaoJ0BstX1QwfH10SOSJUOOtJuiRcAUb4g5Yw=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Bespin.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\2n20zSOA1xW+OZVz+9u+B+6BB+2ynugDXlh-Uqf-Vk4=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\converter.ini",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\zM0ly1J1wJnssrXg8X2uzNAFWJlig6u0YsQISD2BekE=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\stylers.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\JtE2ayhHxPADb7u3oVIzIPmtqLrnJW3vHLmpEDR3S6A=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\shortcuts.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\jAMFq0bhaCxXdZWxzXbFIESR7XjCWMtp5c1TtCRUW6w=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\session.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\SWhZ9AmisVh4VOppQIApjldOw3DteJEZYsJ6ebRMA7U=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\langs.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\3f3sgBRbFR7fbwYz5zQACWfEwZ6CWoWOE2+1zlCkUME=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\functionList.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\f2KB7zNqem1TjZ5zwmaE-sF3DJn3lNOrWftNYWPsBow=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\contextMenu.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\MBBrmkz4aljBZDHZ-WkMpnm6sTpSpmzhBw2HjhqOj9w=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\config.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\dwnS6WRAQsh3l5M8jrGDbTqWHUcz6aGqM0rVrGwHZ1E=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\UProof\\CUSTOM.DIC",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\UProof\\X9UXsob5QXzmBo0TQ01jE5vQiJoIemkatCbnjz-k85g=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM03998159fn=Insight.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\wWMXjAY7P+qbXupoieZOLgG+x5O0ZwGBDjyHYKqQ2WON6L2Wbxi+T60ekcNozr7CXeMb3ME-Ye4lFUYFiittJQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM03998158fn=Element.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\uXFvwxQN3vetcweQ4WB02RXmVKXj3RGkqgvpyTnleb6Lx1XOlHHGa470UGbadkMl55WnC+RQwe16EmBwTgqgAw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM02835233fn=Text Sidebar (Annual Report Red and Black design).docx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\YtR0C3yYYHkwTlJjxRWeXNYPVjWxvUI2YjT9KiN4aE9SNjtUuF2CVyXuHKNmsSg3uqmKkQWrfPeD1Iv95ln-Skgr3MOtdYIH1o57QVesFxD2OIbss3K-0TnGScvQO5l7366Xtq4+0MkwhC4xDEPyuJSol35Vs2GzTawFnVL85tCMgQ6drViECZw84xLAsW8D.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM01840907fn=Equations.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\FE5rlQg4qbum-MIFn3J8EeBjLQxfHvjGwIwOk5+PWYDZkpY+8TzYHKASU2lQ4c+-yVzRUfTTxPUETDnsw79E-g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851227fn=sist02.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\3EZcUrbHWZPxX8iPz+8wer6lG2hWVGD7ov4zs2NChpmalRdOWTwLeUjlLEeCffaKGVi4xpAykXOORF2G1TIIBg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851226fn=turabian.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\sEGGNkwfGrNgOvQdFiB2ZhKYtyDK9cDBEIczH+BebfDZUH97PlLbPw+WgQwLxAc-gxvxgPTrIt9Lh-wkY6f9fQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851225fn=mlaseventheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\5drWc+7yySaNWbPipIX0Gq4NvjUdNv3j0X0RelNGlKMB+93Y4iqilKYYBOZlecVgii0uUINcHCyzP4CIPPQdWet6EszT5DWee9ITGXEsNt5i0j2jCcdc+rjHTm67cxV5m9z6EjpOXXLBXAJNHdMn5w==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851224fn=iso690nmerical.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\VE8k5MS93ud-bf1pF+UAOPOBbQj9nZ8JIzs6EPhPenVaq07kkCp5yvSNKYWyv8Ygvyown8Y+bF7c76MMj1qQmJXr3KD0CVDaP96QyD9vvug=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851223fn=iso690.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\B0kYn-0fGxKlm6bzNz1f2O4+jvzHyAeONTAbG0NlqEjtb+8fQHbmVTywlRZVdMFW5sX6WtBXnWn3ijXCH9u9VA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851222fn=ieee2006officeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\mSzhr-XPA1Mnt3jDty4A2BNaxpcDAIBwznbiVTvnf5Kgr5Nnj6hoCfchlSsQEBtHc-llBz6KUKenA9hwSU4M9AxS2yWLeKpBiMnCOOMyDdxTsNAnqI2ePDS7i2b+L+ZV.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851221fn=harvardanglia2008officeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\x76EGAklDARhV0Iv4t467sYajJax-Ils65mJXfefVRrqCEviwZEPdpPpPsmmM9KZydPsH-+8+ASII6e6-s9tt9IGZ10RLZJ+9Fra2sTD70gJ7IJQMH18qQP9CiUH6pTFqBO-e9Wkjrsv9iR-iWKR6Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851220fn=gosttitle.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\knFyzo52MPMvkD60RHAbfqkYCuHUC0ujbmIdmK9iTInVqsbLlbNfoWpwsf7956GTcfIFXbrsMYaAuSe7Aw+KDg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851219fn=gostname.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\2DxoaV0vnUrRefcWv5D4RkYJQCW3S3EjkAX24aiWNswtJkdw1EE0ZvJ0U4b5MOw0mZq0UHSgasDLP4XVHdgbbw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851218fn=gb.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\aYRojpbTOtoL4PhgOfPAklFEFhdnLq8lvhYSrtYDgXiHdfyDkJgMMqXr+VBt4B1b.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851217fn=chicago.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\IwIkeSEaoC1K-FzBtDrILnFK8yXrYbze9IiJfiZM0ztVtOnELKn06NE3KyVxYOMEFfQ7UiBPxmLL5nzAFVJWlA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851216fn=apasixtheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\PCqioszYQ0AjyjyK05TYQVxzXvmaXskKtOmcfQvXRLo8-NkDnTWr0x+Bs4mJLMVBLADDWFrKg-Idx0SYT30PvjRuAjv24xwpj7CEJnv8niC7s2gXdl6VlL18lrPDcrWz.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001115fn=Parcel.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\BlQP4OSgJkOQ2vITV27B67mTo7BCAvnBWrPCcrHOQicfYj0jeMct7PZKOwQLNdBYTp8FxFNzqv7B45aCvAWW4Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001114fn=Gallery.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\hrYFRgnazPOVapujQNf4EIF12WC7di3-CcVoKIcRQVwsbTOfkhfqHyE7Q2IF5NsqU-q0MH1cmJ9sEx7de2W7qw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001106fn=Badge.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\j8mmfU65-sWuKuSv2mdqfnzJx22Bn1PP1zRPSj8rdmZZBPngmGysrQMmkuAvx8XKvPKLlCxIQ9or5qTjxFQ6Mg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001105fn=Crop.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\4ExmPqubBstG3MXeOzPn1XmGYKlsaztYNiXNXNju-MS90AV8pR8hs+gY+9Uz87Rrqat1a1BC74igHhWn3XJ1XQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001104fn=Feathered.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\oxEQCWLV6xpWuppq818yqxKIDfGLaSRxhy6KgkL3FhohjP0pj9ToTQEupDV2qr4ZQX6udMIxxLh1qpvjBfnNKQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001103fn=Headlines.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\BR96-yhizvG8FZ7jQaASpticS3MyVQalRqisU4-ioONmvnYxmklQUmj3xzYFTJrgeUjIZcNyUXex5SpMmzdt0w==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033937fn=Vapor Trail.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\1gMr1c81ojNmvsY8qThtDtiTFc9niTGhBQ4wXm+W+iR6powUxjJfBdJYUO8-1GXb4LLzcauePKV3ZjUwMECJo7nx-b2L+4BqcGF8tw+yeDw=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033929fn=Slate.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\aH-V1vIXHw5fak73oFjJTLFSD38LmuS6CUt4V+GnIV+hpSZIp9pqwNiOUcDEmzLgN3OsbJPm2fwMVS+NupwxqA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033927fn=Main Event.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\kDKOhIB9YTFmBQfnKqc4FoTJLq2D85Z63oBp4yXiUJU4QIkQAITnR239++1FIeWvMAZnRNoMV5RAAtmN8S0AUg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033925fn=Droplet.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\2U7PSf9c-+tnV9sfBgbjQmrfq-77Fc1PsIHnxjtUKXtxeYkQdq2rV-5xJpzwoZ1i-9eICiedMThe0n4yoqgziQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033921fn=Damask.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\MaWq7+GeAMbNtw1W3uEiBjQ6qaIoOepy9xalxlg7bfOdJ01vZx1W7KtELZ6Ql+OQ94RSdntRnQlDWByiYpXxCQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033919fn=Circuit.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\SvZfzR4gU9XagVt3coVYS7XG9cdoOtzFtgTvuAXToINxUZcwB8UEo9skucjZjlYUVoBrB-Yw3xGVYhREcPf8pA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033917fn=Berlin.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\ZWodZpx8s6BWyBac1o85i2VfR0ajiIfRvZ5cWVtzyqZmDX7UhqBsBVRiaawZjxN7zCgu3wuMS0ziQPXGRwcXyg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457515fn=View.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\NkWT36EbEjTGgUmMd2IKekFtQ4RD-QEhn+YXBZnwjJrWC2B3CQrAm-yid-OeUv447Gkx4kbeucVo3UdX6HU93g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457510fn=Savon.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\3OPH3gNiE4Aqro+KKMFRVXpURmr5tYLTWKafIElRo+W2CoJ+Rj--06YVEPrkeeuBtVaajw09RDeN1VLVR-hAtA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457503fn=Quotable.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\Yxq5GI6KIvkLIKog7NZnf56tfu1ijwgVGK8YX+1Bh0UHmS+bC2Lj1RxzKGxqvWrM1Uh7L4VA0R-Qudkb7gWsPg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457496fn=Parallax.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\l+YaA+BTfTAWY5S6Eiaj8Vh-IdN+KG3VVY+NCwN5JeKi3lBlvJw+-Iun2n+SZ1-edmie3jcAxQhWmtTm3PxkAg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457491fn=Metropolitan.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\BYTJfQRcSAW2xi9xodOVpJl1uiO+YvqQQ8jsAYzNwqFaILPSQYOE5L2mhru9Xu0-8vXugkJG470moTRKM8Ohl3t1QmuF44cDZMcF27s3e34=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457485fn=Mesh.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\tvjYQnXMstm+1jyG-y1D8BynJ8BfmrWdANfVfSCOlYrjEYfaaiB9fXaSVjWaxXuhsOn4KaQ-P1nvagIAiy1GjA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457475fn=Frame.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\otq7Wcnv0mP6pUBJaipj1o1rOuuDUODIHyKUGPkIGsfyLRGUM8HiofHAojKCjlgq9ApejJOOwDN0esbgk6pv2g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457464fn=Dividend.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\PFG1GbscnHVaLtYnKcI2zBvU2hn8RFRNJYJ7pHIzs03dUG+VEmvUGWwWUd++Ek2jqBu+WlOmwkX7o9PNuojKwQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457444fn=Basis.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\2OXM2JXClUDfTewbsPlnHeRPGRlFb7VLZHb4nT712ZgcHcXpZ54v38CdaG1GtlBAjm1WLzcwEP2MmBkgEVrOKA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03090434fn=Wood Type.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\J8nVkGMHjqtYALovFXBlASXXlCe9dmoNKWOtaHX1caQqy7fc2kwPISMs+AgLZZ4WN0z2Rin1fJQPBWEsP1t+8g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03090430fn=Banded.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\ZUBrqrfhfbisSRYsTSrnO2zxQa0dyLfNLA1S8QjASSdS282ps3IEAx4u3NDfNsEEt-iCvJbaz3Skqg5m9wABxw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\Welcome to Word.docx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\uHma73bPMD7krDceSthNeH5NRnzCfIz4l-zAGF0FUso5qimsqaTxua2z84VSWClr.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\NormalPre.dotm",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\3tbxwb3KK1M5J-JDRtsnTQ78tT4lEXjkT++CkS2BW7w=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\Normal.dotm",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\2GjEvrZeLnMhuaoUAn+xn3pFZ8ERQNZIqDk1nY5nsfc=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Outlook\\Outlook.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Outlook\\nlAM-GVaLAoS45B-WKCMqtx3gkrLnlbOGu-oqESZNXo=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\Preferences.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\bP+JDMRKb+1V7JU9EnFqS1D61bahJSJ3a7C524Wix9c=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Office\\Recent\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Office\\Recent\\fguJpYbpZ9K1RJXcgGQtcNWe9wU2TXNzCjLjzXa3rBc=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\Built-In Building Blocks.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\BUSETakwhsh0U3wSXX+ovTv5RIaPLJ95aE5EWrGRMdDj2kx0T3+Urg31s6wcRSyZBNucu093CXFoXnOTECoE5w==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\15\\Built-In Building Blocks.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\15\\qcIiJROXBmY5CAf9RW5f3FKBU3VsTVRtn8SO3hQTAGltmeRluDA-KUCwNvQOd5DzirWFfCFmDGRz6kfVnfBbYg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\TURABIAN.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\+xFfG8Jt8c0lEbtc0uW8J+bybIBL2kH2KvUe9oYOo28=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\SIST02.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\6XvLh5X8rqdskfqcFrUV0uJoVWE0Iba4GrpCVhW6MdE=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\MLASeventhEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\oWQ+RKnV8p+IXkkheQ53FQgPPPRmL73aDKo0z19lJoPQMHI4mI97TtauVQMUiEvC5vFVskU1DrF3hWhGtmtp2v-ifPeGS6FvU8op83aVlEg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\ISO690Nmerical.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\wdN9+wvN5IA2u-o7OizRgY7ZJYB0G-AESs9-hFPBoW1EhP2NeOYfkPrCCidgR1OP.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\ISO690.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\t9DESv9+KbevaWqxe-BL9OVjUf-uYgPkCaE5J1JnnHg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\IEEE2006OfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\Le9yWqjDMT57HZvIPVgqjHd28ps+cKP0wqFN5GtjzQyM85b1mXUI3tEimAbKdni1.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\HarvardAnglia2008OfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\Y4CImabH3bq1ulNso1qPiQr4kKnBfb4jWxhN-IAX5xK3RVaWQt4n-jUfLnb1YotdkcCtQBpwa3FqurfLQwDtMqNde55g8oHfN-emivFHPts=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GostTitle.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\-WOHlz3BGG-ElTScunvSzPs9CtsuCjmV9-UzeH5d1Zg=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GostName.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\lXfeAkz78cC-AtrSNXnzE0oU3aksm9M+xevOO8ddABY=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GB.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\s25fP4BxstvHfZwb6MD7-g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\CHICAGO.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\tAGI9YzhUNHg2bXdgDKM8OgWfiT-7CPW5lVZbR9Kefs=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\APASixthEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\uwQ2k-TtJd4bJF4tmpkMyWYtg5zERcQXmsFUKVWyGzFVR8H8Qj96dE-ET-WrqazzpwaTS5C03L5IK8pXQcCU0Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAF.tmp\\Text Sidebar (Annual Report Red and Black design).docx",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAF.tmp\\RvWKt7DJxwlWiLTOtQPQtFXs7lLoU2QBFjiQaCDhVFzbOHGbG33pyBg2u2dVaMr+iSvBcx62xUlMNRa7Q+rF10BzNQAQN4ouRJP0XAA1KE2qaqNGpnspZUCLiz8Nbrj-GVLd41bugJksY+YQGT3yQw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFF13.tmp\\APASixthEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFF13.tmp\\x4QlHLKN6GavyifSd+khNo30fkeVVE1okOeKpLtQMz2n51gps8c69gyaX9njQfy8dnL3NE3CG3gPnH3jV3A35Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB4.tmp\\harvardanglia2008officeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB4.tmp\\MabInP9hBTUcWlfqquNx1P51WXLF-DTTI+jfob0AbytPjGN48CdkVW-lFAWUcfdCaxWkfQ1ZzlEIxV0JzlLhg6b65Lxlm-X21br4uGkFRQk=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB3.tmp\\turabian.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB3.tmp\\dx8ZOxuaCvs+YCaqqlELDvXOZxEel8pfqaIbNUAbMNU=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDE2.tmp\\gosttitle.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDE2.tmp\\TRHJC0RpJU6wHzRU98gS5IlKvk9qxSISiJsN1bU+NHU=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC2.tmp\\chicago.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC2.tmp\\P8GfHYmYmr5lQF+mOiqfXyhSLr94QO9iwRZXCOqg8EY=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC1.tmp\\mlaseventheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC1.tmp\\6uIx83epMFmPDgW0vheeQK13w8tobq+lHVWzm-J7kMuqrZIDy5QCh9J18jh7rqagQ6QugCxMKCaK20WN2Ebc1-h+zhiVhJlfUG-BKvFRYsE=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC0.tmp\\gostname.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC0.tmp\\QOxt6sglFjEcNRdrLwteo9HYzRL5Lqao8kauk0LqdQU=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAE.tmp\\iso690.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAE.tmp\\u8fFbu9UmYMEK20oy1WlACwDtpaCB35Ip9IgRCbXO3k=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAD.tmp\\ieee2006officeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAD.tmp\\jaQH26wxxnQioiU1LcvAgUgYvvoMKhUlp1EcAqPXu08NkKBXE15wfdTBneBRaMMI.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9D.tmp\\gb.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9D.tmp\\0flEgvtAPUEoMA0RVaWjwg==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9C.tmp\\iso690nmerical.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9C.tmp\\KGiMWtRtNnhzJSAlDIo9bwrIU1cn-y4f4IE-riIy-YA4cG+UKKCf7ZS2Ny3THjQh.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD8B.tmp\\sist02.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD8B.tmp\\3854yJhfkZ5PZV6JjZnoghLYobBw3Ob6iJs5d3hCELM=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\scoped_dir1924_4570\\CRX_INSTALL\\manifest.json",
- "C:\\Users\\user\\AppData\\Local\\Temp\\scoped_dir1924_4570\\CRX_INSTALL\\KkX+UONjARcAyVPKTQI5NwJUGNbsY4J-c9uhBAOXpIM=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\outlook logging\\firstrun.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\outlook logging\\Ma2pisUw19jEjoRE3-Zdgj+dbrttXWH+SmGuVyU01A0=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1904.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\wAZdCNaWuc0HdSsgZS3ZE5lkhRI-aEK0i1sCTf8IdaMGh8UsAbEMlwr9jbOvWKL+FlFBu3shizIptRgPb8Mmzw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1834.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TMAPDd6mZlQnlUloFQVU40vKInhFmzCi+ErBbPzdBjHwA5Twi98R9Re2TcRh1HkiIpKKfdQyDYhKaOm0hsFz2g==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1450a.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\KHYr2KU3WVOxFTXp3NlLtc7dffZFuU7GqG50tq-8OFAn55+EsSy4DgVVxnG7eg6+ND69H9PNxZJL6WXJkxAo9A==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1450.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cr1MBGsJCZoC+WCXv8nPNA2KadzZIRrxAfMVx4Y6oPO6upzcnYyr20NR1LQIX97Z+UAu00bU1rExEBNxL2P0uw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1449.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\sVkXVmlVei0bgVf+vRqHLiPwGPtqmo0-TCJBdJuodB0MtsGl5FaNUSz1b4s2oe70QbP-9Fg-+BV0Lm9ka1AaLQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\user.bmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2oByQkGpHs+XeQfeRBoD1Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\GaNyrhEY5a6+sNyziBfawGgQT99K-mx3fnSUGYLeYIXeRzgbajWc+dFF+x546lZ2Tp2gcjFpYgQfxbgVIavatbvYcKvbuRvXeIFU67kMWbLALu3O1mtgFYxlG6zx481wL6eotrnfm82Uejdzv+BmbsXLI-OrbnRajBOIsijcmJs=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\FUoFCVn1w5bKjH+PfwJ00zo1Wh9dfwNvb2RfNmSd5z38pjBvbBdK-wzHiWlhvpqhlExhw6ndwnX-Z6hc7vTK0Fu5JPmLli3K+SxAIZIZqGSHLL4Yo-kuAK9K7Qborqb7AAQdM4N1EAAGKoqdqX8OV9EQjCqPkOPRdD3Dl5NjxHc=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cd5s7wH0Z-vUviPAQlBTdpAurtM8R6cqTyL2yYrURwF1HoCN1TX0h+eOZ2+7GEdq+UV53rPN5fjRgJU6nOB8iqy1ViJqf44YJkgaR3TSmGdlIQEwtisS5I-v8A0XlnT4OHeBg+AF+ONGvsnL88UqBiBJVQZ1vPmpMbw+noZeqSY=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ul22I80tXTA1ZFeIUkD8Ow4GOdeUZq9pvbzQd33kSeQS5Y7dle5PneIyRnypTYjx-yVCPMO0B3vs0MZOlyHQ3Sw10kXrNS8e2IV9aDaCkoLjuq57VQl85fb5Qpb6IPBU2Z6nPGf3YSFD7R4aDGQZ4LJaa1YhETYcnYuA7vIa9I0=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cy8CY6AeGJ0pAWYXPl4KIS7jNE0Xh9yiWzC57UeYTpSpDBtjkgLFTX72qsqiX1+YhfKuzhOh-mgnqP7fitgHyQQGjM8Ghs5meKT3wyZDHIHxwsF23pGzH7wvCKqmecFWaHw0xWo4C8xOuIIgtOIyUD-XVx1Q6c2XYeTW8HBoLZM=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\w6XNc9fzsZmH7+V9oBTyQeFcUaVnHlxVHVqJs0KjnSbIngx3vk4auKyCN3KWIQUnR5rF0yWQamcJq8cNy8eikaPxL5GrRLhbO0ZbO4wLZlozhieEfLbyZyqif4hnZAqWA-mmN7AehhQTJHPOy3f-qSD+4x+xy5yv975H7A+q7ZA=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AUdCfGbzg33dExgr1y3iLhe7W80oN5yYbel70iAhvbfs2A04Tq0SkK0Y-aCFwdTq8S3cLB8OU6OlBELHLvO4wjYPU56CwZp53D-ojOg2wh2Vo1cqxik-vXxQP165sOLFAUU3EsgYhWn08EzbkeF6fIFdyPErhfjeX7zCTiG2laQ=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\SetupExe(2019031622322792C).log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\5BJlocv9LbRUiqq1eMJElW6BKE+VXrN61gSsrq4zZg1ED5MB+4+XweS195sy9ZCz72PAr77Aqpv0Ge+6Z6V3yA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nS38XN7p0yeUm1GgOU+KMBbKT0XgcCKu1Lf-9wx0T7L++RR8pCJ1l+zqhYDjC-Dn8-LTAtr36MrPPQo-heo7RFMBVcUfknwwt-kiubCxwEEgRZme5SjcCOTIMn5tKFtWFATLQCaclLhGl4HZ1NwtraQMkE45+Nx3lc3Y8JrVZsY=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Z4Z4Oeb+kFy28oNLVTZylUk2YJ6U-L-lXvI12Sn51rqKhKp3VGS8P4CnmTYFqCyhxa4BbdcH+fVXb5MlU95m8klsxTX7itUwH-C5UsO3gHRHHQYJ0PaSKHpbBqO4vAvdeiMj3PR-nXf4n1DOx4WtLBNn-HAUJ1sKGJySgbXAenk=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\jaqBU7WDgL8DiKkoxM4OY+HitXUObY5AfVAqf+7PX0BaRl-8uzbCX8-+gG0FEO9gFhqr2VZBxUNNEpcAwZFd3GlReAp3GBB8MIbtYaPDvH4=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\StructuredQuery.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nBYfced0danA7qBN3KIIcDT54+5vNVFSV7FGkiUl5fNmtdXgBCRgB6q2SgfoTLUH.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2221.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\GZL9xCfKaXF8TtXIY3pjAXnp0GomD4ivQl1WwFIrJTc80HivzrEjjhws6iiD9BuLZCqgsAZj+q10oUDh2uFjbQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2015.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\FT-baFFeBrGdGsstKA3QF6wajiY7jRXfbM8wO3WMDiBDyC6Z2PGNhI9I9IzA005FMIu5Qzzvo0Sqz8reGupW+Q==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\MSIcb2dc.LOG",
- "C:\\Users\\user\\AppData\\Local\\Temp\\XpHDoHWEIxK1F+7D8ofBTOM6PLS7Ptp+qk1T40zzgMU=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2011a.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\8t-eoKSaB3ZosWl5S7J-lSF886UX+wD7W6Jh36+0ce+P0Pg0AvLYc5qnm9NAjyaLD2cxP1x91TyRAtTcfdWjFw==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\jusched.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\gH5SYII92muSu7QZJI5N9Y-0Hg3pJwYDrWzbHLgJteA=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\jawshtml.html",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ECiQe0M297anEe3dPsrcviOB1lNIFoDrcgfOmv71Rr4=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\JavaDeployReg.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\IONoMbD8tf2b8X3yfSz1DJ+2GtTd0cmegNdrEnI5mqEwjopJxycpj55uWGaUH8Wp.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2011.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\D+xRX3liJeZwL+yltqiMotQ1Lrusc8d0Q5ugUcvFOeBYIzh+UTRHcH8BSOX3vJz7qb0eVSsIQNyGJsPAH5g2yA==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_c0f13af742d0ae1bd04715a5af96a169.jpg",
- "C:\\Users\\user\\AppData\\Local\\Temp\\EA62MJQt3ZrhXW505mYV6WHWqqyQTV3pIwgdtcz7QyLiKHaeCako4p3h0uJWgsTIpmef2l0vo9NcMul0rUnle-Kag93o9OYL9hKiL7uqYORk1naDsLqHjzH-a5brQ1U0eGfBh2emcJvH6meTNk9M-iYNsyw9MdNu8KrUbEV1Fro=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_installer.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\rn1BUHixHU7hEqpuhYyfkVGOKazZINO3kwhlLHfLfyAU54Wf9pKKqkts209PVZX5.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\au-descriptor-1.8.0_211-b12.xml",
- "C:\\Users\\user\\AppData\\Local\\Temp\\yBSFxRQK+HLUm3ttDpHbCuskGRwWvLmFIloJjFrGYFlwGLnjv5cWZwOm7c34KkQd2LyInODtFT5tWw6ae5FfEQ==.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeSFX.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ykqLtYLJmk5T0e5xpu1p4p6qabsMkDi8Ew-onjWqEow=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\LiofrVWEXwm79ONfi0fgxsByJkIj1NUDOSn2sEuKSPM=.C30C4DA81AE308962B9A.crypted000007",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1934.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\8Jbh3SAEeOAP5lf0-qQtC+88yPcJuH6IBtUg6Eghmqnb5F0SW9dyn16L9DyyErJ7rQq5mGW9QJ64xRTPJPhWSg==.C30C4DA81AE308962B9A.crypted000007",
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state",
- "C:\\Users\\user\\Pictures\\Host.zip",
- "C:\\Users\\user\\Pictures\\Host.xls",
- "C:\\Users\\user\\Pictures\\Host.pptx",
- "C:\\Users\\user\\Pictures\\Host.ppt",
- "C:\\Users\\user\\Pictures\\Host.pdf",
- "C:\\Users\\user\\Pictures\\Host.jpg",
- "C:\\Users\\user\\Pictures\\Host.html",
- "C:\\Users\\user\\Pictures\\Host.gif",
- "C:\\Users\\user\\Pictures\\Host.doc",
- "C:\\Users\\user\\Pictures\\.xls",
- "C:\\Users\\user\\Pictures\\.jpg",
- "C:\\Users\\user\\Pictures\\.html",
- "C:\\Users\\user\\Pictures\\.doc",
- "C:\\Users\\user\\Pictures\\.bmp",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\userDefinedLang-markdown.default.modern.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Zenburn.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\vim Dark Blue.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Vibrant Ink.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Twilight.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized-light.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Ruby Blue.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Plastic Code Wrap.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Obsidian.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Navajo.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\MossyLawn.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Monokai.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Mono Industrial.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\khaki.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\HotFudgeSundae.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Hello Kitty.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Deep Black.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Choco.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Black board.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Bespin.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\converter.ini",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\stylers.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\shortcuts.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\session.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\langs.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\functionList.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\contextMenu.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\config.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\UProof\\CUSTOM.DIC",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM03998159fn=Insight.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM03998158fn=Element.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM02835233fn=Text Sidebar (Annual Report Red and Black design).docx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Building Blocks\\1033\\TM01840907fn=Equations.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851227fn=sist02.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851226fn=turabian.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851225fn=mlaseventheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851224fn=iso690nmerical.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851223fn=iso690.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851222fn=ieee2006officeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851221fn=harvardanglia2008officeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851220fn=gosttitle.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851219fn=gostname.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851218fn=gb.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851217fn=chicago.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Word Document Bibliography Styles\\TM02851216fn=apasixtheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001115fn=Parcel.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001114fn=Gallery.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001106fn=Badge.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001105fn=Crop.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001104fn=Feathered.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM10001103fn=Headlines.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033937fn=Vapor Trail.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033929fn=Slate.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033927fn=Main Event.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033925fn=Droplet.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033921fn=Damask.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033919fn=Circuit.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM04033917fn=Berlin.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457515fn=View.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457510fn=Savon.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457503fn=Quotable.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457496fn=Parallax.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457491fn=Metropolitan.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457485fn=Mesh.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457475fn=Frame.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457464fn=Dividend.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03457444fn=Basis.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03090434fn=Wood Type.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\TM03090430fn=Banded.thmx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\Welcome to Word.docx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\NormalPre.dotm",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Templates\\Normal.dotm",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Outlook\\Outlook.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\Preferences.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Office\\Recent\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\Built-In Building Blocks.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\15\\Built-In Building Blocks.dotx",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\TURABIAN.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\SIST02.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\MLASeventhEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\ISO690Nmerical.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\ISO690.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\IEEE2006OfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\HarvardAnglia2008OfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GostTitle.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GostName.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\GB.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\CHICAGO.XSL",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\APASixthEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAF.tmp\\Text Sidebar (Annual Report Red and Black design).docx",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFF13.tmp\\APASixthEditionOfficeOnline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB4.tmp\\harvardanglia2008officeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDFEB3.tmp\\turabian.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDE2.tmp\\gosttitle.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC2.tmp\\chicago.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC1.tmp\\mlaseventheditionofficeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDC0.tmp\\gostname.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAE.tmp\\iso690.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCDAD.tmp\\ieee2006officeonline.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9D.tmp\\gb.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD9C.tmp\\iso690nmerical.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCD8B.tmp\\sist02.xsl",
- "C:\\Users\\user\\AppData\\Local\\Temp\\scoped_dir1924_4570\\CRX_INSTALL\\manifest.json",
- "C:\\Users\\user\\AppData\\Local\\Temp\\outlook logging\\firstrun.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1904.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1834.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1450a.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1450.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1449.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\user.bmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\SetupExe(2019031622322792C).log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\StructuredQuery.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2221.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2015.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\MSIcb2dc.LOG",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2011a.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\jusched.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\jawshtml.html",
- "C:\\Users\\user\\AppData\\Local\\Temp\\JavaDeployReg.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190316-2011.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_installer.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\au-descriptor-1.8.0_211-b12.xml",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeSFX.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Host-20190127-1934.log",
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\System32\\Configuration\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xi",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xVersion",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xmail",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xmode",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xpk",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xstate",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xcnt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\shst",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\sh1",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\sh2",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\shsnt"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "whatismyipaddress.com",
- "answers":
- "data": "104.16.154.36",
- "type": "A"
- "data": "104.16.155.36",
- "type": "A"
- "type": "A",
- "request": "whatsmyip.net",
- "answers":
- "data": "104.18.35.131",
- "type": "A"
- "data": "104.18.34.131",
- "type": "A"
- * Domains:
- "ip": "104.16.154.36",
- "domain": "whatismyipaddress.com"
- "ip": "104.18.34.131",
- "domain": "whatsmyip.net"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 10,
- "body": "",
- "uri": "http://whatismyipaddress.com/",
- "user-agent": "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0",
- "method": "GET",
- "host": "whatismyipaddress.com",
- "version": "1.1",
- "path": "/",
- "data": "GET / HTTP/1.1\r\nHost: whatismyipaddress.com\r\nAccept: */*\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0\r\n\r\n",
- "port": 80
- "count": 4,
- "body": "",
- "uri": "http://whatsmyip.net/",
- "user-agent": "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0",
- "method": "GET",
- "host": "whatsmyip.net",
- "version": "1.1",
- "path": "/",
- "data": "GET / HTTP/1.1\r\nHost: whatsmyip.net\r\nAccept: */*\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement