Loading ...

Analysis Report

Overview

General Information

Analysis ID:8156
Start time:23:39:16
Start date:13/03/2015
Overall analysis duration:0h 7m 39s
Report type:full
Sample file name:
Cookbook file name:default.jbs
Analysis system description:W7 Native, up to date 12.12.2013 physical Machine for testing VM-aware malware (Acrobat Reader 11.0.04, Flash 11.9.900.170, Internet Explorer 11, Firefox 26, Java 1.7 Update 45)
Number of analysed new started processes analysed:2
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
HCA enabled:true
HCA success:
  • true, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Provided url points to a PE file
Warnings:
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtCreateFile calls found.
  • Report size getting too big, too many NtOpenFile calls found.
  • Report size getting too big, too many NtQueryDirectoryFile calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
  • Report size getting too big, too many NtRequestWaitReplyPort calls found.
  • Report size getting too big, too many NtSetInformationProcess calls found.
  • Skipping Hybrid Code Analysis since the current process likely is based on Java, .Net, VB or Delphi


Detection

StrategyReport FP/FN
Threshold malicious


Signature Overview


Spam, unwanted Advertisements and Ransom Demands:

barindex
Moves / writes many txt or jpg files (may be a ransomware encrypting documents)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMANIAN.TXT
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1250.TXT
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\license.txt
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\README_th_en_CA_v2.txt
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\CORPCHAR.TXT
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Program Files\AutoIt3\Examples\GUI\mslogo.jpg
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
Source: C:\Users\john\AppData\Local\Temp\download.exeFile moved: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
Writes a notice file (html or txt) to demand a ransomShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:21<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:21
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:20<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:20
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\IDTemplates\ENU\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:17<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:17
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\Services\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:19<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:19
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:19<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:19
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:18<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:18
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\ENU\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:18<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:18
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:18<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:18
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Resource\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:21<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:21
Source: C:\Users\john\AppData\Local\Temp\download.exeFile dropped: C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Adobe\DECRYPT_INSTRUCTION.html -> <title>your files were encrypted!</title><h2>your files were encrypted and locked with a rsa2048 key</h2><p>to decrypt your files:<br> download the tor browser <a href="https://www.torproject.org/download/download-easy.html.en">here</a> and go to <b>http://r7twae4a7jtozjwv.onion</b> within the browser.<br>follow the instructions and you will receive the decrypter within 12 hours.<br>you have ten days to obtain the decrypter before the price to obtain the decrypter is doubled. scheduled deletion of the private key from our server is after 30 days - leaving your files irrevocably broken.<br>your id is <b>q7bcr32ws6</b><p><b>guaranteed recovery is provided before scheduled deletion of private key on the day of 03/09/2015 10:46:20<p><b>the price to obtain the decrypter goes from 2btc to 4btc on the day of 02/17/2015 10:46:20

Networking:

barindex
Urls found in memory or binary dataShow sources
Source: download.exeString found in binary or memory: file://
Source: download.exeString found in binary or memory: file:///
Source: download.exeString found in binary or memory: file:///c:
Source: download.exeString found in binary or memory: file:///c:/use
Source: download.exeString found in binary or memory: file:///c:/users/john/appdata/lb
Source: download.exeString found in binary or memory: file:///c:/users/john/appdata/local/temp/
Source: download.exeString found in binary or memory: file:///c:/users/john/appdata/local/temp/download.exe
Source: download.exeString found in binary or memory: file:///c:/users/john/appdata/local/temp/en/update.resources/update.resources.exe
Source: download.exeString found in binary or memory: file:///c:/windows/microsoft.net/framework/v2.0.50727/
Source: download.exeString found in binary or memory: http://community-downloads.quest.com/powergui/update.xml
Source: download.exeString found in binary or memory: http://crl.microsoft.com/pki/crl/products/cspca.crl0h
Source: download.exeString found in binary or memory: http://crl.microsoft.com/pki/crl/products/tspca.crl0h
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=104288
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=108995
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=109270
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=109695&result=block&t=%1&url=%2
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=121338
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=125824-http://go.microsoft.com/fwlink/?linkid=125723-http://g
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=247104.
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=247104.&click
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=291257
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=291257.
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=291257.r
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=291337%
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=3448&clcid=%#04lx
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=37020&name=%1
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=52661
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=55273
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=58927
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=62022.do
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=63849
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=67233
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=67234
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=67235
Source: download.exeString found in binary or memory: http://go.microsoft.com/fwlink/?linkid=96776
Source: download.exeString found in binary or memory: http://microsoft.com0
Source: download.exeString found in binary or memory: http://powergui.org/downloads.jspa
Source: download.exe, crypter.ps1.dr, DECRYPT_INSTRUCTION.html.dr, DECRYPT_INSTRUCTION.html0.dr, DECRYPT_INSTRUCTION.html10.dr, DECRYPT_INSTRUCTION.html11.dr, DECRYPT_INSTRUCTION.html15.dr, DECRYPT_INSTRUCTION.html21.dr, DECRYPT_INSTRUCTION.html23.dr, DECRYPT_INSTRUCTION.html29.dr, DECRYPT_INSTRUCTION.html3.dr, DECRYPT_INSTRUCTION.html34.dr, DECRYPT_INSTRUCTION.html35.dr, DECRYPT_INSTRUCTION.html37.dr, DECRYPT_INSTRUCTION.html40.dr, DECRYPT_INSTRUCTION.html41.dr, DECRYPT_INSTRUCTION.html44.dr, DECRYPT_INSTRUCTION.html46.dr, DECRYPT_INSTRUCTION.html5.dr, DECRYPT_INSTRUCTION.html51.dr, DECRYPT_INSTRUCTION.html55.dr, DECRYPT_INSTRUCTION.html56.drString found in binary or memory: http://r7twae4a7jtozjwv.onion
Source: download.exeString found in binary or memory: http://schemas.dmtf.org/wbem/wsman/1/cimbinding/associationfilter
Source: download.exeString found in binary or memory: http://schemas.dmtf.org/wbem/wsman/1/wsman/selectorfilter
Source: download.exeString found in binary or memory: http://schemas.dmtf.org/wbem/wsman/identity/1/wsmanidentity.xsd#identifyresponse
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/clr/
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/clr/assem/
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/clr/ns/
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/clr/nsassem/
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/maml/2004/10
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/maml/dev/2004/10
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/maml/dev/command/2004/10
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/powershell/microsoft.powershell
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/wbem/wsman/1/config/client
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/wbem/wsman/1/config/client/auth
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/wbem/wsman/1/config/service
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/wbem/wsman/1/config/service/auth
Source: download.exeString found in binary or memory: http://schemas.microsoft.com/wbem/wsman/1/wql
Source: download.exeString found in binary or memory: http://www.%s.com
Source: download.exeString found in binary or memory: http://www.microsoft.com
Source: download.exeString found in binary or memory: http://www.microsoft.com/downloads
Source: download.exeString found in binary or memory: http://www.microsoft.com/pki/certs/cspca.crt0
Source: download.exeString found in binary or memory: http://www.microsoft.com/pki/certs/tspca.crt0
Source: download.exeString found in binary or memory: http://www.w3.org/1998/math/mathml
Source: download.exeString found in binary or memory: http://www.w3.org/1999/xhtml
Source: download.exeString found in binary or memory: http://www.w3.org/1999/xlink
Source: download.exeString found in binary or memory: http://www.w3.org/2000/svg
Source: download.exeString found in binary or memory: http://www.w3.org/2000/xmlns/
Source: download.exeString found in binary or memory: http://www.w3.org/2000/xmlns/)
Source: download.exeString found in binary or memory: http://www.w3.org/2001/xmlschema
Source: download.exeString found in binary or memory: http://www.w3.org/2001/xmlschema-instance
Source: download.exeString found in binary or memory: http://www.w3.org/xml/1998/namespace
Source: download.exeString found in binary or memory: http://www.w3.org/xml/1998/namespace)
Source: download.exe, crypter.ps1.dr, DECRYPT_INSTRUCTION.html.dr, DECRYPT_INSTRUCTION.html0.dr, DECRYPT_INSTRUCTION.html10.dr, DECRYPT_INSTRUCTION.html11.dr, DECRYPT_INSTRUCTION.html15.dr, DECRYPT_INSTRUCTION.html21.dr, DECRYPT_INSTRUCTION.html23.dr, DECRYPT_INSTRUCTION.html29.dr, DECRYPT_INSTRUCTION.html3.dr, DECRYPT_INSTRUCTION.html34.dr, DECRYPT_INSTRUCTION.html35.dr, DECRYPT_INSTRUCTION.html37.dr, DECRYPT_INSTRUCTION.html40.dr, DECRYPT_INSTRUCTION.html41.dr, DECRYPT_INSTRUCTION.html44.dr, DECRYPT_INSTRUCTION.html46.dr, DECRYPT_INSTRUCTION.html5.dr, DECRYPT_INSTRUCTION.html51.dr, DECRYPT_INSTRUCTION.html55.dr, DECRYPT_INSTRUCTION.html56.drString found in binary or memory: https://www.torproject.org/download/download-easy.html.en

Remote Access Functionality:

barindex
Contains strings which may be related to BOT commandsShow sources
Source: download.exeString found in binary or memory: LWRN: Comparing the assembly name resulted in the mismatch: Retargetable flag"LOG: Retarget policy is not found.CLOG: Name redirect found in retarget config: %ws redirected to %ws.FLOG: Version redirect found in retarget config: %ws redirected to %ws.MLOG: PublicKeyToken redirect found in retarget config: %ws redirected to %ws.$ERR: Parse XML memory stream failed.CERR: bindingRetarget tag is not processed due to insufficient data.

Persistence and Installation Behavior:

barindex
Drops HTML or HTM files to system directoriesShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile created: C:\Windows\IME\IMEJP10\DICTS\DECRYPT_INSTRUCTION.html
Infects executable files (exe, dll, sys, html)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\AutoIt3\Extras\Editors\TextPad\Manual Install and Notes.htm
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\Adobe\Reader 11.0\ReadMe.htm
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\AutoIt3\Extras\Editors\Crimson\Manual Install and Notes.htm

Spreading:

barindex
Enumerates the file systemShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\Browser\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Esl\
Infects executable files (exe, dll, sys, html)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\AutoIt3\Extras\Editors\TextPad\Manual Install and Notes.htm
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\Adobe\Reader 11.0\ReadMe.htm
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem file written: C:\Program Files\AutoIt3\Extras\Editors\Crimson\Manual Install and Notes.htm

System Summary:

barindex
Tries to open an application configuration file (.cfg)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
Uses Microsoft SilverlightShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
Uses new MSVCR DllsShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80.dll
Binary contains paths to debug symbolsShow sources
Source: Binary string: C:\Windows\Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Source: Binary string: mscorrc.pdb source: download.exe
Source: Binary string: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Source: Binary string: c:\PowerGUI\!PowerGUI!3.5\Source Code\Platform\Quest.PowerGUI.ScriptRunner\obj\Release\ScriptRunner.pdb source: download.exe
Source: Binary string: C:\Windows\dll\Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Source: Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Source: Binary string: ity.pdb source: download.exe
Source: Binary string: C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Source: Binary string: {indows\Microsoft.PowerShell.Commands.Utility.pdb source: download.exe
Creates files inside the program directoryShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile created: C:\Program Files\Adobe\Reader 11.0\Reader\IDTemplates\ENU\DECRYPT_INSTRUCTION.html
Creates files inside the user directoryShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile created: C:\Users\john\Documents\Fax\Inbox\DECRYPT_INSTRUCTION.html
Creates temporary filesShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile created: C:\Users\john\AppData\Local\Temp\d69b2c25-f0ff-4351-8b1c-066f001c88d4.config
Executable uses .NET runtime (Probably coded in C#)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
Reads ini filesShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile read: C:\PROGRA~1\Joebox\user\settings.ini
Uses an in-process (OLE) Automation serverShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
Creates files inside the system directoryShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile created: C:\Windows\IME\IMEJP10\DICTS\DECRYPT_INSTRUCTION.html

HIPS / PFW / Operating System Protection Evasion:

barindex
May try to detect the Windows Explorer process (often used for injection)Show sources
Source: download.exeBinary or memory string: Progman
Source: download.exeBinary or memory string: Program Manager
Source: download.exeBinary or memory string: Shell_TrayWnd

Anti Debugging and Sandbox Evasion:

barindex
Checks for kernel debuggers (NtQuerySystemInformation(SystemKernelDebuggerInformation))Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeSystem information queried: KernelDebuggerInformation
Creates guard pages, often used to prevent reverse engineering and debuggingShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeMemory allocated: page read and write and page guard
May sleep (evasive loops) to hinder dynamic analysisShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exe TID: 1864Thread sleep time: -922337203685477ms >= -60000ms
Source: C:\Users\john\AppData\Local\Temp\download.exe TID: 3600Thread sleep time: -60000ms >= -60000ms
Source: C:\Users\john\AppData\Local\Temp\download.exe TID: 3600Thread sleep time: -60000ms >= -60000ms

Virtual Machine Detection:

barindex
Queries a list of all running processesShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information queried: ProcessInformation
Contains long sleeps (>= 3 min)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeThread delayed: delay time: -922337203685477
Enumerates the file systemShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Reader\Browser\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\
Source: C:\Users\john\AppData\Local\Temp\download.exeFile opened: C:\Program Files\Adobe\Reader 11.0\Esl\

Hooking and other Techniques for Hiding and Protection:

barindex
Disables application error messsages (SetErrorMode)Show sources
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\john\AppData\Local\Temp\download.exeProcess information set: NOOPENFILEERRORBOX

Lowering of HIPS / PFW / Operating System Security Settings:

barindex
AV process strings found (often used to terminate AV products)Show sources
Source: download.exeBinary or memory string: Microsoft.PowerShell.Core\FileSystem::C:\Windows\ehome\mcupdate.exe
Source: download.exeBinary or memory string: mcupdate.exe

Language, Device and Operating System Detection:

barindex
Queries the cryptographic machine GUIDShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Queries the volume information (name, serial number etc) of a deviceShow sources
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\ VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
Source: C:\Users\john\AppData\Local\Temp\download.exeQeruies volume information: C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation

Yara Overview

No Yara matches

Screenshot

windows-stand

Startup

  • system is w7native
  • download.exe (PID: 2800 MD5: A14F1C1DC020BED807A1E666D154D89A)
  • cleanup

Created / dropped Files

File PathType and Hashes
C:\Program Files\Adobe\Reader 11.0\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: E9941882A06EABF170E3CEBFF4CDDCE7
  • SHA: 8DE6196C2371E2F926D9B2405F6E61ECBC714092
  • SHA-256: C2519EFFFBFCB3DCBA2C46CCEA6319C6198938F5666E9218EAD77E23D9464C07
  • SHA-512: B9CF308AC2909F6147A58CEB5457CA77DC89D2CD3C227622D811322681B8F8808A1726BA09A6036EAC5FE3F3469698B419C1FAE48CA6A5B93E8856D4771E3304
C:\Program Files\Adobe\Reader 11.0\ReadMe.htm
  • Type: data
  • MD5: 8E2C4B344122172C5390941E1D274828
  • SHA: 204D477A469C60A50C2CAC5DE9B6EAE58F002FFC
  • SHA-256: 517D9F96CF8B9468BD04C7973D3D423D67397C0AB7381343A2619B6F27E5EB54
  • SHA-512: 10F9725D4188098D05488B3071CEE53149C53EE8A3D782F406A0BAF359892C1D20A9D0B497655376C034D9D5AD0139FAE70B3A0E37272C2AC39627E9C4808A67
C:\Program Files\Adobe\Reader 11.0\Reader\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: B4EF525B615CE68EE9A89AE424BE7C96
  • SHA: AB9CEE5FD2A96E711249EA6B62B9C83C54690F56
  • SHA-256: 3F2AF89DA8CB1768BFB103DF47DF3941C9F3F6DFB7A253283B69CB2A3E1974B4
  • SHA-512: EBA0A7B9FB1BE3EFC82EA32C76EAFD775AF3F5DA29C903465D964073514D49ED0723A0048DCCB850445C2799DC7D43856EF981F6C997EEAA07D748D6720B4037
C:\Program Files\Adobe\Reader 11.0\Reader\IDTemplates\ENU\AdobeID.pdf
  • Type: data
  • MD5: 0C16A3055298A87EB3058B8BC72FDF3A
  • SHA: 66EFA84CBD0788320C65243859B8AADF70B7E9A8
  • SHA-256: 8DA9CC1CFACE1577A51D8EE3D924D91AD277A5F9AF1D5936250FA44B797F6215
  • SHA-512: A83F610703C1192CD31F806AF44A8BD48A5DB35EC958A8245ADCF2C3CAE50D5EEB654C7F3FF385072F8A46DA584DABF56E4C6AF2A0EAD04F553980A9F8BCCA73
C:\Program Files\Adobe\Reader 11.0\Reader\IDTemplates\ENU\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: F9B9AEC2EF775E0FCD34A8C5EA02F28C
  • SHA: 177BB4D30C13629F1E3A1521E6B08C6DDF3260DF
  • SHA-256: 5F19EA5FF079B7C0E992692B13B001C731D2F4C35DB6846817C9B15CCACB8E93
  • SHA-512: 69004822530B670BA1FEDFF67745CE196F392A5B40904E0B8EB802D02124DFE4A5C6D74120AE9F35D7C3DC70E18BF3E1756B733D3DC998DD7A7026D251D731FE
C:\Program Files\Adobe\Reader 11.0\Reader\IDTemplates\ENU\DefaultID.pdf
  • Type: data
  • MD5: 83A5268771F4FE931D5343E9C972B1C4
  • SHA: 652792165527C253E2F4CBBC2AF5E7496CF38711
  • SHA-256: 6754359D33A035346C796F6CBBEED67EFA9001CF362C2C17463674B9C3E4E42D
  • SHA-512: CDA9BC894533B0616638F0EB3C69F57B3AF6AB5CA44894235C966AEC7AF98DF33350EB5B63CCF2B9F5EB1A83C02B4DB1DD7A547885C7BE3395E273B426D39CF1
C:\Program Files\Adobe\Reader 11.0\Reader\PDFSigQFormalRep.pdf
  • Type: data
  • MD5: 86DAE784690B0AAAADBF2299847057D4
  • SHA: 12A6BC8FF42C25F18BADCA575991B778A42171BF
  • SHA-256: 53D023BB70C58AAB5864BCA42D264CE6837A1AB0029C424D39415DBAD27BAA83
  • SHA-512: ED4EE6F3BBF145E7B2525481C5AB63B6F904AA308DFA215ED672B45660B8EC3A7408076B879B1D517820AFDA9A57CB7989190B55BB000D54C969DFE0016C8F78
C:\Program Files\Adobe\Reader 11.0\Reader\Services\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 34E45003A0783E1E4005CD998C70D908
  • SHA: D9A6DB971A28CCCD67517B6EF771C51AD959F173
  • SHA-256: EF3F41D54819CBC15E879B14D9EF1A573846FFCDB45A86AA2A26B704A4F9CB41
  • SHA-512: 525C163AED62AA41F71A44BCCE399B1668D3F15810BED921AD0CC5E552A32E406483A227947609F62E1CD5D918FF01701CF630B3DA281A8B98ECD2B2E02A3859
C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
  • Type: data
  • MD5: 05F4F79DA9B27AC0EDADA1DB8E862D01
  • SHA: EDBC8045D5069B1694FE8B9582DEC174B18F52E0
  • SHA-256: 973A12D98DC9560FCB5F7F25A715588734E674B5F4ABE155DB40FD2A33A08399
  • SHA-512: A9B056B83F6A94661803D0AD714A334D4F64003D8D1B1AFF065E9B7041B8865C5543732B7464028EC7E209A79F67BE25676D03A97BABA45C4FC76C7C5E357071
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 34E45003A0783E1E4005CD998C70D908
  • SHA: D9A6DB971A28CCCD67517B6EF771C51AD959F173
  • SHA-256: EF3F41D54819CBC15E879B14D9EF1A573846FFCDB45A86AA2A26B704A4F9CB41
  • SHA-512: 525C163AED62AA41F71A44BCCE399B1668D3F15810BED921AD0CC5E552A32E406483A227947609F62E1CD5D918FF01701CF630B3DA281A8B98ECD2B2E02A3859
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\add_reviewer.gif
  • Type: data
  • MD5: 99CFE7F200512C3B076E00BBAA774445
  • SHA: A9A762931C4D01EBEE9CB6F96D11F942922D5289
  • SHA-256: C359C32654234B5A62ED646064B276AF82F4E12B8609A759E446AC473634E40F
  • SHA-512: 5FEF99B218D3242F398D090D9C28D2DE9C9D63E6F02C80601AB012228BE0F322DA2B11C54C3E519EDB2DE1BEA5F3D7A5291553B4C065CBBC854A0941F720A148
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\bl.gif
  • Type: data
  • MD5: B71C1666F2F63DEBC4A61560234EACC4
  • SHA: B17009F13F14398C56BFD9F738480D1AA5C4FB7A
  • SHA-256: 8F62AADBDE2D99F2309BD5444F286D02CE614E4E6BB753205FAB3CBEEE9FC18B
  • SHA-512: 13B1A38F070AAB0823545416B51C2A23888D77D1250F5543AE6075BE31053E6F313E0E9DA39C67AD182FEB33CF5F0B68360E5818D73C8A1A7429FA6C4486DCD3
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\br.gif
  • Type: data
  • MD5: BA63EDEC69DAF84BE0703DD52B8A77C4
  • SHA: 11243694D2A79BD73F44C16ACDB1EAD5910BCF34
  • SHA-256: AA1091EA9BA327634E4087EE16B93732D222D2CD1034FEE2200A38ABCD27075F
  • SHA-512: 7F6C7C73554B7A623918ED08419D102FC6AC52BDFE236BEA7F4D87BCDD8B2F9B29EED8D257801B112487B6EE46A56333B0FAD61D8EEA92C31E0102E700522C4E
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\create_form.gif
  • Type: DOS executable (COM)
  • MD5: 3EAA237716F3ED601011ECE07A019F32
  • SHA: 486993C357AEE798C407DCCFC7C5F8A40BB3AF4D
  • SHA-256: 767567E369B5F9F45FE2D7E6941CFD36A03D8B6F530728B38EED2B636B8D6BEF
  • SHA-512: CEFC6EB13E310C7B5633FBD4AEC52DCDE89146EDF65E26887F644F905BBA0D9032FDD740C4F5B20FB8AF8557DB0447048A330E7940ABC85D1BC0ABFE33DF1BFD
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\distribute_form.gif
  • Type: data
  • MD5: 62275D7AC4F723E00B2F6091215C42BC
  • SHA: 87C30D14E3F9AC428C4669235C4C59B4E740025E
  • SHA-256: 9316488BCCA662FA5C085DE901A0036D3B0B86BDB469930BA78A74C3A9F19AF4
  • SHA-512: 2B8E43693B55F477ED8221F81FFF6C383DBD03279B870780C4BBE30BC8E710865F16F0E43D56501B869C6FD237A239460D512719A1053838494DDECA68811136
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\email_all.gif
  • Type: data
  • MD5: BD673BC483F53D0A7CE2990D4CE31E12
  • SHA: 620944E76DAF7295E72ACFC47DB35638E6B31AF4
  • SHA-256: 0A89FBEB9013ACE2721A2B7CA724FE4F41B859C6913AE2F8B4F594BA3654A215
  • SHA-512: 714242EDE68049F6CF0D33AC27683F0777014A49E6C10BCB43258392D4616638850D0966895AFB431B030A3D9E320DC020FF4CAF03063EFF7214392F2B4FF031
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\email_initiator.gif
  • Type: data
  • MD5: F877DFCE2BEC2A1A2B16E2D2D39F3C96
  • SHA: 0F5E8EF61512C451C471D51D081CA40D91BB087F
  • SHA-256: 47DA3AE87AAD86837E420F5509A7B126C575B7E34D6074BED29B3DE0D67A4BA0
  • SHA-512: 5EBF9EFE74F7EC4A3253C6DAF30348606ED1679B4EB08B9707E2B2578AF8C453BBD7A902FDCD00E2E8D4D8DA87DDC2DF63A19EAF5AEC4A309D0BE7EBD6D10B0B
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\end_review.gif
  • Type: data
  • MD5: BFD95EDA1EA2BAD990168AF950CB950C
  • SHA: 44390BF52299B24310BAD923E38FDC20B18778DE
  • SHA-256: 090EE5AB6153613E27A12336CB9C7CE08DE9D6F4064FD3DF823D00DF8A877CEF
  • SHA-512: 333F5FF231A4A4AB92FA014E3CDAAB5FAE50F771EE49E43EACE4BE2ED4324331743D8C0B0AF2150D80C273B7CA0C9695DA57517D01E4214598D6C518C0CA8F43
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\ended_review_or_form.gif
  • Type: data
  • MD5: 59000FF0FF6FD1AB9D9B18448E7205B8
  • SHA: A62CA7149452D26124CFA198C86DC9752836279C
  • SHA-256: 8315A0C3D0689DE81BD2558E268BA5DAA438B62958C73BAFE08AB9A60B321796
  • SHA-512: 749E0D1D5C53E55651729A1FDE872EB9F2DFCD983318141D4D101E11E08FEF66C098B2340F52A548CCD18B39B9EC09C2C90C596F7E0A31C281BBF5BB561845A1
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\form_responses.gif
  • Type: data
  • MD5: 8037AE046548574EE4C06D8B4D889D3A
  • SHA: 3410E6CAEDA884BE34931367EBD70A08F49E4D82
  • SHA-256: 073A7D714442392FDE0041AC13225D78D347BE78093B93082B966B7536A55288
  • SHA-512: 48AD579CE648A13F80E578074510B53B4E43C18D1C1F42C9C7BEB04D91A649752962C103B070C1D49B9C3DA7E263E1372C94F50ABE3ECFF622EAC988BE9D7973
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\forms_distributed.gif
  • Type: data
  • MD5: 4FB899797180BC91ADFD0F067916615C
  • SHA: 9CB7FC2EEBBCCB92D9929A851B9AADA91B057BB3
  • SHA-256: 11FF346FAF9780067E986018EB7289E4327D1F7F55A517572D9CE98C5AFA212E
  • SHA-512: 9D34A89BA812F7F3A6FCC12158BF9DEB5950448C62B50A8F3FA3B8F09F99C3E3D8C1F5186168CB071B6E328B1DF8FDCC0D8D018C71C3525D3E10E051BC2BB97C
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\forms_received.gif
  • Type: data
  • MD5: E47A234AF2FD826A7E4ABFE03BE1D951
  • SHA: E4ACD7F0314EE7C812D961C8DC6EC9F68057110E
  • SHA-256: 511AD9B418708FDCCD1B58E1FA49F312171FAD7B99CC20F932BA1C6F11425CCB
  • SHA-512: 9B49D48B01B4498CE254D8767F34042EFFF7CB09A4CA9321BD60C9C0569B02A48AE9E2D7B959B17F0C13759F5BB3078EF6EB7270696EE867245C2AFB1546A3B0
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\forms_super.gif
  • Type: data
  • MD5: BC069EB2CBFF15383151AD37DEAC5514
  • SHA: 46B8840FFDCE7F1EFC7FA291A3193E3CF07993FB
  • SHA-256: 3214090CC509D66E09A6A781EF346C9A2A9B31E2426F8989E1BBE8E135412F3D
  • SHA-512: 7DEE3CEBE1EAF35D45908408D9E10F82579323D823EAC3F3BD36ACDC5E80C09A87D878925327575B089424E46C6BC47699907332F0C9FE38F6B879B5BE55C511
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\info.gif
  • Type: data
  • MD5: 2E1C0E02BE5E16EF0B3119F779C8209B
  • SHA: 871838CA9A8DD32ACC08237113C0176E681269C9
  • SHA-256: 8C38E5E872AD89E5D3A28AF3BE177EEA2D0D6BB20EAFDDA4B0AB2498B3BAD599
  • SHA-512: 2ED118B849891AA780947C1F345D5068759659CED4BB97C761C3E5CD6F0A22671BB1AD595D161ABD492A2B33C27F97F50B26E0F394B79C3803B4F9E165A7874F
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\open_original_form.gif
  • Type: data
  • MD5: 0ACC66522DA0369325F2EAA64F65BD03
  • SHA: 4DC6DAE291ED4E990FEB71D8AC90592E4A31580C
  • SHA-256: 17EE739C491D2CE71C634F28A494C217CF7CF076DC636688B473EAD1967C9AE4
  • SHA-512: 9BFA8113447FA640FF6900BEE90E0EC28496E278E49CCED9060E0355E1CCEB4CB81009A529E7A84070E409CAC73082805D496DDCB9C813A3D81A789978718A15
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\pdf.gif
  • Type: data
  • MD5: 16C9054F090DC429A7E26A447400B014
  • SHA: 63AF5EA5B3201DD500E9B6B3247FB452C6A6A472
  • SHA-256: 0C8CD216BEDE6600BA47F3BB0FC1CE5B33686643B6973B1BBF8D5B0D7FFF9184
  • SHA-512: EBC9F398BE127EC083EEC321B528D58F6B6B6D851621D66E0EB7DD83A38698A1B240C16937BFFB622847A99544282184C76D3ACCE3BC8200EAB81B9CFBD243B9
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\review_browser.gif
  • Type: data
  • MD5: BDEA875A887F24B27CF5150DC27A9758
  • SHA: 5F111B1B2478953BE572941FE7AB9104F703626C
  • SHA-256: B39FDC9B821CFD362EE3CB0FC37DDC7356674727128EEE46B8A1578F42813ADE
  • SHA-512: 4665236B9EF6CC69D8827D1C5DF8F4C3CD84FEC7A121FDCA585B4CF9B981EF7C77331CD7F9F5DFBCD5CFCE4B58D4C6E71F42F77F7543908A1F793E1836FF4A83
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\review_email.gif
  • Type: data
  • MD5: 5F4D300C459A4EA1AFFCFDFED2C12846
  • SHA: F5C7F886231DA50AAE90525ADD1EDADE8CED8AB6
  • SHA-256: A5D56779BECB0BB3E5CC2946BBFB105B2C34E9345177D26AC2ADDEF30B609429
  • SHA-512: E5B55AA6D87405860885BEA0F782E04B65683F60F93B88982533837EC9562250359F35B3E999F23704A1D201EEF561081B96FFFDFE7F488DF5B07CD3996753F9
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\review_same_reviewers.gif
  • Type: data
  • MD5: 30212B02977C746EA314C41B9CA86646
  • SHA: 10A337180A9E6C1E93B9826D6E2C8B00E093DC9D
  • SHA-256: E39B422161CDCF2467FFAEF2C85FCB902FA7A1A6DAF42C056797956297301AA0
  • SHA-512: 99D347195116394AE1DF5F8557405442A6120121D6E3084A216607D023133EBC925A5EAA55D769A4FF7F2ABE6FE1F3477BF4654ED8F0BB5E9BEF7453CD42A4DD
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\review_shared.gif
  • Type: data
  • MD5: 679B6BCA683FFE97E845159CEDA2DE1E
  • SHA: B43AFE0CA64755BE1DC22F8082FFCADAB9860660
  • SHA-256: 1318DBB109B2C7F2651885DF51AE6C6C0B63CF438530A2753546FC0FEB30D44D
  • SHA-512: CEDF1257524B1480C82F7EA3392EF6D6A3890FBECD97675DE6504BB647642171DB67F7375E185C62250C699C2A31B328C43BDC0E4853C4C126A36ADF75FB2A6F
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\reviewers.gif
  • Type: data
  • MD5: 4AF03248B02BDBC1AEA58FEB23E913BC
  • SHA: 71D8B06D2CB643AFD4C119C392A76975804EA916
  • SHA-256: 27AE684EE031462C0CA528922BBDCDA7B8C66CDA3C1A1DCA6CB42F6547D64C02
  • SHA-512: 7293DBC028861C4B9A0A83C0E5AE8A6AA080D3FB28DA5F6F0DC3235A5B41C81B11304B4C4FF6A21B6CF6F4025E9457EF506B50C05366EED3EE378EA0EBC0F94B
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\reviews_joined.gif
  • Type: data
  • MD5: 886EB04E65A4F85A35BE2D8E515F151E
  • SHA: 46E935CF0D612176374C7D2373931C86319A5D92
  • SHA-256: 2D6F18DBFF234455A6B3944983763CD8CE422DE2C3AEC184BB6ABAE27E64AAB4
  • SHA-512: 70FA12FB05528D5A7F48CF8512122B7E79F3A3DCEDC77AE6A60BDCF5F6D231450B8058D2798CF5662A76F264A7A9353BDF51D0C7CD58303DCC36782A2897FEC2
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\reviews_sent.gif
  • Type: data
  • MD5: 9C7E3B2CA6214768E32FEFDE3C7B3C9A
  • SHA: DFFD2AD2AABF393395C08D8609AA04D5CE17FC53
  • SHA-256: F6DF1632CBEF110D08369E7B29111BADB038F573FBD82C89F035686136730489
  • SHA-512: 240DAED5B5C86F301A1913B2B1D96535CBF7C213BBB06E0B872B0251A974E8DF6FBBB1FF8B98F8A419480C575E2E29C14AD171619C88CD522FF3CEFB28EE7700
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\reviews_super.gif
  • Type: data
  • MD5: A421E982AE9F8BFB2E68770664937C29
  • SHA: 9535DDD005ECF675DFE6D38F779257B64AA88470
  • SHA-256: 388D884A7E7D924FDB0E3BB5B8CCC9C0C38AAF16B70A88FCFEFE830973E48BEE
  • SHA-512: 4CA5FE0A2AA039C62B8F75DB7890689BB77028F9D7D01E76212D0765C84DBBAABEC5188C4965D0264D93CF57529F454117F3482DF9722DE044201AC371E8DB42
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\rss.gif
  • Type: data
  • MD5: 89CD7A002161D3C868D1D04DAF994C95
  • SHA: E43DE4890A59723881A6A056930AF76391443AAB
  • SHA-256: 22E1BB879EA38672A9A0190F2B54482FC1A0CF2F600D21EC990BFA49456E1495
  • SHA-512: AB714AFC48DFC575FA0B8A057EF8C75F656A0FCBA0F53DEEFB7A6D098E477DBB54EA91499A421007AAAEAD2B68EDC864757B5F95724523A3EA34441CD4C0DBC1
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\server_issue.gif
  • Type: data
  • MD5: 840A57C167076237CF7DF5679943F1C4
  • SHA: 4629E91B3F4B3EDEEFDD969B2FDD044B3B256227
  • SHA-256: 17308ADAC5F7B4090F467E45361B1DA5D3F4C5CECC2FFEDE7C9111B7E7857A47
  • SHA-512: 57983A8FE064586B3A2493B68A90A075E9A4058F30AF101572F438F140EA0B6B232A3FFFCFC301667E1DF15E7F2125B5F405AE970218337F36D72D62ECAD8C1D
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\server_lg.gif
  • Type: data
  • MD5: FEE0BF300F0D417334F0134EC759413C
  • SHA: 716059F2B6395F407A2513FB88D212751EE6AC5C
  • SHA-256: 0CC2963D9BFB7815948EFD3697F14802613E64B23B428E90ECC4A33269F1E67C
  • SHA-512: B14EEEE007398EBE97CF3F8337295508E33C5F6391155A0B71DEB1017A832542310AEFA236343575CB1029614801C22D56742C794713BC8B68815E17267851B1
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\server_ok.gif
  • Type: data
  • MD5: 8B027BFF109ED95FDCE4C89FE45EDBC0
  • SHA: B9E0E511F44704256DC6FADC201C93B99D97E5C9
  • SHA-256: 135C80EAAF8362E82083EC630FFB9ADCDC12C2D4C1C87148100BE636E3B264CF
  • SHA-512: 23B8EBCAA03F6BEA9FED089D6E263F2914CE1BE1593DA02DC78A2A1C931BBC43FF654BC2459F39EBCF0C311A8054F39F0E57CF100F12DAF423EC4BD791AFC704
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\stop_collection_data.gif
  • Type: data
  • MD5: 94E29D80F82DAFD67DF9BD5F60380FC3
  • SHA: 4B3A9634A590E9BFAC90C5E0A76C0F20A0CFC1CF
  • SHA-256: 3CA9FC8E5C5943D9D2F154B57B992B0741C67532A70B3B508FC49D079E8006D6
  • SHA-512: B64B736652122BC753BF5840BF6D112A5B840B4046A52263A5A891A10085483FBFE64AC54162FD8E0457B3271B25417456DCA5481324583B0715D42C031E1570
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\submission_history.gif
  • Type: data
  • MD5: 51EEE707896ED56FADA1DBD8DA681129
  • SHA: A194081B92E8B94030ED7E89C3AF23A0521FA043
  • SHA-256: 894A09A9E0604BBD0E8560BF3FEE097428A4FD9530DD4F0E96A52093D18B7E69
  • SHA-512: 07A59CE473AF59685397FF2584E9C4549C6EAA47C9F0E05128FFDCAC40C7191AE397C3A59425D65EDF4C85D5B4DC38D42D05C1E0A9E80225C85AE30C1A4F1665
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\tl.gif
  • Type: data
  • MD5: 8260C315115CA53D955645FD779B563A
  • SHA: A312EFFC8529E1A06EB579B9FE2990C0340B3E40
  • SHA-256: 8CF070FBECE37D77A5DE9354DCC1326DD16BA035A44B459EF8DE28D9098A81E6
  • SHA-512: 67E7A86C6BC957BE3DD54CA026E0BD395BF4762F0C49053A3955866781D01800168D0BD729DB2C21D5DED8BCAE5A0EE0B546C2531E791AC24D6B99FA970343D3
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\tr.gif
  • Type: data
  • MD5: C0285CD5B7DC74B9118B4557352EC67A
  • SHA: AD4758A7DF14CB97E108CCF1CDEFDFF88A35B755
  • SHA-256: 3B4F35C7A22D667B8E04FFBD30BD4070115FD6AA7111E153F04F621F08D89612
  • SHA-512: 32BDCA468938FD312E19B1C3C78C708EA74FC76779A274FD0E6EAE9202D4967613E541173B44B648FF30B0CA716DE7DCC70409EB32A1354EDF5A52571565D3B8
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\trash.gif
  • Type: data
  • MD5: 39A4D606B90D9A345B3C0435BCABC675
  • SHA: 7E605CDEF4A016144CFDA80B0F71E82653CAFFCD
  • SHA-256: 1DE09F408428A10FB44071FAA4E8B983A9B97DD2DB9BA2352A017E55E107F580
  • SHA-512: FE7BCE94DAF7D7FDC4F5C25F13A5590A16E7E3A1F56A084D160E73BF476D9782C715C97538FE376E9633DDB5BB6A215EE034AFE8F40F064AF1FC9821C4AA2195
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\turnOffNotificationInAcrobat.gif
  • Type: data
  • MD5: 7C2F6ECB641C7FA51DC47643FA1D1246
  • SHA: FBB182FF59EECFB17D19800E4375E0B8818FAF47
  • SHA-256: FDB21231C02DDD0554C2A70FEBA1FFBFE9F48792F8059FF02BC1459BF1766FD9
  • SHA-512: F998565387A182F7A7BAB397BCD3F82781F226E4E17D3E781217F09C22A997AEED0AD20DC64EF246FF197033586341D59DA569A6699572C40D323E5A0A05AE14
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\turnOffNotificationInTray.gif
  • Type: data
  • MD5: 4FEF9E93EA40EF77C007F0088F886D3F
  • SHA: 665A881901FBCEBCB0B871518D00FF021ABD8C3C
  • SHA-256: 4B9CA07C2A6FC010527B0EFF4EE18626A6E4946F30D89576576E12CEC375855D
  • SHA-512: 984DF662CE871FCACE2560172BE2AC012B664E8667129F4D2321A70B24BF0FE965E676BCA69FF3A5B3CC664DE2F3C29F5D9178B623FAD54B3289295FC0418920
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\turnOnNotificationInAcrobat.gif
  • Type: data
  • MD5: FE004B6D4C39AEAAF38B8DB98B1021D0
  • SHA: 650B957452A16295E00A92C14DF72C538A8784DE
  • SHA-256: 9903FCB9BBB74BFA295498F569BD33D60456D0F7D6FD70E9EE2E4B5D34126030
  • SHA-512: ABBCD28E9344A3775684910ECAE4E680405F454100B3E164E1B99A4C2B26E0BF6170D84D473B8CB29E0BE07CEAAF0FCF7DC4756A655D263510D103EF84DFE2BD
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\turnOnNotificationInTray.gif
  • Type: data
  • MD5: D33D641EFDC3814CABB5296E83E04FB6
  • SHA: C7C9D5A7BCE6BDE753495F7EAA0A147D1CEA9CAB
  • SHA-256: 0BE3F74335F5619D0E985E1B1E1336386C7C948ED65290FA5419E3008F04C1FF
  • SHA-512: 875F38B2CFFBBFD4975570386C5DF2C1A6143908DAADBD40C81CA24DAC7CD33FB0D37D3AD62A7D0350E4E7B4AF382D88401E75F7EA4273198A77ACC8A11A2858
C:\Program Files\Adobe\Reader 11.0\Reader\Tracker\warning.gif
  • Type: data
  • MD5: 3FA7F24F22D64D599844A9D9F40B5A3E
  • SHA: 07C4325D24F7BC505F63F5D02BBEE16B93B03314
  • SHA-256: 1E4594FDFCAF3891C85DFF2C139BD15FAE683FD5E8BC597422A5D9D88514C6EC
  • SHA-512: 98B907B52E8B885236677B0C2AF4C1668D91A31051785AF3FDD9735F3031F6D00AEC6693CB8E7DE14D8FCC53F0E12152BA9068D1FED6F9020A4FE008B706AA12
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Accessibility.api
  • Type: data
  • MD5: 4A58BCE9334AA82024F89408D0D8851D
  • SHA: 64B79F4ECF231047528D405703518C48DD127393
  • SHA-256: 1ADC0B8EC8162799A9269532DDC9B24DEB2DDA78CE5F91AE7F9E3314CE0B785C
  • SHA-512: D91E86AC8E58B111754C7F6E0A0450623E6893C2C680BB6AFB3C145E2282B45A5A626261F06F904AA5CD041F8C18E80BFD842D8B73C4C387469E4F2BB020AECB
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\AcroForm.api
  • Type: data
  • MD5: B93B508F2110C62254A293D7B3A07D5B
  • SHA: 55A2DD3032632AE5BF310F3AA23C2A89A8EFA027
  • SHA-256: 37F54FBEC8BB653B44D668C7F7BA748718198953C62E423DA51084228357834D
  • SHA-512: 518E9B0DF592CEEC4C86EFA9A2BDFEA56B7D6E8849A3AFE903D7FA43C24557765312FDECEAFEDCAB1CEFF19229124FB2032F9C1B59ACE69BA5CB31FBDAB56EBE
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 926B2B5251942EC17AA8D81F8ABBB2F1
  • SHA: E5700A9C8621EF87EE423893CD165721098BCC3D
  • SHA-256: F44182BC4249510C77222DE5BBD08DB0116DF3B67CB21DCD1E1D38096BED6F84
  • SHA-512: AA0E8B9762227E9CCA5FFC7A6B59025AB5E824DA50FEB01FCCFC1FA48A6E14215C60D4840C0DB0ACDE65D82E14D2A9E077B27F418DE94A374B738EFFEA11B3C1
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\ENU\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 926B2B5251942EC17AA8D81F8ABBB2F1
  • SHA: E5700A9C8621EF87EE423893CD165721098BCC3D
  • SHA-256: F44182BC4249510C77222DE5BBD08DB0116DF3B67CB21DCD1E1D38096BED6F84
  • SHA-512: AA0E8B9762227E9CCA5FFC7A6B59025AB5E824DA50FEB01FCCFC1FA48A6E14215C60D4840C0DB0ACDE65D82E14D2A9E077B27F418DE94A374B738EFFEA11B3C1
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf
  • Type: data
  • MD5: DD0ECE562C8DE85906AA31FB87788156
  • SHA: 5879D9F3CE090AE87F586C818CC04FFD853943E4
  • SHA-256: D1FA0D33B02ADC02CC351F44D9ACB6DFA64563CD7F14AFE75EFE36E589E952C2
  • SHA-512: 5259DE2CD38FD5DEA920370ADAF2B8AEF84F0EAC47179711D1E799324592598780D089E6B34B812A0A1B0D8EDD9061D202535034188DBB413A7D2BE0F1F831A1
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf
  • Type: data
  • MD5: BC4A3064D0BD62C49682A0331821D58A
  • SHA: 2E0FF729008FFD6C515DEB693C5E5AEAAEBD0DCA
  • SHA-256: 7AD253052AA67DB97B676FD6D2AEBE9CFCD5EEFEA9385988E1AA69E5FF42A3AB
  • SHA-512: 371427AE6505A7D11FCA5935312AE34960C9015F1F2206D27FEE509C5712F2BC3225B7B4DD3B06F9FD86A7CD99ED324EF3D32C8143B30BA7CF0896074F71385B
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf
  • Type: data
  • MD5: E58EA1B8A4A56B2CDF5DD4647045DFFC
  • SHA: F64BE317E332687853743EDFE7C187A8450D2CAE
  • SHA-256: ED367BE9903D0E5362E3CDDE9735F1E170D9444EEA78EB81BA980CBE2734BE9E
  • SHA-512: CF74DB7DBE97D349C3942DE22828660636F6E64ACD72F3584D35695A744A527AA849EC4A4ABFFBDC964D839251E9C8E4D67C5425A7D6ECFD87CD9F28078CE8FD
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annotations\Stamps\Words.pdf
  • Type: data
  • MD5: 485C6654C955686826EC5EEA1413A95C
  • SHA: 94C67778D4DE72E1C45F22119A9D671FE4F80C48
  • SHA-256: BB6F3973E1DF1AAA002F3476CCF3631E857F730D94C72CE55271547E81505452
  • SHA-512: C93BC8DE29FB22B3CACBF26C8C34552D1957144CAFFF281080395C2581541F251C8AC959CEF8087049AA430133335BB3CD6DD476D3ED240AFFDCA369D8DA9900
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Annots.api
  • Type: data
  • MD5: C20C9E2E9C02973B57C338086C869A7F
  • SHA: 1B4820E8B48D02F2A24C4260F6EC2FB36A7380E7
  • SHA-256: 47E9B0CF93547F39FFDCB9F9D30D981547F62A53446394BBB8E6D37EB3FB06C2
  • SHA-512: C75EEFE58D099897ECC807254FBDBADE1200A1F7BE6195F5B5B3F6B3C5FF61C6DA9EB6011AE0C3EE6C01E9FDCBE8F893F5985B870FE9474C5B4243EC85327EA0
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Checkers.api
  • Type: data
  • MD5: AA2359B4C3462891441B768B97099FEB
  • SHA: 645D10E1AA1CDC42F78210A45AEDC37C3C52BCFC
  • SHA-256: 8A8BBC125F5EB040EE9ACE9589835CC4BBBB469B5979EB840D73458024C33507
  • SHA-512: 2E821296DB3A31B74DCF513534B60CCD59D99AF382EF6D2B4EC1070A8EC939A2147D17F5667331A8E7C74C68D321955721B468902F873047EF85887058E0D241
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 926B2B5251942EC17AA8D81F8ABBB2F1
  • SHA: E5700A9C8621EF87EE423893CD165721098BCC3D
  • SHA-256: F44182BC4249510C77222DE5BBD08DB0116DF3B67CB21DCD1E1D38096BED6F84
  • SHA-512: AA0E8B9762227E9CCA5FFC7A6B59025AB5E824DA50FEB01FCCFC1FA48A6E14215C60D4840C0DB0ACDE65D82E14D2A9E077B27F418DE94A374B738EFFEA11B3C1
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\DVA.api
  • Type: data
  • MD5: 7B661DBB28491328D9474EA222F73CFA
  • SHA: 4F1E4FF53E5D40C32EAA69D54E8D14EBCA4F80B7
  • SHA-256: 3445BD817D18B028BE8BC9869E7B45651F5DFAA7EA30488A15ECD7ECEA77DBE6
  • SHA-512: 49CDA7824764A3CF3AF1FA260E20338A46601733628D0607B8F4089BDE3F5D88D7F39FE6972B344F7F416DD5F6A6E160DDB6D04B41783979FDC5557BBB02C1BD
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\DigSig.api
  • Type: data
  • MD5: AB6500C36E17903481306B03796FF2BA
  • SHA: 25D2607D393BC74F64E56B03B78E497CB84BC1BF
  • SHA-256: 621ED773B7F978FE7F2ADC9F0D1DD431085FBAD59B1C3D9AB8914DA1068FF4FC
  • SHA-512: DB3026405F139B4A056AA3399ECB0DDF181D031818E4704DF3709DA0473BCC00337E1D46E365980A2E8779EFD96B35405D84FDDC73ACF1A27B63A4FC50577382
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\EScript.api
  • Type: data
  • MD5: 3AAF9AA6C7CBC11C2B177258EF91C4FA
  • SHA: DE2977372DA2F19E6B90E14FCA8AB29E1F419646
  • SHA-256: 3CB4B7C7683EBD74667B74146D08EA92EAE492D3B832283B48AA239DD5394A21
  • SHA-512: D1117C42E53142FCB67EC7C6F74B852A2475BEB2D282EA5A17AB9E2A828B62C138E182C1DA6579286E203B75464547E317784B9FF26FA9AFF50358FB539C341C
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\IA32.api
  • Type: data
  • MD5: CD7D0034DF25516FD738F2E34FED73DC
  • SHA: 2531D5F26D2842762D19FC0FE5383C9067886972
  • SHA-256: EE82C8E5CD820612ECA7B3534669B14CCCBC5D4194DF2EDBEA1B5C0811F00BB7
  • SHA-512: 00D507606D82487D452631B6FA7304B3AA35CBDBF3A026839170B772EBD047AFFFF027D6A0BA4B7875DE73B17E8425A5A6A38B618D7E87ED37FF8C52810934A4
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\MakeAccessible.api
  • Type: data
  • MD5: A129B63B376F0B6F3D84E45C8E9524A0
  • SHA: 8540DADA12A184F9435E114FD6D30B8CFFFDA711
  • SHA-256: A1B2802D00A53F1B3376CBA125B7B9D5D04DD295A866CC373DAB0835691DCF7B
  • SHA-512: 1B5365FDC69CD3B125C40F1C7D34C77C9CB79E72F8CE47AAA8D5EC7AC0C411949891F76CE3F1708C7F76D65DC122423EC7D892022AFD3102439C10FC77CF86AD
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Multimedia.api
  • Type: data
  • MD5: C06589D4D03C532DA0E5D3212EC14222
  • SHA: 1FF62D65F43BA410DDAEBA61144BC35C82349686
  • SHA-256: F4809398E933C3EB40719314CF0AF747D61628B025D21C6D92624BC76B9E9978
  • SHA-512: 319349122447E869F550C7B67A2C413439E7120A89CB4F4524877F5922BC6256D4C8FFF06918A16BD9ED297DD155EA4BA7B610481468F6FE87145CB3B4DC5254
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\PDDom.api
  • Type: data
  • MD5: 07209F40A0E936CB4F0CA42AB975CBB7
  • SHA: 89B5142E1B7A524F015A8B5CBFDCCB4B2935C5D7
  • SHA-256: 68FCADD9BAEB63E3BE6866D49D967F40F24E4C1891AF19870A4E0FD79957300A
  • SHA-512: 9FB4071BE949B1545A7DFC49512BBC3CF0C6C5E347DF8886CBC8805AF01DB8F2268BBB5AB81B917BF83C4ACBBC7583016D3A62C33A0EA4A27F4C96DBE946F9FC
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\PPKLite.api
  • Type: data
  • MD5: 898F1A48AC213AC6B4A763545AC4C8B7
  • SHA: 8784C41DB18CA4FFD1C8059B614589B389414940
  • SHA-256: E908086CD60559BF99EE04807311E6D658A62927C2D78E37187EBD4E1ED765A7
  • SHA-512: CE8024FF2A4645F87E710313F62E456CB3572CFECE05C88B43EED7457913D89DE834B89AB135543FBF346DF6E313B111253292CEC9C57C08F259670DE5F41397
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\ReadOutLoud.api
  • Type: data
  • MD5: 84E4C3C973400B04E76244880C650930
  • SHA: CC48A9698D61926B50F2512C38F828ED04435DC5
  • SHA-256: 1D44DE84A134803511537A5E6F1F2B7A53E8C3968908F4EBB07FDFF84056F85B
  • SHA-512: 680F77D7E26C10C0CF7BE8A0FBA3A4FEC18CB0DA14C9BD416194F45EA084AE2ED6A60F221BF5577D4DEB191D3A1D76E8F3F5193D708E4B89225A39A293C6F2F7
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\SaveAsRTF.api
  • Type: data
  • MD5: 11D2990DE09C21E88AEBE369B9F6E05C
  • SHA: 7CD79B9F3BE6038D927FC74A5E1AA4BE1256A580
  • SHA-256: 9D9756ABF49B3D0395868A23C1658484169BB3B2C188322648BE61AA9D54E6E0
  • SHA-512: 00014DEB116B9838C607E771A755D4FD8D6EA6FFDB06636106E1A0BC561877CC210962EDB3124D8D23EB612E3459271E0659F272A89C08D2E54DC4DE8A5A1894
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Search.api
  • Type: data
  • MD5: 71DADA3FE5B7E259AC21CABA37848079
  • SHA: E8EF349FCB1899BA410960DC99E958A47702E5B3
  • SHA-256: 65BD5B60E060A9D71EB71CC86CB2F5792BC04B0402AFF860AD300B4E360E37F9
  • SHA-512: 2D991EAB2AD968DEE845FF2F47787E36F6618F96847AC9C2E39FD392734F7E2C15554745CB8A9EAA00C56484D5410FF937E5C20CA9540480E19E5C81E3A01255
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\SendMail.api
  • Type: data
  • MD5: 9A7DABB55372AC5F5CDCEF6DEB6F8F0F
  • SHA: 97075B7C1D061987C5BEC21D88BD95A0F6F2A2DB
  • SHA-256: 05BF3AA4EC110C6B808BF75D9ABBFADDCEA78F659D7ACFF8A7FBBD7E1E43191E
  • SHA-512: C25DF7605916A583EE009443D94A504C624A70836C1BE8AB08AD3AA60C2D6CE32072FA2377FF88F066C9905AC354D7F2DF0A343CA160D712E213EAB6EC78DEE2
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Spelling.api
  • Type: data
  • MD5: 6DF9F2F1CEABA3889D8B6C43F5497A4A
  • SHA: 55969305EB6701551F76886066400B5A2417649E
  • SHA-256: FCBB1E6D68895D4C94002D12C360FBE0685E2B09135EB99ECE8E8942E4DEAB4B
  • SHA-512: 1BD8E9348D1FB49CA21D5DC99D572B45E066D0E0011969FDD2511C326CDDFA828D3045F46BFC33E3C00993B8D0A9E71CE6A23E34621CD4A6156B5C7A056C4A3A
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\Updater.api
  • Type: data
  • MD5: 7AF3BCBD3A38E425FC888A74075EE53B
  • SHA: F89DE09B4D27E7CBE39C9825DA6111E5BCBC19C9
  • SHA-256: 67DC8B3E9594DBC85D7A12EDDA8BA7476D6EC9DF8AD81849898E7DDC726433D6
  • SHA-512: 2C7F8F0F7FD74D59D627D502D97AB78C9B7274ECAE181E9E2CA36CECDFC4470EF71EE55FFA37333604E9F9E6006671B85BC6E384719A5ADB8D6076353C02EB53
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\eBook.api
  • Type: data
  • MD5: F8328C4CEBBAEF6EA2F477F257EFDB77
  • SHA: 3A1BF3687860ED01A29748E98FC4658255F68A72
  • SHA-256: 749704039C0F6EA10CA4A65F10DA9CCADF50EC4B70A6FBE1242A630BAF053417
  • SHA-512: 5FECA77D5F204A028AE869889F45CB98D73B5CC53676BCB4C73DB761A07B81B8AFB30C27DA82164A776BFE0682CBEF7447238DEA8277810F16BF113149D209F1
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\reflow.api
  • Type: data
  • MD5: 87D70EBC8B6C310ECED28C17DEBD202B
  • SHA: FA1E6DDAA4FECBF94DD39383D57710F3296EEA7B
  • SHA-256: A48A2942013F1EBC96BBA232D002FCFB5BE837FAAC2D479EFC8B8ED65BA97263
  • SHA-512: 3F00DC06C8A7E8B247818452C011315E5C824DC8B5DDE8438D425CB91A06C074200BDB0987A0A50904FDA8EF96A1C4A85BA59585D1B24B8E46787F26C377F5FA
C:\Program Files\Adobe\Reader 11.0\Reader\plug_ins\weblink.api
  • Type: data
  • MD5: 5F4E31929658E2377E583C401698FC17
  • SHA: 187A3F32C2377A58768472D4B996EE6887BF05A2
  • SHA-256: 7B40DB450128428BFD3696C6494453351D08C58D37ED92739A956B68ECE51C93
  • SHA-512: 3731C6DD53A9C3157823FFF70E6C8AC765BE1CB53F3E5AB68B1146CBD057CABFB54137B7006F23830D24DAE503F838BB5D6AF5DAF6F01C65E4216487D581B67B
C:\Program Files\Adobe\Reader 11.0\Reader\pmd.cer
  • Type: data
  • MD5: 6BA1EE2D52B1AE6B57D303117C4CB896
  • SHA: B41A48D7AD85B821AA752778C78E55C8530E22C2
  • SHA-256: 0BC91DE0310CA5BBC2F3F39AB29FF9847C1284B202FBAE627374D85D3AF0F040
  • SHA-512: DC2FD0D28C504A51549CA080EA6B3220960DF27CAEBF6C88887D2039EF1B56EBD3705E6A523DF51F1D7247D822684E3E92700053AD1B06EDB901542C0DB5D2D2
C:\Program Files\Adobe\Reader 11.0\Resource\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: E9941882A06EABF170E3CEBFF4CDDCE7
  • SHA: 8DE6196C2371E2F926D9B2405F6E61ECBC714092
  • SHA-256: C2519EFFFBFCB3DCBA2C46CCEA6319C6198938F5666E9218EAD77E23D9464C07
  • SHA-512: B9CF308AC2909F6147A58CEB5457CA77DC89D2CD3C227622D811322681B8F8808A1726BA09A6036EAC5FE3F3469698B419C1FAE48CA6A5B93E8856D4771E3304
C:\Program Files\Adobe\Reader 11.0\Resource\ENUtxt.pdf
  • Type: data
  • MD5: 42A4289E3AB803820FD5BFB3556D1704
  • SHA: 156DFB9AD3F1C8328C8E261364964C77E168919B
  • SHA-256: 7535B3CBD7FFE60A06A8E1298EA8465E24E341333A2030502C5081B612AE86DA
  • SHA-512: 9038C9F478184A06097FD778630EAFF389EB4930F8A90585F18D0054D3F30F3E4C8816745AB1E198525A37239107DD01578A2E0A1A70C96FFF678E03B0DC6D4A
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Adobe\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: B4EF525B615CE68EE9A89AE424BE7C96
  • SHA: AB9CEE5FD2A96E711249EA6B62B9C83C54690F56
  • SHA-256: 3F2AF89DA8CB1768BFB103DF47DF3941C9F3F6DFB7A253283B69CB2A3E1974B4
  • SHA-512: EBA0A7B9FB1BE3EFC82EA32C76EAFD775AF3F5DA29C903465D964073514D49ED0723A0048DCCB850445C2799DC7D43856EF981F6C997EEAA07D748D6720B4037
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Adobe\symbol.txt
  • Type: data
  • MD5: 720F8B61FC36C438FA7CC2B239195BE7
  • SHA: F55533EB06EEDD10335160AA8D05A481BEAFDD21
  • SHA-256: E4440574DF57C9E4A116279C8F9CF9D1E3D93D46C7D1234A316ADD1E2D2D4602
  • SHA-512: 4F2215109E30FF1243E589A88AAE1B7810CA6588428329B5E791D425BDBD888B530A97B23A43058BD2B1AF1F5D596AC22AD7617C9E7F98664CC1250F831F9AE3
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Adobe\zdingbat.txt
  • Type: data
  • MD5: 796D940A4E37B3C9DF03223789AD2C9B
  • SHA: 02322CCC5AB18AD9C43FC4064A8936A732454BE4
  • SHA-256: FBCFDD4ED4AA4858D5C124E842391814A06BC238A60D4167DEF10ACE7714420C
  • SHA-512: 6A7606C85FF6A1B2B8EEBAB392EBA69177795EAFBF7EEC11E48E60AEE9C18888C9EA22F218D813FCBFA50C732A01BB8403733DB683CA3240442BEB586E49AE38
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\CENTEURO.TXT
  • Type: data
  • MD5: C1F95379A036A63175AC477A708D1CFD
  • SHA: 79EF41CE00C4CA3755EF7A8553708585CF7B67D9
  • SHA-256: 88A201A0648CB009843C39CC6B988A3DB53438568C8AFEEB51921FC33885229B
  • SHA-512: 56389BBAC86145432061B8C1183AA87999DF12E345F9DEBD5CBA875C809512D0992CA744547303B36B04BF679D31CAE734D38668C74EDE7AEFAC6B636A4C36FA
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\CORPCHAR.TXT
  • Type: data
  • MD5: BE588FF8161F4816E07CB09674FBD0E0
  • SHA: 8230F5DDB1ADFC8D948B0AC102403C4BE9F33C76
  • SHA-256: 4DD2C76CBF7822AE4F272A6B76C871F86502D093C3ACE8ABDE935F7EEE7DBD87
  • SHA-512: 2590C5FFBE3E70192562F50F5AD11BB0E567E2A23E377CD37B822FFEE6E3734BEE58869345CAE2DAB19602AE746E982A42135A894DA25DFD093A1B8C034B011E
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\CROATIAN.TXT
  • Type: data
  • MD5: B1F6410FE5F16859B3AC4F9249DF4E00
  • SHA: D93F7CB4FE87E2A3E9488E0C0851D5E4B7D5ECDD
  • SHA-256: 8D3A4D0F760CFE44090A3C1E4449E82ED56B203C7645374546F089EE8F08DAC8
  • SHA-512: AC1C1C84A4DB6EB2B389D085DA2B654FF2DA422F68EE9675DD3ADADD5E2BEB10950BF6CDC27D27CCB9F56DC56CC11C6EDFA05EBB059C8A62196133E9536BA456
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\CYRILLIC.TXT
  • Type: data
  • MD5: 46989562BC13E47AD20FF7492AED976E
  • SHA: 206CD87E6D64D7DA29BBEC44DCF222831F69CA38
  • SHA-256: 9EFD351AB8E583CE49DCBC575715CF4363996F1C1F0EAB1D092FC04385928922
  • SHA-512: 6DAABD19A6EA5147BAE5A707C7DB54AE9C3845B8AB5CAFB47847073F60EA34756E262D1AD5F5E1256F0739C417BB5E453D35B29F9AC963BA11A31FC69A2878BA
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: E9941882A06EABF170E3CEBFF4CDDCE7
  • SHA: 8DE6196C2371E2F926D9B2405F6E61ECBC714092
  • SHA-256: C2519EFFFBFCB3DCBA2C46CCEA6319C6198938F5666E9218EAD77E23D9464C07
  • SHA-512: B9CF308AC2909F6147A58CEB5457CA77DC89D2CD3C227622D811322681B8F8808A1726BA09A6036EAC5FE3F3469698B419C1FAE48CA6A5B93E8856D4771E3304
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\GREEK.TXT
  • Type: data
  • MD5: 6EDD7FD660342AAC7899CC54D1630B24
  • SHA: 43BFD8D2C80BA631077698527BAF4242F057EFED
  • SHA-256: C71FA02AF67F1D758674972BE7A822EE482722C00CFAEC64D7C3F01BF4346DD2
  • SHA-512: 66CD2072A0A2639AAF0D2255F2DC1BA0F912028A7C61035B24D314EB64E5A73865970B27B38313BF526053074F29C868687FE079DAA02CCCAC59DAA2F078E8AC
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\ICELAND.TXT
  • Type: data
  • MD5: 22E2E9C10FB0D8C88B7F184BB5260AC9
  • SHA: DFBE14A9ABCED5C2BD1EDEF820837115A9676BD9
  • SHA-256: F6438D73F6C4D2D2ECA0A16270C581D782D65BC878F07E408DFF7B9D29820D79
  • SHA-512: C2C12F0371B051D63B2E5F9E2F00A3E12876BF8F346C432BBE2755562AFB422FE410A886FAC892B67CD9AA259D2AAD12FD8D8E6DF996B491E26DDFFA7F011669
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMAN.TXT
  • Type: data
  • MD5: 783B0A385F98E4B3338C58BC232C1670
  • SHA: 432A9BBE369CE86DCED3490C249C934601A8F047
  • SHA-256: 758D5D704BDE65CF04D0F620BD2EC1E794136291EC0151BCA13693A662A891F0
  • SHA-512: AD82185BA61E3E175E6E8E741D062793031161D916F0C689513DDF16E9A5C7734C5092D0EF98B11FA7D3241DBF10FC074469AF8804778D9C17C14A49452AF81A
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMANIAN.TXT
  • Type: data
  • MD5: 7B929719CF4AF6F78859F5679DE8CC6E
  • SHA: 88D517834519FC08C526CD4546CF3647329E2D4C
  • SHA-256: 9B498BBBF5AE857F6CE7F806ECE501298B2374D0A02EBDA589E02E08FB0C9129
  • SHA-512: 6510FD31674FC3E8F4D961E271FDAC2BEF3FE47D4321EDB7F69B6E6957E43CC38E62F6989383D73D44F85F54DC486AD4991D414555FCDE82D8C0D8C9E81AC947
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\SYMBOL.TXT
  • Type: data
  • MD5: 638C07F8B398F4B4875C117D564978EC
  • SHA: E2E0E263207E7E451440517682AFB34A0538CB47
  • SHA-256: 18DDD726844182B0398CB466008F6272095122883A5187DC8AF701B784601662
  • SHA-512: E945CD0486BEA43BF1BE227979678E01479DE613C1DA2666F932D00CAED6C86BA296E37EF308005F8BD7DE33D9E690DB42947285614DE3CB8B0F4EA1E04BA186
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\TURKISH.TXT
  • Type: data
  • MD5: 1D300C7D3F25CF6E376C068D5ECAF771
  • SHA: D13B6C368900EDC734F9DC42E9DB1A63321F430C
  • SHA-256: 252D1E149F65197817D3EEB096E61184D07E21628F8796C8B5DBF0FA2C3CE692
  • SHA-512: 66C05529CF83DE3C17C6E2245C70D4784CBB7A693D923FE3EA6193B600D1CDCFBDFA79E25FF84D222E7AF1E325D26D7CA070E08EA28972DD27C9E666C5F89C40
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\Mac\UKRAINE.TXT
  • Type: data
  • MD5: 24885E6E2D828A01E37328E7EF09EDEE
  • SHA: B75DB6D32B2F5C31CE79ABBB47E14685085C4903
  • SHA-256: E3E9A049257A858D4BA9F6699632261A85126BC9631FA16BC2FD5EDE33506FD3
  • SHA-512: 7C93C5572ED8F35D84EAEAC0DA2711EC3BC72EBCCF77838D41EEFB24C2463E816085391719988138D177D5F6786DCE187628E790ED94B4898BB9931EC20D7BD5
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1250.TXT
  • Type: data
  • MD5: C061F57C71F5E2E9E03A6060D54E166D
  • SHA: A12DA30A6062E27E50A66099DA61BF3AF8484534
  • SHA-256: 3F96A316D6BAB40FBF236412FFE2CBBA882DF2487D4493C6168FC1FE31F5BC6C
  • SHA-512: 85F5F392957AA2B04BF412C89C8F526B5ED1B2B047FC072936C01D30DFD0F528E376EBFAC705F34240C8D5B020CD13A270E23C57DF6178B1BF42AAF2BE869D2E
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1251.TXT
  • Type: data
  • MD5: 0BFB15012076A94191475CF5A74858F3
  • SHA: 75D5C5816700D1FC24029B228FD87FFABDEB6070
  • SHA-256: 7853F3F92449E9C64DD229BDE3A1E4EC260F186F293BD7C0E4B17F69398B0496
  • SHA-512: 3F1605C61C0E6EDEDD96B4D11048DA2243BB18192776517DA9AB26FF900B87BBFC0EFAD553F04C0E2B1F8D6A91DBA86E2D36A6B98CCBD3CFBD5CD2F51EEC11E0
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1252.TXT
  • Type: data
  • MD5: 9D9E214C8FB5099F399F2F4357ABD34D
  • SHA: 536DB5DC8AECCE1FEFF522EC137039C5B6E7E947
  • SHA-256: 46025DCD3377DF6A76966759839ACDCE70392102F8C950E49552E8B1CFB84F74
  • SHA-512: CF911A1782C75BCA366C2EEB9BA943A481B756A3CBD0275FBD401E1D4B5EAA3E717D39716EE712A1A9A01C3FF293A30B51F096653179869130FFF9CC03E23474
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1253.TXT
  • Type: data
  • MD5: EB545AC2ACF6DD389FB81A2302ED1D35
  • SHA: 01C501DC7C251A85CAA52437ECF3FB3127CC6FB1
  • SHA-256: E2E0F40F72E06E5774ECBE85B98412CF4B9440049FD3D292880A90CCEA76E325
  • SHA-512: BFF8857F993CA8C314BF8584339B5336E973477AC76FE5BC90773529ECB77C55D06CA36C465583CEE7C1AAF138C6D7B49F27F728F2E265E72BF97954EBD8406E
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1254.TXT
  • Type: data
  • MD5: B3F6ED32528FCB5ACCA8B9EB4EB55A97
  • SHA: 10C30A539F07EC1014FBAE31B726DA76CB4D5B1D
  • SHA-256: F49420CACB58B776C5050FE4DFDD3D21B483AA83276407584AA9E69EFD1B9099
  • SHA-512: FAF2E7204F5032EC4D01E7A2BE7371A867B20F0B09EA7824E64A124B1E3D095DA3C870CB1FBECC5EAB03127596BD8AAA688002D07542ED6009D3CAC0F5C7D4A3
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1257.TXT
  • Type: data
  • MD5: 7E84C16840669F9B305D15A8122F6D9C
  • SHA: D0B2E17BC3E11CD2CD487D4AC7F059B400F9EC9A
  • SHA-256: 40D80293AEB0B2E156422E0CDBF5AF9E6D619901612245C185F620F7CD7248D4
  • SHA-512: 52FD5C23FDB0228B2525FBDE7DF36CE1CA2261479A30144AE592033075AABCBA3F278F9CBF26562583E28BEF0A565DD9D1A686071C6DFD522C483E7D069A437B
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\CP1258.TXT
  • Type: data
  • MD5: 034EDC312FFCE439DCE8C3BA1AE4226C
  • SHA: 4C6606BBD20974F86CD2FA34CEF771DD25FA29DA
  • SHA-256: BB1AE5A12A26383AB3AA6D7AE02CF6DFD9E760CF1C37C5D7077AE31394C0782D
  • SHA-512: 676D445247D9A7860D5BAFB963BC3E8A6D9C733FD3A29D45D67557421F8D1F40D62DCF5AF953B95E25FF02EE965D102F5C84B1C2274E7037ACD8C9AC2012F794
C:\Program Files\Adobe\Reader 11.0\Resource\TypeSupport\Unicode\Mappings\win\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: E9941882A06EABF170E3CEBFF4CDDCE7
  • SHA: 8DE6196C2371E2F926D9B2405F6E61ECBC714092
  • SHA-256: C2519EFFFBFCB3DCBA2C46CCEA6319C6198938F5666E9218EAD77E23D9464C07
  • SHA-512: B9CF308AC2909F6147A58CEB5457CA77DC89D2CD3C227622D811322681B8F8808A1726BA09A6036EAC5FE3F3469698B419C1FAE48CA6A5B93E8856D4771E3304
C:\Program Files\AutoIt3\AutoIt v3 Website.url
  • Type: data
  • MD5: 850AB14F7DFBBBF6E1561BB329229BA3
  • SHA: 11D3ED3714376DF5B50EEF9FAAA2D172BEA1F50F
  • SHA-256: C5A6BF5EE9CE0DCFBE1F02AD5235BE8E7A2D5E330C5A408A8539F7198A827D3B
  • SHA-512: F256685ACF4BB96522895E6291EFBA34799411A67ABDCFD14176A62291380FD0969CA3D5FC3E341D065C0E6A1FE2B1F6DA9A5B2E4221C6226DB6C417B7BD5797
C:\Program Files\AutoIt3\AutoItX\StandardDLL\VC6\Example\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: AE025D11011062975C4E9D24E1BD6A5F
  • SHA: DECBD33685519C6A6927E6AC45D0E6D229627350
  • SHA-256: 90CB9E179E5BCD9E5E6600360422A463915BC5087C3BDDCE068DA2EF4FB2FB33
  • SHA-512: BEB57BEB8132B57CE9F97FDB2EDB43F6655AAF2C5DD60FE89C0E8209AD0C2BDA8B24F04BB4290EB3C82AA1B0D6154B93C40A732C9549E72D1933E4BD8E9C2F0F
C:\Program Files\AutoIt3\AutoItX\StandardDLL\VC6\Example\main.cpp
  • Type: data
  • MD5: D0D1E8CC5D112E8D84C64234FAC13093
  • SHA: 36848D067F199C4C923D5B9AC081A92F8F622C5C
  • SHA-256: ED5662C159A76BF491703825A493376AD2B37458B5788FE54F70F8C2F32741D4
  • SHA-512: 4DC47AF7982A38233EDF53740DBA552353DC4EB09436AF712D6ED25802A0AC00217459979F2CEF577778CBBBC5FAA2858F73155FCE90900D3E93C72D6E092DB5
C:\Program Files\AutoIt3\AutoItX\StandardDLL\VC6\Example\main.dsp
  • Type: data
  • MD5: 98EF236A8A29D580ED1D3A0582786103
  • SHA: 87E3EE478B3F94EAB3FB7A4174C3C8FD59395E5C
  • SHA-256: 300415B8A523CE07148A5C2C03E6B3F0C5DC70279FBC409A4769B694189E2803
  • SHA-512: EA96BE13A2D87B5B750C314FE86802BE8ED4AFE0E1178A309AD1FBB48FCD528DD7F3C56DE269D952A19919CC5611233605B2CA78F2EC7BC02C62ECCC471E5BB6
C:\Program Files\AutoIt3\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D10F531E9BC5059FF6E0AE19C58A8020
  • SHA: 7FBB5911D45F9784F935B2A25B0915FED0A163C2
  • SHA-256: 4BF346CBD4C2CE3B18643562CE851FFA6909DFDF2A14D62070485219E5097E97
  • SHA-512: D235033A9617FD1B1779B6BCFE269399EE7FCF001355E7381D7A6444202C96D32FB3EAF17BFEA753661A582727FFAB374FAD87F54D489E674A68BFE2910B0C68
C:\Program Files\AutoIt3\Examples\COM\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: AE025D11011062975C4E9D24E1BD6A5F
  • SHA: DECBD33685519C6A6927E6AC45D0E6D229627350
  • SHA-256: 90CB9E179E5BCD9E5E6600360422A463915BC5087C3BDDCE068DA2EF4FB2FB33
  • SHA-512: BEB57BEB8132B57CE9F97FDB2EDB43F6655AAF2C5DD60FE89C0E8209AD0C2BDA8B24F04BB4290EB3C82AA1B0D6154B93C40A732C9549E72D1933E4BD8E9C2F0F
C:\Program Files\AutoIt3\Examples\COM\Worksheet.xls
  • Type: data
  • MD5: F20AE552DFF316401999866BD17E4EBC
  • SHA: 7A2838839ED84B11DDA84026C51B759148E91A57
  • SHA-256: 47F1529966C59DAF1100268322B416014E722D3FCDCF7E4EF1EC923A54588B6D
  • SHA-512: 85AD89937A3872A1764BB227380EE83051F619F4B1A527BB1DCB4097E41CFFA054D24AF35D0860DCFB9E47300F02110294242E75E6E19392306CEE2588AEFD7B
C:\Program Files\AutoIt3\Examples\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\Examples\GUI\Advanced\Images\Blue.bmp
  • Type: data
  • MD5: 5E35C1597E3F9D83C421D5B623B0A755
  • SHA: 685FA71397910283707F9BD641B76D4237443B2F
  • SHA-256: 517190A583C29A71D1A64FE93F453654721062059B512C9FD13137D966DB4809
  • SHA-512: 55FE53E67561BAE30171F4A69414B7937D51456DA472D12BE019A40E82B11E20079D4ABAEF322D9749CE1B4B1D954360CA1C3498FC0E0D35569BC98A0E94195F
C:\Program Files\AutoIt3\Examples\GUI\Advanced\Images\Button.png
  • Type: data
  • MD5: A51690169250FC63AD1C9B9F9DDA9516
  • SHA: 580339EE698B40B59EB0B0FD9CBC5AE75F6CDFF8
  • SHA-256: A14723143CD5477C2472A56C4DDC2253D642E973BA717E627825558C658EDC59
  • SHA-512: 2D897490DA4481227FF950811A8D32B5B8B567495BA942DBA6A31DED8E79617FB57DD93824519FE5C3B70AECA1B605D22F1513F3C72F4F266BB7F61D6A194535
C:\Program Files\AutoIt3\Examples\GUI\Advanced\Images\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: AE025D11011062975C4E9D24E1BD6A5F
  • SHA: DECBD33685519C6A6927E6AC45D0E6D229627350
  • SHA-256: 90CB9E179E5BCD9E5E6600360422A463915BC5087C3BDDCE068DA2EF4FB2FB33
  • SHA-512: BEB57BEB8132B57CE9F97FDB2EDB43F6655AAF2C5DD60FE89C0E8209AD0C2BDA8B24F04BB4290EB3C82AA1B0D6154B93C40A732C9549E72D1933E4BD8E9C2F0F
C:\Program Files\AutoIt3\Examples\GUI\Advanced\Images\Green.bmp
  • Type: data
  • MD5: 3376A219C974F450DC794560796AC510
  • SHA: 66C18A2C0806FAEF6B68CE43CF51FE3580D9C68E
  • SHA-256: 3B958A39BABF98B23CD6AE9DFBF57EF0683B186AC7F1FA14C2A97FF1C72D9C93
  • SHA-512: 0E87DB0BC5A10FE895AC4E405D9E0A81B3DA51B2952A1F7A4D1D0D85F8019538CB544BF78948C7EBA2C135749505BAF0DF83807CF8C3AFC3B112EC3E4D61669C
C:\Program Files\AutoIt3\Examples\GUI\Advanced\Images\Red.bmp
  • Type: data
  • MD5: B831592E2EE2978482B590D404D786D8
  • SHA: 15771519547C47E0B6226A487DF86EC54BA87116
  • SHA-256: D6230B6FEAE258E777130E6B2540B94020EFA10C2A9CA4550B3112F66AC05E38
  • SHA-512: 9A1745246387FC08251E83BE716D54208F79942CC370E39C30AEFA6DCF2DF5F241A382BE366F275A5392E30AF3E01F7DDB686777BDB9C2A3589E645AABCF2F5C
C:\Program Files\AutoIt3\Examples\GUI\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: AE025D11011062975C4E9D24E1BD6A5F
  • SHA: DECBD33685519C6A6927E6AC45D0E6D229627350
  • SHA-256: 90CB9E179E5BCD9E5E6600360422A463915BC5087C3BDDCE068DA2EF4FB2FB33
  • SHA-512: BEB57BEB8132B57CE9F97FDB2EDB43F6655AAF2C5DD60FE89C0E8209AD0C2BDA8B24F04BB4290EB3C82AA1B0D6154B93C40A732C9549E72D1933E4BD8E9C2F0F
C:\Program Files\AutoIt3\Examples\GUI\Torus.png
  • Type: data
  • MD5: BAEF8CA065570713C8FA6EE5F7589332
  • SHA: 5FB64AB2CF2F57AEF09DD1851AB4C3B6EE43B09D
  • SHA-256: C9ECA134CB07BC50DD643874D17953A0BDA2D065EE0AF5608A5C509A1AFECA24
  • SHA-512: 3102B5F428CDBC2B94E5EFD6600714EF8AD41B95B834161CED4DC45F60DCED85AEF343BCD00C3AB85EBDF74EEDAAB773C3E02F135BD0523D41EA746B9AF32575
C:\Program Files\AutoIt3\Examples\GUI\logo4.gif
  • Type: data
  • MD5: AA08533DC23D726329D431D75AFD6CB0
  • SHA: 1A25EA192AF6E2C57EB0EAFED5A49CC71DA979F4
  • SHA-256: B508BB1040450352387063E0B7B1A722ED409F4F3295B4280A7902552472360D
  • SHA-512: 8C9DD09E93950BABD6D05A3734B0ACED6E587B1EB20016EC40624322C1AC1980A41948F061586AAE7F54852788A3E278D8CC6597D59257845A5FE9C30A37A4E9
C:\Program Files\AutoIt3\Examples\GUI\merlin.gif
  • Type: data
  • MD5: 43C3092D6D06A43338AFF6F98C10682E
  • SHA: 3A12BAF921239507D31BE4AE51E847EE1B48C88F
  • SHA-256: 3A59E59D6E842B619F169A3D0E508144AFDF68E9E4D59951CBE4FBD67A971278
  • SHA-512: A80F7F62DB83B154EB2C1FF7C78A38F57535D5D109002828D210DD253766ED8D435A2A2D0FE3F40C6B7945483FC17F28F397D0B86E0FC6B3CD9F73CA7322D372
C:\Program Files\AutoIt3\Examples\GUI\mslogo.jpg
  • Type: data
  • MD5: DA31C4C290243D663E3160BC0C628392
  • SHA: 8C496E0102B9BAA0A52F543D509C2DFA19C785AA
  • SHA-256: 5F61D3F4E44EE3B818F8D71BB1884E02373654AE259A21FEEC8FE2AA8B4A4AC7
  • SHA-512: B587707977DF46CFDB24AB9B61923AB07707D52043A4B7F7932BCBBB71E4F555FCC31D0A0337108C8D5AC8E19934EC3EE93E7AC905CEBD7966249758D16B61A8
C:\Program Files\AutoIt3\Examples\GUI\msoobe.jpg
  • Type: data
  • MD5: 9E609A638063A1B649CD9763774D74C1
  • SHA: 047AA6269AFB0C630F286EA6C995D495557C8A16
  • SHA-256: 5761B1F74939BF5C75AC026759F3A39DDC6E75182079A0562F8EBFB210FD9543
  • SHA-512: 4C6663426682F5CB11A450B32EE0AE3B7ABF9ED284CD78BBED21864C346325916D77553EBBBCA10B2FB567211DE88BA59DA52C85FFFF99C95DEC6CF6EBCC7D17
C:\Program Files\AutoIt3\Examples\GUI\sampleAVI.avi
  • Type: byte-swapped cpio archive
  • MD5: E77B3EF6AF391966EB57E37980E5DCF6
  • SHA: 269D0C66E933AB4740331E4767051ED82EAA9DC2
  • SHA-256: D49336B339269F940D3A9E0A0DDA7275FEDBC7E5AC7BD899D816EB0032CD11CC
  • SHA-512: 3B955FDDB9529DE22BCE5CCA47F7FE4D3D86025CCE063767EE4342D38BC2E9676AE22B740D8EA9F7446C2A4DC042CEDACCCCE52B1F9D5DC538463C2DD6D045AF
C:\Program Files\AutoIt3\Examples\_ReadMe_.txt
  • Type: data
  • MD5: 0048BD7252E2584DB3687AE3CC7036E9
  • SHA: 329EAEAEBCD92ACC7ADB7303981F3A7B23C1AE13
  • SHA-256: 9F4A282794506ABF0121900AF103269765A2CCA61E35B4F8F1F51B5CDD4CDE88
  • SHA-512: 0474BECB79248F24EBB85A2C66494B8A4401EF3FCC6647630F92A5FCF3356B4C1DF09BA20C826CCA809495CBE60F4662C44D759F76D39E9630187041684EA92B
C:\Program Files\AutoIt3\Extras\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\Extras\Editors\Crimson\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\Extras\Editors\Crimson\Manual Install and Notes.htm
  • Type: data
  • MD5: 098D28E28283E3E570DF6A2BBAD6465A
  • SHA: C4A1B72BF447DC9986E15F29551CB0C0C9A0470E
  • SHA-256: EA13214C1E111A31206DD23A930365B2538CF162578E2881785011FD8FD5E874
  • SHA-512: 1DB3E4EB1F5C66E58BFBDD4C23ED88C5FFB4A3A0C9DB67BCB1D7EA2C01EC88B38EAA92485C73E3E73DF9F8DDA402192CA3104FC1222B76724241129380A8D2FE
C:\Program Files\AutoIt3\Extras\Editors\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\Extras\Editors\TextPad\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\Extras\Editors\TextPad\Manual Install and Notes.htm
  • Type: data
  • MD5: 1458C4F4932D4947CF3EF084E77E6525
  • SHA: D39DBFB0843773B51DB9657C98CB8968E5681534
  • SHA-256: 5374A83DE5337E4846982D6FDF1949381CA342C59534CCEE7948A258A952398C
  • SHA-512: FA7043A127AA876458ABF03597C54DE7EEC68282A91F3AA1623723C4DA809A3250E1C2EFB8A7AA4FF81B6E6D144DC9CF215134F8736ED0E3849481C6959B6297
C:\Program Files\AutoIt3\Extras\Editors\_ReadMe_.txt
  • Type: data
  • MD5: 3120528B18B7F567897CFE3C7615FB73
  • SHA: 991CD7C80014D4E519838E878299CCE37182DB3A
  • SHA-256: 3A6D5FEA212061FF3B21C6328B6818BBA552558F702D4CB621978636B8F65083
  • SHA-512: 0CBD1C285D7649654B9401F48A8CC37AD51445E0E7B9D25D62ED671FF4D426A1AE177452D1E87C31597E26FA2E6561F672540DE15EACBB9D096ABC0D76A1CB97
C:\Program Files\AutoIt3\Extras\_ReadMe_.txt
  • Type: data
  • MD5: D99FF1DC99A61FFBC625EA4EB3440F56
  • SHA: 7B0B6702EFB5629A046771733EC82F1E21FCEDA9
  • SHA-256: FF24860E96243850E30CA21E3FCDE36AE3C0B184D5A6C8A301D64CA463AEF22C
  • SHA-512: 2D322F83896B4E0330C42583A0E62F7CAE738648092E44E604D6BBDAFCBEEE214F1CF1C09E2786FAD181D046FB1405E7FE69B794FC7E144733FDB91A888E4BCF
C:\Program Files\AutoIt3\SciTE\api\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 43BD4E4A77C4DE6571FC011ECCC63BBC
  • SHA: 2F81E9AAFDBA41B37091B12EFA7E2870A48B48DA
  • SHA-256: E8EA7319347DB97C5C8E01C7CC39CB63F0EE9CD42C0DF6600462EFC2D36F9264
  • SHA-512: 64538D79421426CCFE0ECE804E65DBB21E34895D4A1E8CD12BACF1C02976082D47BACD64546A1156E3F9A3D6A511C087FA8BE123F7E269B5887AA259CF9F0A16
C:\Program Files\AutoIt3\SciTE\api\au3.api
  • Type: data
  • MD5: 1E8D47365663B64260040F5965638132
  • SHA: B0295F0CF1D5F790AA650795FB330D635E8F8782
  • SHA-256: 0987C4760E44C428D0E9807955B20E3F75DE5D30CFE3DD51BC6CB7E03E6AED30
  • SHA-512: 080CB09BC2A469114FFD4E7CE5723764C50A7D22ACB101710CC6AACA84FEBD2C0DEF4662DAB635AF4176A05C32EBF7489A1A2B1515CBC3F1132B54E4A4E13DD4
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D10F531E9BC5059FF6E0AE19C58A8020
  • SHA: 7FBB5911D45F9784F935B2A25B0915FED0A163C2
  • SHA-256: 4BF346CBD4C2CE3B18643562CE851FFA6909DFDF2A14D62070485219E5097E97
  • SHA-512: D235033A9617FD1B1779B6BCFE269399EE7FCF001355E7381D7A6444202C96D32FB3EAF17BFEA753661A582727FFAB374FAD87F54D489E674A68BFE2910B0C68
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DisplayLanguageNames.en_CA.txt
  • Type: data
  • MD5: 771069250B1F3BD9DDF4119CA030B249
  • SHA: FDA83407F5146B11FACE638579422929CC28DB8D
  • SHA-256: 2B9882BBB1EB5B2191379EB66D928E53391C408F21C152AF5F6E108ED6A342D1
  • SHA-512: 7BE124B3C03F7F190013054547CA0DFD496C347C6749A2D579D0828CB94D8B7AD16E5F3723750595E251EA32BEDEA274AF3BC220FD514DF0A186788A09E5B388
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DisplayLanguageNames.en_GB.txt
  • Type: data
  • MD5: 771069250B1F3BD9DDF4119CA030B249
  • SHA: FDA83407F5146B11FACE638579422929CC28DB8D
  • SHA-256: 2B9882BBB1EB5B2191379EB66D928E53391C408F21C152AF5F6E108ED6A342D1
  • SHA-512: 7BE124B3C03F7F190013054547CA0DFD496C347C6749A2D579D0828CB94D8B7AD16E5F3723750595E251EA32BEDEA274AF3BC220FD514DF0A186788A09E5B388
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DisplayLanguageNames.en_GB_EURO.txt
  • Type: data
  • MD5: 771069250B1F3BD9DDF4119CA030B249
  • SHA: FDA83407F5146B11FACE638579422929CC28DB8D
  • SHA-256: 2B9882BBB1EB5B2191379EB66D928E53391C408F21C152AF5F6E108ED6A342D1
  • SHA-512: 7BE124B3C03F7F190013054547CA0DFD496C347C6749A2D579D0828CB94D8B7AD16E5F3723750595E251EA32BEDEA274AF3BC220FD514DF0A186788A09E5B388
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DisplayLanguageNames.en_US.txt
  • Type: data
  • MD5: 771069250B1F3BD9DDF4119CA030B249
  • SHA: FDA83407F5146B11FACE638579422929CC28DB8D
  • SHA-256: 2B9882BBB1EB5B2191379EB66D928E53391C408F21C152AF5F6E108ED6A342D1
  • SHA-512: 7BE124B3C03F7F190013054547CA0DFD496C347C6749A2D579D0828CB94D8B7AD16E5F3723750595E251EA32BEDEA274AF3BC220FD514DF0A186788A09E5B388
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\LanguageNames2\DisplayLanguageNames.en_US_POSIX.txt
  • Type: data
  • MD5: 771069250B1F3BD9DDF4119CA030B249
  • SHA: FDA83407F5146B11FACE638579422929CC28DB8D
  • SHA-256: 2B9882BBB1EB5B2191379EB66D928E53391C408F21C152AF5F6E108ED6A342D1
  • SHA-512: 7BE124B3C03F7F190013054547CA0DFD496C347C6749A2D579D0828CB94D8B7AD16E5F3723750595E251EA32BEDEA274AF3BC220FD514DF0A186788A09E5B388
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Adobe\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Adobe\Products.txt
  • Type: Non-ISO extended-ASCII text, with no line terminators
  • MD5: 59E26DFD38BDFD2D9428C4584A02F432
  • SHA: 256920E1B35E91BE92B4A78F262D973893567F87
  • SHA-256: 41DD576959007239E482C7DFC8C01B03A8262D7F51ED591109B696ED9549E364
  • SHA-512: 0629D6AF80E172BFFDFFC72295BA0FED104BB73D6AE2538A955BFF241806DF8F40DF1BF14FACF92F16E944B8A6043641D477C06802182278C5FB67C1FBA144FD
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_CA\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_CA\List.txt
  • Type: data
  • MD5: 11F998C7B974BBBB43A58D97DC265DB2
  • SHA: 5C8853713E1CA6E1ED2858E636DE7994A9269F84
  • SHA-256: 39A21F3437E51D0B5BADB3B5D679944442C6126DF28AE9BC649F3ABD4AC50B21
  • SHA-512: DAB54431152124C7757A48799291F370BBAC654A5AB1D7AA5CCE600FCE5594ED00726634E7A2A1E44D703ED9ED5F96258A57B9C7E77798E5079B998E45CB6C7F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_GB\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_GB\List.txt
  • Type: data
  • MD5: 9290DB3DDF44D5D0FC9544789995FAEB
  • SHA: 2E06B06E59DB31D8D1252CCCDEBFB3EFC09C3D2F
  • SHA-256: 6FA9A9B460C59F57CA825510BF7C25A8002F6F32116545E82536CEE77EFD5600
  • SHA-512: 027FF6A36A7F062847E70D5215EE0F5C1658B9D9ACCE2313005F975D158EFF74B09F29E9F8C58C4148DD413ECB476F0E2E8B47A77328A664AD4D58E7D71EBA9A
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_US\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_US\List.txt
  • Type: data
  • MD5: 2B5A8A0B21BE0184795160EF47201744
  • SHA: 2733BB2CAADC5ED8726EDDCEFDBBA14F9DAD812A
  • SHA-256: 9280C298792AB8ACDA1FE23C1A29FF0E433D44EA702C3A596B730684E0026C7A
  • SHA-512: 814307282654157A6F935E4C7ABF0E1B466FD53E305D46D3310186C1C116900411453B488DD7F15F25F77AA8C1613DE4619CB8674D5994FC220C2631B4047E7D
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 37ABDF1B0475A4ED3F70DD3B743260E8
  • SHA: 35F2955FA3289AB60155661951F0E24F7601930F
  • SHA-256: 7578852223E2F36C14C34AD18DFE98C05C19F1A0E0FC2ED31E89BF1F0229972F
  • SHA-512: 60E66783AD8B8173E39EC8525B32FE90A2CEE4650015CC12D424FD0191E2E6EBCBDF337CDCDC1A3AC9F9FAC8C4DA598DF4F91D92E985987B0BF80DCAEC543327
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\README_en_CA.txt
  • Type: data
  • MD5: C41146EE0799ACB93B1EF89F2A9B2E4C
  • SHA: A7E00167A9F1D8C5E432236973FB1D2603E92450
  • SHA-256: 139CB1CD0E39E4CF2D429AF5856E16C44BA0EC3D77109D691FF2ACB367C291F7
  • SHA-512: 95C77197AFC8B22DE9C1C39F1719957265296B6BBFDC1820A4FF6288D6768DD81B977E5889BCA2AE3CECA2A1FFD6A0A124CF13404A23B687241F0455859FF884
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\README_th_en_CA_v2.txt
  • Type: data
  • MD5: 662FB5B6ACD4EC05DA6EB6A49E76E25F
  • SHA: 4B06482711C61D8D6E9710FE8149855FEDF488CD
  • SHA-256: 19FEF9C8FAB6E970684057B35B5C24D40F4F7EA5200995DCE3E35C3D57BFA7E0
  • SHA-512: 9CA6EF56E24205CAE9580E3FDFBABC5677CFDB8920A996645AFC2AEDFD6A2A73728B3C3341CB5491F1D2F7D0DC69FC3D1C4595BA20132149E8D10112448159F2
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\en_CA.dic
  • Type: data
  • MD5: DE2B139521E03664ED323DCF7EF2ABF5
  • SHA: 702D04A941D681D688101795AC4430EF1C981A13
  • SHA-256: 88CE16F0DFF580E7A6F0F6C588B8A728D3DEEBF745FD39C2747EB623A4602F9A
  • SHA-512: C87CCBD6FBFE61C0883A3907E1C45906401F5EB9E9353ED12C728DC024CB085724F7B8EED8B89B1FC607AA4C5DE3C83C6941DFC21A20E9C89B7F7DC6A687FA15
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\hyph_en_CA.dic
  • Type: data
  • MD5: 88F20C30F65784059B5F2A9F83FBBA5C
  • SHA: 6791A2D7D82B9E1A799A11B0DA89EF9FDAF671AB
  • SHA-256: 681D47A93A254D2156D40C63F5AD80A1305B94A8CB22196CFD241FD0640FE907
  • SHA-512: DE1470841C5274A28B85861DB24565A850DFD37F5553CDB58220CFFAAF6BB32F2132D9A68AE350DC5403F2EDF14F1876A2909F93FDDB073EAFE690E9B8525EFA
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D29487E19BB8B283D63C9666268EA271
  • SHA: 388EA25395327304DDD472A95C192E0B635E01A9
  • SHA-256: FDDAD7D617E81DDA41F35FD0DD9A541FB7F6068A2B0594D5A3FE219D44DA2F00
  • SHA-512: 1710FB11CD8CC9CB387A67CA456C5EB1CB63611039CA87950A1FB01B22452D37D2A59651CEEDF98EB0EAB462316F82D87FFDD316FABAE8B92860EAABD1EE8F4F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\README.txt
  • Type: data
  • MD5: 817C970593802026063984C6F0F86367
  • SHA: 870815A788332BC36B63E2AA23129D0AB628F085
  • SHA-256: F6EE38CFCD5C88787EB4EABD8991364FA0FD1DF524544BDAEA6AB0448B1F29EC
  • SHA-512: A6B4B16CCD97C52A2777774EE3D75AE20FE01726BB083C9BE7660BCE959F6EC0E306705C293333BB2EF2055FCB0714A9859CA87C9D73715012ADAB8F537822F0
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\README_en_GB.txt
  • Type: data
  • MD5: EE1B10FFF76EE20E10A4BD18DCB9E9A4
  • SHA: 5D452F4AA4BD00E7E58583AD9BD54E1A7C4E906F
  • SHA-256: 84A46CE646F4DF8AABB4909F3A6927D5BCD6CB0444E5C485A3180AAFEA32D704
  • SHA-512: 20E5C7FD2986FF5582DE40D7FE84DFD674D5C4C67BD5B447B6B134EC8B5688434F377F35D402B0F220987DDED0E98595567605066FE5B6EE28FDF60B13FC3CEC
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\WordNet_license.txt
  • Type: data
  • MD5: 7DB741D435AE5197514451942FCC70CA
  • SHA: 48F63AB0261D0911395D1D04EAF815E3E15C4154
  • SHA-256: FD20367C3011B5BFABD59848119C7263AB691488134B07E3B6D39B3D4187983D
  • SHA-512: 789B46294E4941603785C6ED9E47DFB1EA82971E8ACC2751E65477AD19EDEF6A36566069B4B95C478302BE354A90C69C9E284F7599862D95FD40DC3A36ACB2BE
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\affDescription.txt
  • Type: data
  • MD5: 0CFE77EB786E60110FA5EA351C8E00F0
  • SHA: 4F56637461AC321164B830CCDCA3B6FF1E8B7AAE
  • SHA-256: E96BA406F5C3275BDFB1A422172AA075C92D8934F11B080CFDA93FFAE1C4B2D8
  • SHA-512: B4CCBEF1EECAB60A609048BDCD0F498D670C011CC271858843FFA66415B76B9E174E4B3334CCE10CCA9D7FB553B691EFD4A1AD4314C60974CC73AE07C9F93E5F
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\changelog.txt
  • Type: ARC archive data, packed
  • MD5: 47E675A5CBA621062C33E3EF2C12F329
  • SHA: 2D0A8CA0144304408449AEC4CE732F352C74E2E2
  • SHA-256: B4FB40A1D1A57E43A6ACF14231AD7F0FD9297994A66C7AA2D193CD92361E9DB4
  • SHA-512: 113709BCD924791F5C166E2FBFF838D0D8B7C022818C39E3058107429E24912294CD33C7E18060EE9628EE93C7DDB7BFD2E227641804AC551FB1F58EDF317A62
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\en_GB.dic
  • Type: data
  • MD5: 9CD3A1C45C0AC9D820669419F00F7B57
  • SHA: 087F8897191F472EF3BCE288D86450679EFD5A09
  • SHA-256: 06A6A0833CA1D5AD4A8B24875E004BE74DE40D0F8893F6F25D26D8F39292FE71
  • SHA-512: 7FAFA48D5B6EC402C29053FE4B0AC85AF4771A8729B5137F57D56131C969A0FDA3A240B4B716106A7D72739E43554CCF893AD7D39655D1AF0EA3275A2F3E810D
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\hyph_en_GB.dic
  • Type: data
  • MD5: 1BF2E7BCDE579AB7A31AAF641C312BAA
  • SHA: 28FC5C279078303051A06D34D886FB32C745E17D
  • SHA-256: 652FAEB7E25373005C0A79B2D9A5C8DE5244E869686320D253FF91CB06665FC0
  • SHA-512: AC08136D5378362410473A55E101323EF2F78C208F36E9612B944D6F7B6A145E7E693F117D913243BB8D14379FEF2BCCC2FEB8D73A99ACE4FF1ECE8D4A7A0E19
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\license.txt
  • Type: data
  • MD5: 87E2294983676565444C9521DE0A00E4
  • SHA: 1724C6CF4943CAEEA87FD868C5AF79462FF7613C
  • SHA-256: D31F930C45D43D1488882BE5E27D7A20AF7BF84CDC5893D86FDFA2F389D721D3
  • SHA-512: 83E26CC36624D31802853B7A9B7888EDE30A879EB9B8A3CB877DE3B1517F4264AB87E53E416D95FBEB5D723777ACA22803259E17A1DB604EFC7B01361776A7DB
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 37ABDF1B0475A4ED3F70DD3B743260E8
  • SHA: 35F2955FA3289AB60155661951F0E24F7601930F
  • SHA-256: 7578852223E2F36C14C34AD18DFE98C05C19F1A0E0FC2ED31E89BF1F0229972F
  • SHA-512: 60E66783AD8B8173E39EC8525B32FE90A2CEE4650015CC12D424FD0191E2E6EBCBDF337CDCDC1A3AC9F9FAC8C4DA598DF4F91D92E985987B0BF80DCAEC543327
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\README_en_US.txt
  • Type: data
  • MD5: 73542E54EB2B0A49B7140A064F8056A0
  • SHA: 3CB0B11A97E03E9626604285E1A1DFCA9F096D05
  • SHA-256: CA3296CD98863BE8986D3CD3A8A6AA90AFF544D499BBE5325325381A71988FB6
  • SHA-512: 345CADD185B254AE1540F142C893BF418DE1872922AA5F56277F720FF41FCCF2AE67539B62D13F0C86035FB848A51E9A7666FE71104FCEEEDB3B5429D55696C1
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\en_US.dic
  • Type: data
  • MD5: 0CF9A9DB76005DB28760F3700792613D
  • SHA: E559E21CCA35B865072B77F4062D99F1CC8E0111
  • SHA-256: 9D9993B25A9751A65D5E723DA915E7763C75BE641E1163864132A48620400BE8
  • SHA-512: A821981821B2CFCD3F3288388E420BF6A2297CDB4ABE2D7B39CF2FBDC2301F3A83031F94B58713CCA9F88D63647A4FD0F40FE90673B0E767EEF1E9AEA830542C
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\hyph_en_US.dic
  • Type: data
  • MD5: 916CF190FA34A87CA533E69B0C5CAB3E
  • SHA: 68F790D9786BD57AD652181F44997C1042C0CF30
  • SHA-256: D9521B144AE2CEF04A8A183476666522EEF0B2F5F90142525E3184CB90395B0C
  • SHA-512: 6F50577BF119AAE9BFC2C4C99D2736A319B99F9722CD8CC1579D288DDAB33FFB031017AE1135A15863446D60D939DA0E75DDE16E73C96EDD5FEC741C92D38FF5
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dummy.dic
  • Type: data
  • MD5: 78D1187FFE7FBC58F4292DBE0F68D9D2
  • SHA: 7B071F1D2E180CEFE0CD1078B808FC1C947619AC
  • SHA-256: D53DDA97BE398E070A9F6C957C3473328E8BCD11D882AA7327F8A9E2957DA40E
  • SHA-512: 3EBBCB6A2F60CA2058AF032CC2B5CEF8432A8CF732887CCEDED5737D9D5397D57CACFA623D30B3B077830DE2BCA94C5010FE3B947BD195333A297968369B1434
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_CA\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 37ABDF1B0475A4ED3F70DD3B743260E8
  • SHA: 35F2955FA3289AB60155661951F0E24F7601930F
  • SHA-256: 7578852223E2F36C14C34AD18DFE98C05C19F1A0E0FC2ED31E89BF1F0229972F
  • SHA-512: 60E66783AD8B8173E39EC8525B32FE90A2CEE4650015CC12D424FD0191E2E6EBCBDF337CDCDC1A3AC9F9FAC8C4DA598DF4F91D92E985987B0BF80DCAEC543327
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_CA\added.txt
  • Type: data
  • MD5: 4FCB2AC938855F8F0DDBDD93F43EBA4E
  • SHA: 8F8B65B0D42C0A2130713A99AB3CC52953FA3F99
  • SHA-256: DD34A3FBEAA7A2ADDEF7858324CCB946C370715F73658922707EBC2A6B9F4F51
  • SHA-512: 3AA74FF0DF1EBB5DD4BDA493B37A1EF9051A50ACE3094E8AA22A74DAD828F2D4EBBC0E43F185BE6648947DE4003CDEB8E7EAA19F8ADBAAA0FB3461BEBA50EFA1
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_CA\excluded.txt
  • Type: Sendmail frozen configuration - version \0060\031%m7^":xP\230(5
  • MD5: 13640D8F2B8DFB79A6EC8DAD2BA36EF8
  • SHA: E3770C09C0C72DD88CCB4CF187975CF7600810A5
  • SHA-256: 96777817932B8C301B2A2951A89EC60AE2CC2F9E26E675A3AFE87E9590D5AC68
  • SHA-512: 2E7DD8D62DE519374D201356042A9148DCB9423808057F9F999EF8CA2CBB1599AF84C15EBC883560B64137987E5B7F91486A75B35A90568AEEF9D27B89A575E2
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_GB\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 37ABDF1B0475A4ED3F70DD3B743260E8
  • SHA: 35F2955FA3289AB60155661951F0E24F7601930F
  • SHA-256: 7578852223E2F36C14C34AD18DFE98C05C19F1A0E0FC2ED31E89BF1F0229972F
  • SHA-512: 60E66783AD8B8173E39EC8525B32FE90A2CEE4650015CC12D424FD0191E2E6EBCBDF337CDCDC1A3AC9F9FAC8C4DA598DF4F91D92E985987B0BF80DCAEC543327
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_GB\added.txt
  • Type: data
  • MD5: 3EA374E3A29F36E94C19166533D8070F
  • SHA: 2B08703B694495292BA0229739F2149F82DF230D
  • SHA-256: 692775BAED02BB6367F8EBC177047E1B274F372584F62FCC4F0C2735B9D1CEBB
  • SHA-512: 16ABE36421D7C5774A92B79DF25AEB5265F6F369E7A97BFB39761E1E980FABCC1688B1D959AB7668A68F261EDC92D9853F24CC9AF1E80DA3E61621F37FA4E0CE
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_GB\excluded.txt
  • Type: data
  • MD5: C1CA27FDC226BE0DD14E2568E2BDAB13
  • SHA: CBA5D64B618BE7EC8839B0550A63CCDBD4A5DFB7
  • SHA-256: 2E0485C76D89CFE35536ADEDA9C8FC634CB1D8EDDFA2C53D88419949928A90D5
  • SHA-512: ECF2542FA2B18EB329E25B85B11C35E80D6026C3C2EC9FD35B51845723742E45809592E03AABAD9743158B1D9D63B5449F2D0A6EDFC258C410D2DDCEF3B0D800
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_US\Added.txt
  • Type: data
  • MD5: B3231651F2E96C0DE7DDF10CD56CA104
  • SHA: 69780333E76D0DF449CD7A09D2A0798582DB75A3
  • SHA-256: 541169CBBF421DB0D1E3B800621833C36EFAED8627A52CB92D7C020ADEF1BAB4
  • SHA-512: 2CD966E50353B7956278469887933B899744C70D864107376559FD68E5CE322A2C4DF613DFA1FFBD989355D04E8A77E15EFA0F9D6E00D23D2979EE5BD66B31E8
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_US\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 37ABDF1B0475A4ED3F70DD3B743260E8
  • SHA: 35F2955FA3289AB60155661951F0E24F7601930F
  • SHA-256: 7578852223E2F36C14C34AD18DFE98C05C19F1A0E0FC2ED31E89BF1F0229972F
  • SHA-512: 60E66783AD8B8173E39EC8525B32FE90A2CEE4650015CC12D424FD0191E2E6EBCBDF337CDCDC1A3AC9F9FAC8C4DA598DF4F91D92E985987B0BF80DCAEC543327
C:\Program Files\Common Files\Adobe\Reader\11.0\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_US\Excluded.txt
  • Type: data
  • MD5: 38A86AEB09C0DBAC1AEAEC61C0ED3157
  • SHA: 8AC0BCC9D17C45BBF1430FD20DCA12A89E6BAA31
  • SHA-256: CEDFDB5C531B5A6CE3630F656BE14BFE80BD60D7CD92071E52B9B9C2D6BE1707
  • SHA-512: BF501DC462152D7518337C4CBFD48ED7484EB4D92F2E5DB8BA914883AE746AFE1320AC5EBF2AF269BC49D8E1AA6E1125165B257794F055BDB14FFF4F1F2502E8
C:\Program Files\Java\jre7\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 765AB83DF5A5F417A34861966DEA1418
  • SHA: 4D542369C6D0A90477A8B47EE871CE903B1D2EE0
  • SHA-256: 599C3AB4FBBDCDBB82F9BDDAF198DEADD5DB25B552574A7DFFBA1399CD0060C1
  • SHA-512: 0CDF616A0E2DDEE3335B25EB5F56C8D5B12172902DB3A912A98E356B66D4809AE98E989E83F485F29450A0FE5BBE87B55807FC48D361A1C471B9675DFDC1C0ED
C:\Program Files\Java\jre7\README.txt
  • Type: data
  • MD5: 81DC3DF0641CB00FE566E6DEBBE9EEE9
  • SHA: DE888A65AEDA08E0881A6C50F169443FC01D4794
  • SHA-256: E944EAC00C41CABD0B4A024DF3F7C86EC7737E78E4FDF0C4943877AD08EBECF2
  • SHA-512: 2F0526AAF7064DB013A7933FEAAE8AEE15C0D30EE4E01A1D6401458BBCE0828F82DEB47EA185C9AB642F0E1E4F5AAC8581AAA21D015A4AAB7B4496154C745414
C:\Program Files\Java\jre7\THIRDPARTYLICENSEREADME-JAVAFX.txt
  • Type: data
  • MD5: 0733A57E3F60F87D3BFAF013F56AD514
  • SHA: 01F21D13AD5DCAF6DFB7D5C7F550FB6F6746FEEE
  • SHA-256: 8FDD881BA9A58E8713503A832BC95B8A141FADA05F0728E158A97F642D5D355F
  • SHA-512: 2329CA5341A07784519A0587A25D3DF0FA980F5E9FDE4AFD54C1BB14E1655FD66372EE1FE190E189067AE34953970A0F6B7223C0D970CC31E8DE75B6D94B4B34
C:\Program Files\Java\jre7\THIRDPARTYLICENSEREADME.txt
  • Type: data
  • MD5: 9129523356350237E83E7352A3893643
  • SHA: B6BF5156CD0DDA4C9FF85090455CF65BFE0AC771
  • SHA-256: 77C509FEDD4C9CCB7C6F0DDD28B6444E71E2F5B880AE445F7FEF8B165155791F
  • SHA-512: 73D4DFA6B9486B998DF9F12F1FE1C89790E10A806080D4BB7E806347DA4D51354E99AC04412663AA659840FCB9390169850F13A12358FBB875679D67E22AA8A4
C:\Program Files\Java\jre7\bin\client\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 6028E566C910706C347F5E32381F4462
  • SHA: 5D60DEF1DD80D9164A723FEB95D78FA0D7A6FFB2
  • SHA-256: 10EFCFD1AAA51CEB6105EBEBB1FDB9B0D81B548E7E6D84A4A794CFCA97579D82
  • SHA-512: 78A6143F0EA229F436F07797E1B972E559E2E56C6048DB699092C2D1310C320DA2670468E24564C5F5657A1525A04B379D23DC249E9BB124AFC262A64182E8EE
C:\Program Files\Java\jre7\bin\client\Xusage.txt
  • Type: data
  • MD5: C364BC280B5DDCBE1B6259E809790F4A
  • SHA: D58D36569A381282650CA150E3EF55600E01EAC4
  • SHA-256: F33E46E7F5FA86443671443185DF6C73FA34F21F6DC5EBB1DD57FD21C4A25175
  • SHA-512: 3DA15E54D7946D6B427CD7C6230C7C1F5F24ED961E5386D655A92D4FAD03A591F7EBB57961CA704DA567CAB31C70675D4C3BF52DCE45EF6D3C2B0148526332BF
C:\Program Files\Java\jre7\lib\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: C98CE13DAF2B2B95ECEBF26E220761C5
  • SHA: 6CA543871AD61B642F21927D315F1BE1A705C557
  • SHA-256: 2B4336898022970EEA047DAE9C543F9FB72F73D3FBAAFB49F8B9B2CB34F3B10D
  • SHA-512: 21571E7B70F5EB630115E79E9EB9ABDAF5245018A9FA4320B684DC49E64EE654538B84D3684F061AD3B13F5891353EA429D2ADBC4AEBF0173BDFA430342881B5
C:\Program Files\Java\jre7\lib\alt-rt.jar
  • Type: data
  • MD5: 8B7ADC9497ADDDCA1ED2C9932CC78069
  • SHA: C051BC0B489B0E5CD983B76DCA31EFDA0330CD72
  • SHA-256: 99D7A25398EF9082E94B60F6AD506EE6F3BD1EDC512009AA6D8B20FC98DEC70B
  • SHA-512: AF5035D0E87DE643AE6D5394553A9DA9D0FC57586A41C018665093C4CAC2E0E5897C6BB9FAEA0F252E70AFDCFC9007C13366ED3696CD925AE9A3FCB11327534E
C:\Program Files\Java\jre7\lib\charsets.jar
  • Type: data
  • MD5: 8A757766DD7AAAEAADCE541CD90FE05F
  • SHA: 7BA6A7DCA88038AF8DD865A004344B16C8497775
  • SHA-256: DB2F3F1064401BCDF52A7AD2569A52554500689746B81DE6114E77E603B4E681
  • SHA-512: 8FC575109ED71D81A4022523D1CE9B0D88AB4EB59DD756350134EA65F9A440DDC152C62F7D9BE31139E6D85F6A5F8456DEC5D225CF516E43553B0872A508FAFE
C:\Program Files\Java\jre7\lib\deploy.jar
  • Type: data
  • MD5: 296D484FEBE0B80538785A56EBF18818
  • SHA: F72D17769FE75F07E00CBB701F17CAF801484D73
  • SHA-256: 9DC4B659D07291BA8B18C372E18AFF7BB25C76287AE15912273B45AD9E72A1E2
  • SHA-512: FAC1462119B158E6AC6C8B34BC452E4ACFF79DAC77CC9143B943CD6C73A999EC15298558E8A01E0E80A16C599DF92CBDA696D680A05A8C78B32351CA8ABA602F
C:\Program Files\Java\jre7\lib\deploy\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 994D688A719ACEA86FAFBE63D78A09E3
  • SHA: 7080C3711EFF895CC4B9E6DB31C7265E7FA0F17D
  • SHA-256: 162C2884FE204018B74A0061CF75EA682CDEF67D752D81B3F140B34817B12129
  • SHA-512: A897214E29F4192DCAE98206EA459082DD4F39BBA06A049F54042646567E3F3180F0E4456C722E98A5FC87D8998027778286E45E12E1D4EFE524045A2784DDBF
C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip
  • Type: data
  • MD5: 44B11D2591BC2E647C925EFE7CE429B5
  • SHA: A7E18F06F8FAA6FF24FB6C3B10D8FAAF99155401
  • SHA-256: 5DA182B51F9F8D97117EFFB5F035A7CB5A436924A9BF86E147F7F1E13CFD7DA6
  • SHA-512: 172978A05BFC707EA91A890E0BFA5E5772BFE343BF80C8B8BB9339BFCCC6AD7BD902ABED3A52450A4C37ED0504EF7CD57F1BD3EBD573C222DB8AB989ECCF2088
C:\Program Files\Java\jre7\lib\deploy\splash.gif
  • Type: data
  • MD5: 087FBD1E4F6178341E960E718C746F24
  • SHA: EDDAF2068974F18CDC251AD74FE5A7AF9AF2CE10
  • SHA-256: 209C4ACC740FAE908900D19C40D1AE25DAE6F89C814FDE70422A814CF283A061
  • SHA-512: AF284B30C527F55A4A4058F081C89F7D6BE51BFBDF24BCB540F6AE550554176B111CEB1A4F52386FFB0ACDE4C55DA2D92333A5CC57631152B37B1481B913D36A
C:\Program Files\Java\jre7\lib\ext\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 994D688A719ACEA86FAFBE63D78A09E3
  • SHA: 7080C3711EFF895CC4B9E6DB31C7265E7FA0F17D
  • SHA-256: 162C2884FE204018B74A0061CF75EA682CDEF67D752D81B3F140B34817B12129
  • SHA-512: A897214E29F4192DCAE98206EA459082DD4F39BBA06A049F54042646567E3F3180F0E4456C722E98A5FC87D8998027778286E45E12E1D4EFE524045A2784DDBF
C:\Program Files\Java\jre7\lib\ext\access-bridge.jar
  • Type: data
  • MD5: 614C4F44A184AF75C196606A7B0AA201
  • SHA: C06ECAD4176193316A09032A30E8028B0FE928D8
  • SHA-256: 40194056B2CEB07C8166A6E224F4E8AC318E956F9055EE6E4CFAB74E716C2AC9
  • SHA-512: F4EB71F2B2EDD48B8EFCE155FD9738CA0DFCA36F9A8EA5A6135AA7FD6D275E28B151EC0E69EFC5E88B5E906DD28D93E6C8EBEC62A961892C984F31540E50FF28
C:\Program Files\Java\jre7\lib\ext\dnsns.jar
  • Type: data
  • MD5: 3CAA0A1CAB97E3C533405EF05E46B6FC
  • SHA: 7E2F93093D3C83B08E12CC01620094767AEF1C5B
  • SHA-256: 6CC2ABD2064F7B19FAD16392C101F4B39CABD90B08FC89C24935C6A29ECEC554
  • SHA-512: C7A2DDF2B7AFDA7B2335471BFEA1D7E85B83C2329A2B190D763719A62E8BE00EC6981B720145C8F19FF654C49D4DB84BA3468137800F0E3A0BC890D76F6006B3
C:\Program Files\Java\jre7\lib\ext\jaccess.jar
  • Type: data
  • MD5: F6C9A949CCE56EA75A23F02F2F8856B5
  • SHA: 575B2E1E12AB2B39BD36B5C16FC27E71F1343C51
  • SHA-256: D8B0D289165DADB985DAB2AF27D9319317F814ED580DA51C24DE1D8998D4596B
  • SHA-512: 1FCBE369E225CA13EE79544A7E032E42A17A0A5E9BAC11FB0D4A298D9EEB0FD90F7EA3767486FB486A97FFAE5BA0AE4985CFDC2066A738123ACE96B593F21CB6
C:\Program Files\Java\jre7\lib\ext\localedata.jar
  • Type: data
  • MD5: CF26924F44095AC791F98A8182187269
  • SHA: 082DE71254B0496B3C6F01469516B8F9EBF069DB
  • SHA-256: C7823E062C55DABF9638B39E123A417E5E211BB5670C5FB22800B5FBB62FAF22
  • SHA-512: D491CFE2385E656D4352443ABF34490F7B2171D3D1C6B5AEF760E63AB7248B33ACA8119C2A74D7CEADE490CDE31C0A8E95ACB592DD042065568A668DA889CCA5
C:\Program Files\Java\jre7\lib\ext\sunec.jar
  • Type: data
  • MD5: 171D6074C91D75B2885B4696FE01679C
  • SHA: EF7D0578FD222EB00526BD7411273C7C0116D0F6
  • SHA-256: 8C3DBF5A52CFB617046D4AA5AC7335C90444EC349F99ABCA559FFDAD4D25D7CD
  • SHA-512: 0DDEDF78ACD80D30A5D4CB3A4820CA38FC8221339F8DF4E3B8ABFC41CEEC91716E923A55397B7E5510C940215C08C7E421937D1D6F9EDFE25033317FC5028A13
C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar
  • Type: data
  • MD5: 8F1622E8129A37A6BAA2D0AABE455F7D
  • SHA: E6BEC6CC51E1929E34DE0054E31C2FEB1194A245
  • SHA-256: DA9D89FD02B094558616C14FBFFA740DC3F6B9F32DED89D64380F0567A419B1E
  • SHA-512: B1433F068CC7B9F307FD0B4FCB2FF82403BDB4F24BC3ECCAF7CD9C8D6E63A0218DDD0345D2C9FA3F708F145031213C0EE026ED6C23984E5C6B9A95E186757F5A
C:\Program Files\Java\jre7\lib\ext\sunmscapi.jar
  • Type: data
  • MD5: 0B41B9A4FDE49F52510C5B1E2D580560
  • SHA: 7CB5BE886E355717648B3E430E035BAC84ACE682
  • SHA-256: 7B58C6B69D98FA114CDD606AB65121A2F2AE5A849669DFB2D9989D9E4B545965
  • SHA-512: 33ABDA25F85E35D89364338CDCB0324DA6AD68027BC420F5DDFE4F09F5AD74485851BD967D44B29C270DEEFEEDB0AF9E8C988704ADFDAD465CF4C4E5DCCB4E69
C:\Program Files\Java\jre7\lib\ext\sunpkcs11.jar
  • Type: data
  • MD5: FA0359DEFB3EE95729FC0B18BE69C639
  • SHA: E389368B2B28259FAB84A88A35EF2381B435DE4D
  • SHA-256: 6ED4CC0234D5ACA26185E9D9A8E8E5C6CAF65A840B192DE1C0A04117CA7A12C0
  • SHA-512: 6865D3C5E0B4C07A442718F6C20231EB041E8B98F3CDF250C238546CDC1E22513EAD0C8863BDE220A03C3CC0F3FB740E74BDC15FBC2E2A75B55692F8895E9B15
C:\Program Files\Java\jre7\lib\ext\zipfs.jar
  • Type: data
  • MD5: B728CB06DB592A525DDF393718FED935
  • SHA: E9F8CBBFD7B1B865E1BA3EE000161510F8E59C29
  • SHA-256: D5DA07449B3D3C5CD06F6914BC777C7571458F6D5B64B9712016B380CCBE45B9
  • SHA-512: 6F46ACABE21D252817FFC4C2CB8FF55D38936E10193651F43599576C5D698CB2FE1AEA36935DA81BFC47CBB33EF4E6AE1177EB16152CB76DC58B6988FC234B36
C:\Program Files\Java\jre7\lib\i386\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 5B8CFE1FB49DF8672C1BFDE30034B1AE
  • SHA: 2743C08FAD95B7B836A1A654C976266AF38F6EAC
  • SHA-256: A015E853CB808B45C2151999093BB11E284959922D1CB5F38824FB973176145C
  • SHA-512: DD50E1A75A6586E35784A54DBA56BF94F980A57F0B67166EDE00464FFE18A48532F7012E80B00F95B9E74E82CA7F9FEFD90D97CDDF11DD23B1FA56112CE4A83A
C:\Program Files\Java\jre7\lib\i386\jvm.cfg
  • Type: data
  • MD5: F45B33F93C06BF1892CA04E49BD20E7F
  • SHA: 08A7E0844C22CE0F64360B4850AE18E6ABD9132F
  • SHA-256: D668629A257231B8F305AA863E5CBC7E00BC417C36C69BC93649B74B07F09AF9
  • SHA-512: F2D51AD9956F6B582BDCEF32001DBFBC334CC49A368859D4D67AF74B0B43C31AEABA6E77ED9A0820A36B7F828F4A911B8C5D89C64BE37B94A208304290F7E1EE
C:\Program Files\Java\jre7\lib\images\cursors\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 5B8CFE1FB49DF8672C1BFDE30034B1AE
  • SHA: 2743C08FAD95B7B836A1A654C976266AF38F6EAC
  • SHA-256: A015E853CB808B45C2151999093BB11E284959922D1CB5F38824FB973176145C
  • SHA-512: DD50E1A75A6586E35784A54DBA56BF94F980A57F0B67166EDE00464FFE18A48532F7012E80B00F95B9E74E82CA7F9FEFD90D97CDDF11DD23B1FA56112CE4A83A
C:\Program Files\Java\jre7\lib\images\cursors\invalid32x32.gif
  • Type: data
  • MD5: E021CA429F2B3085B9BF0094388A55C2
  • SHA: 0D7DAA9011FCDAB7ED80AE60D94A2A11292E52FD
  • SHA-256: F45EBF22A68A705846E5682CDC90927EE0F603670B0A650423E2E3FD2D480B44
  • SHA-512: 5306A016A3AE638D8BC7834E47D57B5996DA9C3D94E23A3834956160D064F403AAA075F3F8744E66ED3ABD12414EB07B5AC847686595F46B2FBDF3DF53F88F56
C:\Program Files\Java\jre7\lib\images\cursors\win32_CopyDrop32x32.gif
  • Type: data
  • MD5: E87291D87E0D9ACDF426BF56C287A55B
  • SHA: DF3711675D2C08BF6294190AE4C69853CF8D43EA
  • SHA-256: 4682A9B414A8CD2A832353E5790F5C287A72F20A3E19DF789F2539AAFE9812D1
  • SHA-512: 8004E90E2E5E7F3679D289A0588D0B620D92F789E83A132B4EC8EFB9109EA93BD84B6CAC73788967B9FB2EB9FF3503FCBCD0996FAB5A0D75B526939744E056EB
C:\Program Files\Java\jre7\lib\images\cursors\win32_CopyNoDrop32x32.gif
  • Type: data
  • MD5: E021CA429F2B3085B9BF0094388A55C2
  • SHA: 0D7DAA9011FCDAB7ED80AE60D94A2A11292E52FD
  • SHA-256: F45EBF22A68A705846E5682CDC90927EE0F603670B0A650423E2E3FD2D480B44
  • SHA-512: 5306A016A3AE638D8BC7834E47D57B5996DA9C3D94E23A3834956160D064F403AAA075F3F8744E66ED3ABD12414EB07B5AC847686595F46B2FBDF3DF53F88F56
C:\Program Files\Java\jre7\lib\images\cursors\win32_LinkDrop32x32.gif
  • Type: data
  • MD5: 0D5F8F0361B326DF315F25ADD281FBC5
  • SHA: E7A246EB6798E538390CE5B478EAD33205AE2164
  • SHA-256: 0F2052DDE61D3273904CE8B975CDBA84EF674ACF3DF066CEC2CB8E72B3E1FF58
  • SHA-512: 51077C2D6E0C76A186A0F2A8BA5ED15292C01465EB688E798084B11E54A1EBAFF5B1524A5118140F3380281A3ED40F4495C5119D31E58B32C371ED20F73144BC
C:\Program Files\Java\jre7\lib\images\cursors\win32_LinkNoDrop32x32.gif
  • Type: data
  • MD5: E021CA429F2B3085B9BF0094388A55C2
  • SHA: 0D7DAA9011FCDAB7ED80AE60D94A2A11292E52FD
  • SHA-256: F45EBF22A68A705846E5682CDC90927EE0F603670B0A650423E2E3FD2D480B44
  • SHA-512: 5306A016A3AE638D8BC7834E47D57B5996DA9C3D94E23A3834956160D064F403AAA075F3F8744E66ED3ABD12414EB07B5AC847686595F46B2FBDF3DF53F88F56
C:\Program Files\Java\jre7\lib\images\cursors\win32_MoveDrop32x32.gif
  • Type: data
  • MD5: FC481B7C7580B451AE15815AD2CD159D
  • SHA: 4911E87CFEEB282032342E8465440F3363844B5D
  • SHA-256: 9EB53C231A6AF803EA5AD1BB4221E8FDE147B94912DCB1447007EBFAA812B69E
  • SHA-512: 305767F0F9198E70941EF646D6930DCAF7342AA30F142B9701C2D41AB2ADE5B4CADD729B94BE2496C4DA214DD885D378685C0CB71B7D656CC269FF5037298509
C:\Program Files\Java\jre7\lib\images\cursors\win32_MoveNoDrop32x32.gif
  • Type: data
  • MD5: E021CA429F2B3085B9BF0094388A55C2
  • SHA: 0D7DAA9011FCDAB7ED80AE60D94A2A11292E52FD
  • SHA-256: F45EBF22A68A705846E5682CDC90927EE0F603670B0A650423E2E3FD2D480B44
  • SHA-512: 5306A016A3AE638D8BC7834E47D57B5996DA9C3D94E23A3834956160D064F403AAA075F3F8744E66ED3ABD12414EB07B5AC847686595F46B2FBDF3DF53F88F56
C:\Program Files\Java\jre7\lib\javaws.jar
  • Type: data
  • MD5: 67BFF11ABA63A381812B3E217395B177
  • SHA: E8CEC8B4F975EA665F315541A97236CFCE6005A3
  • SHA-256: 1A347C2143405410E783FDE8A28B9DA5636D52AFE08EE7CA427AE8BC2494D6E4
  • SHA-512: 24BBF1ADCED36E23A04B3C462911BE524ED1B451683DC7CD53087285335D855E8813131370C837925EFCEA63D4341A73F30C7E4C8D7395575B97A40004CA4C32
C:\Program Files\Java\jre7\lib\jce.jar
  • Type: data
  • MD5: CFD7CA382D75C030CAD7DA274348B6A3
  • SHA: 68CD59BDDD2F312D9218FA0B3335F225A988C057
  • SHA-256: F8C423FBA8E35F75F3DD28000FAC739F07191615EA9F2F844F3506B677A4F3F0
  • SHA-512: 86C231199E8D7CFF89AA6B8FD94B2783AA1014183B04DA3B121D392F42B77E7FF93F246108CD0F665757C285B429DB067D2C52F9EF71D3C2DCF7B99D9E7A2F8F
C:\Program Files\Java\jre7\lib\jfr.jar
  • Type: data
  • MD5: 75E845B8E75084F743D43CC775A23777
  • SHA: F152770EA5D8C185B9137C5C93AA9D26E3332159
  • SHA-256: A84591E3D3B978B0E47E1E3F3C8D68BC51A71CDC74E2A5041A4D79B5FEC02330
  • SHA-512: C4793FB618AC46734797A6769D3473A24CC9D4FA63F55642E64F00B2B9EEAA2320EFAE05EEB825DEFB39A4ED758CF36FBFFC2CB4BDAF8C26851CBB3269BEA4F6
C:\Program Files\Java\jre7\lib\jfxrt.jar
  • Type: data
  • MD5: DF5227B799D12AA1301BD222C2B91596
  • SHA: 64907924DBCCB11EF5C9AE1A01457B6F71345A83
  • SHA-256: A2EEC4554129B73E14D69DC35C684038B66ADAFAD75FED3C07804718A278583C
  • SHA-512: 8BD18BD98A4FF5645DEA0A5D182CCA84E1B614E838076F553F85CF8C428FA42BE7CC4FBBDB5463B67427BD1DB5346CC438CF2D8038F32E320CB42C582A7A97D8
C:\Program Files\Java\jre7\lib\jsse.jar
  • Type: data
  • MD5: 186A3789AF8B48BACE067CE5B473CD23
  • SHA: 5410D3C3A4C9C0BAF7A1821D660057E9F74BD26F
  • SHA-256: E5E6B2095D003A798835E8258100ADC4C002E01FC8BA3940E5F3C3960134F302
  • SHA-512: 04F4992CBE5E74ABB594B99DA4B85BC653AFEDC8386E2C0D4631FB947EDC208CF1D198617A8C5EE20EA62993E9604978B513009E662A91486ABA5975850930D1
C:\Program Files\Java\jre7\lib\jvm.hprof.txt
  • Type: data
  • MD5: 28F6A01673D28A1ABAD0AEE70CBFAD20
  • SHA: 4325CC6F814FF990980829A793B6BB7A104653F1
  • SHA-256: 0B40902EB49E729F97826B0FB179E20502DA6CFB17C1E697DD0AF66691E8D10F
  • SHA-512: 97E1B1A51245082027CEF95246E2D64160A1958396BAA06B01F54E486068443FF35CE8F6399060B066FFCE51F2F253BD5AAE48C6EF92B2EBAA0AA46E307645E1
C:\Program Files\Java\jre7\lib\management-agent.jar
  • Type: data
  • MD5: A37FE77E54172AB5919CE0DE94A8E2BF
  • SHA: 8E47CBF2EE9B70AABED5B36FC4820B222BB38B33
  • SHA-256: EA5FE90633AF5F7D46D40C1236D0C6A518270403B4D23A3ACE4425B6B03BA089
  • SHA-512: 30A9D3FD5CF8352D70C77D0A08DC2D0E4543668FB396B47D15719D1089327D377AF3687D53354943775C14FE58659F317AFBE822B00AED31FD3671C456F0D330
C:\Program Files\Java\jre7\lib\plugin.jar
  • Type: data
  • MD5: EFD8B9A127B2D3A5447B59C31BEA3C56
  • SHA: 4BC77A2A909240431C74ACD93ED4CC5DB0696292
  • SHA-256: 36D8D246941706EACEDD292DC98968616D2A373B5CB34B39BFEE58AD2CD49296
  • SHA-512: 9357F22ECEE62483854A56C36E6C371CBDD442EE2B659953B3438A69C73BF2C4E9B60EFC7B2AAC0EEF5C4E5F48A6EA4F7A16F8A5D526C9B1C82A4D852DA482B4
C:\Program Files\Java\jre7\lib\resources.jar
  • Type: data
  • MD5: 813A74D5F0C702507F2CB5D774B47583
  • SHA: 82BED423D7024F71E9D11BE8C3EB845248E1896C
  • SHA-256: CD6AE9EA876C021C02F3E327E560F64E204F009E3B7E5DEE28B282A5AC7DEF61
  • SHA-512: 5133E8E8149AC6FD4E5ECA9C0DC4EAB9E768FAB0BF4A46961D161431FA37FFA512FF223B917DD495BCAF8346D19D1D8F877E2BB1CA82303BD353969A717E0761
C:\Program Files\Java\jre7\lib\rt.jar
  • Type: data
  • MD5: BD53A8305F36D6E0E8129789A06122E3
  • SHA: CA5D44145C1B8819BE298DAE41EF152759E3E9B7
  • SHA-256: A3FCA834202054A9658BA2624B20830C644B7F2DB19921DE9FD3E409556C086C
  • SHA-512: E4AF2BEAF7B213CF69E429F19B28044614F17F5DBDE91EFFD19B17F1CDF6A3B810C90C36D348DD1781CA7E6526C2E0F4E264375A4700DAC6868101747C57A5A0
C:\Program Files\Java\jre7\lib\security\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 5B8CFE1FB49DF8672C1BFDE30034B1AE
  • SHA: 2743C08FAD95B7B836A1A654C976266AF38F6EAC
  • SHA-256: A015E853CB808B45C2151999093BB11E284959922D1CB5F38824FB973176145C
  • SHA-512: DD50E1A75A6586E35784A54DBA56BF94F980A57F0B67166EDE00464FFE18A48532F7012E80B00F95B9E74E82CA7F9FEFD90D97CDDF11DD23B1FA56112CE4A83A
C:\Program Files\Java\jre7\lib\security\US_export_policy.jar
  • Type: data
  • MD5: AC8E514EEBBC294CB4A8DAE8836F675D
  • SHA: F0AA2BF2DCABC257BCBB462AE7A30FAFA8BBA74E
  • SHA-256: 25C9DF73A4E7C2E7C1587FC1A8D1FDA39A6F177B73A7BF9085F834468A0EB335
  • SHA-512: 31B603C349A16C0E523C0C87BA63E5C6E01666CA88E4644D05D03DF070E310BC0E92AA0448EB03B7527503497CAFFA5F14E67D704C32B26C4BB7C032E05B8E7F
C:\Program Files\Java\jre7\lib\security\local_policy.jar
  • Type: data
  • MD5: 435F15241E6925A6096DA6AF56221519
  • SHA: F17125BF28BFD6A26242A12526810A72165B0FE1
  • SHA-256: 530B803FC6970B84A6CF0B59B76612D0D53EE62120342BA73EE8C95A3BDA60E6
  • SHA-512: A89EC26FDCE1175272743B96C87BAB221CA35AB96448EF8C5446F1753DC8C1D8A96B1783487FDD336E2F2F58C03AA1FC2439DECD711470525D0255D25AB9D4FC
C:\Program Files\Mozilla Firefox\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 63AE9B8B09215BDFA24F549BBD64411D
  • SHA: 9EFF34D76D9C4AE283F5553EAA63514A9B8E276A
  • SHA-256: 4203DE0DD33F4A5E54C5BB9F2F80BB59AF3C01001C827123998527EF3E6CFF12
  • SHA-512: 570BC34C8AB2A728BA4E0D72FC04E18EAE61558BB29C52CD509635BA9F5F78071D3B7F707E73200CEEA4B509AB16401065E518C80CFF10407A8866286BFFB1D7
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 765AB83DF5A5F417A34861966DEA1418
  • SHA: 4D542369C6D0A90477A8B47EE871CE903B1D2EE0
  • SHA-256: 599C3AB4FBBDCDBB82F9BDDAF198DEADD5DB25B552574A7DFFBA1399CD0060C1
  • SHA-512: 0CDF616A0E2DDEE3335B25EB5F56C8D5B12172902DB3A912A98E356B66D4809AE98E989E83F485F29450A0FE5BBE87B55807FC48D361A1C471B9675DFDC1C0ED
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
  • Type: data
  • MD5: EE430CE353D282FEDFDC9314671C8C12
  • SHA: 87E652BE9B70E424D86BD2D922AA0CF16E0E6F0B
  • SHA-256: 9DA0E5EA249E166DBE81B6BC1A80E338874BA948823CCF1DE4A59A281D24FB30
  • SHA-512: 4AD34463B211A5820D4382B641266A1E18F55725B55596B3C5B70A972F96E68286E3D60F1FCAB687526FE3440C62415D9DB5E90D7E3DF395F2721557B7ED5E8C
C:\Program Files\Mozilla Firefox\defaults\pref\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 765AB83DF5A5F417A34861966DEA1418
  • SHA: 4D542369C6D0A90477A8B47EE871CE903B1D2EE0
  • SHA-256: 599C3AB4FBBDCDBB82F9BDDAF198DEADD5DB25B552574A7DFFBA1399CD0060C1
  • SHA-512: 0CDF616A0E2DDEE3335B25EB5F56C8D5B12172902DB3A912A98E356B66D4809AE98E989E83F485F29450A0FE5BBE87B55807FC48D361A1C471B9675DFDC1C0ED
C:\Program Files\Mozilla Firefox\defaults\pref\channel-prefs.js
  • Type: data
  • MD5: 1AF4329E6ED0D886C1E0A78DC6CA1F50
  • SHA: 2209DA4006A1A7ED53DEE0C63267CF8652751D51
  • SHA-256: 2E263B1CC3E1707F92DC838DBA9DADFC7736105C40789314916B11FAA7603B5A
  • SHA-512: F27256D5CA0E2A2E9412E0DEAAB774A37F9FDB48563643AFDC46589218062C74A0A518254E024BD8B4183B12B30D0E161CB0CE4B9A64F48A16951448C00BD79F
C:\Program Files\Mozilla Firefox\dictionaries\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 63AE9B8B09215BDFA24F549BBD64411D
  • SHA: 9EFF34D76D9C4AE283F5553EAA63514A9B8E276A
  • SHA-256: 4203DE0DD33F4A5E54C5BB9F2F80BB59AF3C01001C827123998527EF3E6CFF12
  • SHA-512: 570BC34C8AB2A728BA4E0D72FC04E18EAE61558BB29C52CD509635BA9F5F78071D3B7F707E73200CEEA4B509AB16401065E518C80CFF10407A8866286BFFB1D7
C:\Program Files\Mozilla Firefox\dictionaries\en-US.dic
  • Type: DOS executable (COM)
  • MD5: EDDE8FBD91E7FC57AB391640E07D5DA3
  • SHA: 42375BA82B460E5DE9BD492A20AC02EADC0A9E68
  • SHA-256: 350455A68BE5937434B31AF7F2144F41E01418EA58BB06C3D2DC556908A63FD4
  • SHA-512: D7EDE9F7340BAFFF292E9EC3D5D5E258BCED5B81AE47319D9CA465E7F0F2B13F69236A28C627F3834898CFA5EC818B89B0BB70610B6D366F0B5FF6DD6FE77CFD
C:\Program Files\Mozilla Firefox\freebl3.chk
  • Type: data
  • MD5: DE61AD807B9F38E4F5DF8B61B0CEC9CC
  • SHA: 5731E089C94A654336D08635266448E88E65DF47
  • SHA-256: ED6F922DF45B5F1EA9659B8B9FEE2DB844AC993E2645875D93647C680690C593
  • SHA-512: 8C0203C382CB4B6362CC3AEC56AD18C776D0F590F8E1ACDADF3B88EC353619F952CA174ED4DB51A5150CAED42A43E1F9E7D7D2677462741A2A3A011C4705AB7F
C:\Program Files\Mozilla Firefox\nssdbm3.chk
  • Type: data
  • MD5: 5C06D6375540EA43EE4613843033B759
  • SHA: 7AF6C6826684844F8D7F5904EB463F1ADD38936A
  • SHA-256: 0F81700878C0BADF9211CBDDF63B8E8CCCDF2C45CB1ACF23A91E79D498BEBF4B
  • SHA-512: 71FB450A6274CE4123FDE61542890F9105E07A110A0B5A9B830893E39F8B8DE6A7AE17A39FF0BC3AF4EC69B0B222FA62ABA1CE3FE64D009F814A6ED7069CE45E
C:\Program Files\Mozilla Firefox\softokn3.chk
  • Type: data
  • MD5: B8F53A15B1F47FD57F8D4D3D647084BE
  • SHA: 4FB9B78CD965DD126ABC36AEA0154705813A6E8F
  • SHA-256: 1BAE93F21A25B39CFDE9BAFD54F25CBD5C030FA708CA4F63BC4DC52A478061E3
  • SHA-512: E513E35732E3A9812F0313D05C8B1D02EF63AA030BF797CAED8AB0CD81ECBC82E587ADA614563FBC5655232DA2BED33317AE234A8684C98CCF90DE8B4552B3A6
C:\Users\Public\Music\Sample Music\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: BB226F6F538F779AA565138A9E55E447
  • SHA: 6A9C2BE5C136BD1A8DD3ABEE4834029646B08A69
  • SHA-256: D028C1FF67354BCB8E67C9E2BBB030366B88D6A5A77128AAC2EF5552CC84FD3A
  • SHA-512: 2949208BBFBE7EFBF47AB066C27C72126717EA0C37D02F164BEA16E481443D573F563DB54149C700677C13169E3D3DECBEE0F7F5E08CD2FCBD7A37529DD3A063
C:\Users\Public\Music\Sample Music\Kalimba.mp3
  • Type: data
  • MD5: F4E0B2B552B71E884ADD908CB80CBBB5
  • SHA: 832F73F85FAFEC2F7C2490C08802A0AE117C3413
  • SHA-256: 1B4B7E576E420EA046CE14B9B4D9A322BC4092B2F89F807ADF84D4008057D122
  • SHA-512: 83CD0029BFB629315FF5A7104D88AE48F60BCC844645171C4BFEDE882085EC9D73879A4F854E210F981E0F7F2844BFA6B195C15FA696D97A48640A05B409B52D
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
  • Type: data
  • MD5: 874F48F740E31E0D2F2BD921BA7A7976
  • SHA: D487CE45DBB12B32815A0E4FDD662330917C15C2
  • SHA-256: B05E2C1D418A5224E1933A2413B6A10B4115EFD35E82604E3B4F65D33F626AC1
  • SHA-512: 7C2B9B6ADE2C077C30C612FB83482CD4E0162CEF7D5BBB356A501B197A609359971400B759C730A8D5ACA886271A53CF6EC573DEBDAB6F2A4114105523FC23F0
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
  • Type: data
  • MD5: 85A805BBE78C10F21937E3174ED7C21C
  • SHA: 08A70B6037CA8EC053CD5EB3018FDDD360CAEE5C
  • SHA-256: CDC43DA1C2A4CFA020F4BFD6C115752C26F5DAFD7287640E7856898515CD5F40
  • SHA-512: 6648CD1C5D812AE20844AD4F818CA1807C8F4652CBB316836A6C1758EEF2F55C9F24F82C8C9C1E5C14C883E7D45BFB1A24CA1BA7B70D5F06E2B8F8C6975D460E
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • Type: data
  • MD5: 0E1FAF3C481AF36CC0A29155738B47AD
  • SHA: A18D5C93B9B54827524DC74333EF0B056BC50D45
  • SHA-256: 5777DBECE66EDE5A568DF06F04615BF897991B7B206BAAD674D753F045E69C11
  • SHA-512: 09C350E8C42BACAB17443D766BE9071648F3AFB7EFBC47BDC885254ABFC817B9DD77AE137BF806725FE0674F978CBA6951AA9C0896E7B544653C11DE51C38AE1
C:\Users\Public\Pictures\Sample Pictures\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: BB226F6F538F779AA565138A9E55E447
  • SHA: 6A9C2BE5C136BD1A8DD3ABEE4834029646B08A69
  • SHA-256: D028C1FF67354BCB8E67C9E2BBB030366B88D6A5A77128AAC2EF5552CC84FD3A
  • SHA-512: 2949208BBFBE7EFBF47AB066C27C72126717EA0C37D02F164BEA16E481443D573F563DB54149C700677C13169E3D3DECBEE0F7F5E08CD2FCBD7A37529DD3A063
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • Type: data
  • MD5: 51529D4A59FAF9C87C5984CBB0D9C9B7
  • SHA: 5849C44A7A8163565E6F51C35DC10A90CD54308B
  • SHA-256: 51441433A9C5FE0779BAB1534E68803A3E963E933402EEF2A300732EF296C82E
  • SHA-512: 4E24D688886AC71D47E238EDF7CE43FD9576A253A901E5B77D2B9936F977477C06F600C55664B7921D04050D1640913B813D29877292C5EF6C3EEDD94B7B831C
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • Type: data
  • MD5: 66762BC4732186BBD769E4BE80A46C19
  • SHA: A42039358DE2E33B5CDD02D1A988AB8127D20987
  • SHA-256: D837B1143A08E584E5A6407040008B2D2126CFAF71FF7C6F694591FF2E240952
  • SHA-512: 24327671EC2B8A712B4AB8C0A30BE914E367544114A7F9E87C639991326E73B74A5F18BFA90BB2DBC89A63264922C951F99CA4B13BB99942D5199BB6BAE4896C
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • Type: data
  • MD5: DA12CD369BFF312710D8C6802C059686
  • SHA: 8587F5F6447A346A486189B25F60E7BA700C7633
  • SHA-256: 6959DE55E6483FF91B4543197ADED40D655EF36065240343CE0FD891E48FA857
  • SHA-512: 2F864EB196359BA0CC78BA7A1E6AE47CC957015238BE6EAAAFE3AF045D6DC6951761A3FB5B42FA90966C45F3F9968F3703912B6D0932BA3F1A2C38912D2AACAF
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • Type: data
  • MD5: 4A4CA11C9C7B37705A9252BD664AAD5D
  • SHA: 81CB1ACAB3EB4C4D4DBB9F15013D7E0A5148D4E9
  • SHA-256: 9C9C9CD85C6F81F754C9ADEAC54F91C0CFF84D1D09BD71D01842E1EABEDF7620
  • SHA-512: 0A1F7B52D5CFDAFBF44AC4D116C89E6D388B2683FEB5810B58F02375F6D7D00BBE48D21B0BA980B5466EC4C735F378C1F32A7ADDAA9329A48EE8650EFC6A4F1E
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • Type: data
  • MD5: 5EA43C23EB4A41228DBB5B3894C70FFA
  • SHA: 4BF1D5B7298D7AAD6D1B22B24C3938AE60A766FA
  • SHA-256: BD8F321136DCAA9E8B484F9FCF928B799B7F2311FC894746B05B06DB1A4E365B
  • SHA-512: 23EE3F4C01341A8653986CA943E74A2FC3B92BAB3AFE35164743C2DA486A515DBB62C27A6D05CA0689091FEDA06394F6C7A78C32B0A41F1473349D29EF09324F
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • Type: data
  • MD5: 71DF2E6BEAA560DBC260D6DEFF3F5644
  • SHA: 406FF089EF555DE4109081E58C0538C5210F10FD
  • SHA-256: F3D1F78B9BF99FC98D0B94D7BAA629FA1BE8984158B082E14C423856264F1010
  • SHA-512: 9A5BAD0AD3C9F84D0F7F5988111418ADF6428B003B20F48C75EA83ECFB878980F6F2624DD1FABEA878B09B0B4A393A85C791656420D9AC782EB178535AB6BB2F
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • Type: data
  • MD5: 59DED3B65B2CAFDEEB80ABC11B64C21B
  • SHA: EEF4153B25D18DFBF70A00084277454B46A17536
  • SHA-256: 912AB7CEA2ECE0BB42E49E8E1EC86C7DBA1F06E6D910AF40F52871EAD856281D
  • SHA-512: DE14F52C68BE4740513C69827D8F88057C91A746F201B91481C7CEB2F50C3BA617ADFAD01B61B07CDC43406C9CF6588AB62A060A5968099BBA1F807BBA279017
C:\Users\Public\Videos\Sample Videos\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: D8774981119FD31B879C634EC81F4711
  • SHA: FE727E8BE65607437C22E0C95B611A7C8D7D6BED
  • SHA-256: 33087383A4CE89A8DF52FDC24D2968E4EA49F4E1956D1AFEAEECA1B742B5CE59
  • SHA-512: 4668C194E680DEB10956AE365183FAAE26614CF5331F9C6C5A862AE4F87710C510D42A76C37DF76F305DDA5B2EAA90C33F8D12C474A75603F0514ED765A8630C
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
  • Type: data
  • MD5: 21DAE2E0C17A751B71B6197419AB46E7
  • SHA: 600C27A5F3BE1E5A8970B52F75D104B0D216E5EC
  • SHA-256: 2E5202EAA7A1FD3F85970EFC184C3D8D495F495D950B7F7E4234773D38FA58C6
  • SHA-512: 411BBD1587FFBFCB73D7781580E6F34C793A89037764F60C0E26900603E66BC17E273869EC75F300A94864A3242C0D5ED7B6015267755ADD1379E6972045A26D
C:\Users\john\AppData\Local\Temp\Quest Software\PowerGUI\dec3c3bf-b1f5-4c6c-8c99-31f8b09540ab\crypter.ps1
  • Type: Little-endian UTF-16 Unicode English text, with very long lines, with CRLF line terminators
  • MD5: 1BC6681FDA579AAAF55A9A93770DE7AD
  • SHA: BFA2D8028383C2803A733E58BC9368B84D2025D9
  • SHA-256: 9D6019820D2C82AF3F98FBECB478A990FC4F716342716313FE7FBE64FCBE4DF3
  • SHA-512: FA6C21DF2385AF4A910FB13919B16BF738F323F92A1B36B59DAE6C28D87496A5A50DCFB52353D1831F0B418805DEBB07701A8F95D6013D0E92F96DF0E01C481A
C:\Users\john\AppData\Local\Temp\d69b2c25-f0ff-4351-8b1c-066f001c88d4.config
  • Type: XML document text
  • MD5: CF59A11FD4D04A985A9A0143F5A2A26B
  • SHA: 9DEA13BB76661477AAA4B4BF93B03B559A6C4D98
  • SHA-256: EF494EFECED90A05F822764CB5371E965FA96A4637232A1C4220A3700E23A7B2
  • SHA-512: F241F7214C21C5A1CDBFCFB2FD97BAD65349851EBBECDA133CB70C38A51515871BB0E67FE3A6103C3697CC04FF663737A975B323174C68F74BBB943C82A4D4E6
C:\Users\john\Documents\Fax\Inbox\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 436F30C530172F77D0E25B57FA4E5DE3
  • SHA: DF9CC5B84340A491C8AE5B646CA5B4DC671D5E77
  • SHA-256: 9064D490FFB54DB9B4B60BF972AEB327AE3AE189CB0957376404E92CC435ADC5
  • SHA-512: FD52660C5BAD2608FAC52FCAF67BF2BD2057004CD32D5F9589B4C40846D95DF8B8598A0E25333A1C8FFF97A4744A11EF3597E755F64B194AB67A49EB12D35B66
C:\Users\john\Documents\Fax\Inbox\WelcomeFax.tif
  • Type: data
  • MD5: 225857E96759547CED46817799C8B9CA
  • SHA: 74BA404342426B3725E8D9B3A94151FD1706723A
  • SHA-256: 3B122790DB966B1D76820926E131ACB5447902805308CB6038267BF41B6D85DA
  • SHA-512: 3382EE3741349DC85CB94479AFADECFF3A1D9460C94E4159E2E385C6F18570A9993AA1D77BABF3336F5AB215C8179FD896E45E09E3967E1042C3A12A4345F37C
C:\Users\john\Documents\Scanned Documents\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 436F30C530172F77D0E25B57FA4E5DE3
  • SHA: DF9CC5B84340A491C8AE5B646CA5B4DC671D5E77
  • SHA-256: 9064D490FFB54DB9B4B60BF972AEB327AE3AE189CB0957376404E92CC435ADC5
  • SHA-512: FD52660C5BAD2608FAC52FCAF67BF2BD2057004CD32D5F9589B4C40846D95DF8B8598A0E25333A1C8FFF97A4744A11EF3597E755F64B194AB67A49EB12D35B66
C:\Users\john\Documents\Scanned Documents\Welcome Scan.jpg
  • Type: data
  • MD5: 21E6866EE54C682C431FA3CF25FDE7E9
  • SHA: B641F9144CD1D6AFC1E644530000160AFA34E517
  • SHA-256: 2D7C9A1831A6C81E37DAF2F7AC07A8D17C662E75BB8383F08193C158BC92BFE1
  • SHA-512: CF4C63C731D46E27EAB813EB7136ADBFD54AF3B70D5AA4CAD069626DEFCEEE98DD2AE29E86F59A55DCE7AF3E833B9BB317798BAB8604F404C559F79092E3C2C6
C:\Users\john\Favorites\Links for United States\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 436F30C530172F77D0E25B57FA4E5DE3
  • SHA: DF9CC5B84340A491C8AE5B646CA5B4DC671D5E77
  • SHA-256: 9064D490FFB54DB9B4B60BF972AEB327AE3AE189CB0957376404E92CC435ADC5
  • SHA-512: FD52660C5BAD2608FAC52FCAF67BF2BD2057004CD32D5F9589B4C40846D95DF8B8598A0E25333A1C8FFF97A4744A11EF3597E755F64B194AB67A49EB12D35B66
C:\Users\john\Favorites\Links for United States\GobiernoUSA.gov.url
  • Type: data
  • MD5: 605093C626A027B609EB83E38CB5B333
  • SHA: 87C9EF087C604E86287ED123490DB2126D397F4B
  • SHA-256: 18DC13DC41383F9390EC665E2B0ABEF976CBB833406A8D5C0A83EE85F9AC6B27
  • SHA-512: F94664EF97A28EACA80071BD58EF002B469E41F7425BFB9A4A63C15759AC470A7A54166C313F4D77FA97E3B038764BDA6B7A633907DC7F22F6F57F25D2E3F506
C:\Users\john\Favorites\Links for United States\USA.gov.url
  • Type: data
  • MD5: 03C91E33E347CF2BDE90664822F0E08C
  • SHA: 0A0C113C33936E21BC4AD4469FA66F31681D31B3
  • SHA-256: 0806114EC27180E23F4124CAFFAD089522598EECD1297A0E109EFE20A7EBA3EB
  • SHA-512: 0B56CDE0562CA3046D0415023A916E495C9A8DA19623A2275DCE3704A41B2C3C353E3FAD9D21EE71C621CCD39A32A14CCEC9A11A9D4055066DD18634F89E9FEB
C:\Users\john\Favorites\Links\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 436F30C530172F77D0E25B57FA4E5DE3
  • SHA: DF9CC5B84340A491C8AE5B646CA5B4DC671D5E77
  • SHA-256: 9064D490FFB54DB9B4B60BF972AEB327AE3AE189CB0957376404E92CC435ADC5
  • SHA-512: FD52660C5BAD2608FAC52FCAF67BF2BD2057004CD32D5F9589B4C40846D95DF8B8598A0E25333A1C8FFF97A4744A11EF3597E755F64B194AB67A49EB12D35B66
C:\Users\john\Favorites\Links\Suggested Sites.url
  • Type: data
  • MD5: CE5D14AFA04C80C796804A302F19BC1E
  • SHA: 2FB2D13F2B7ACEC98959DAB5984BD3A2F93A1BDE
  • SHA-256: 70CA3D366040D975F302FDD29E55DC109F4B256C45C29F949FDB585439BA1278
  • SHA-512: E8D2DB022E258395BE73221D182AC292ED0485602D75552D047EDD9FCF66820D2EFC70E3D87F0E359CE5AB21FCDBE63D8D6BE3594FC6AC5D9D00A0C08AB785B4
C:\Users\john\Favorites\Links\Web Slice Gallery.url
  • Type: data
  • MD5: 911DB1484C5D1D93C9766F19208D7A39
  • SHA: ED658DF2AA315B6408C62D621383F56434B95F58
  • SHA-256: B9F63542C6ACEF7FB0E88785C2A2E3A52659E6BFE600A4D57A67564A031C9B87
  • SHA-512: A79BC5F0F7D1C4F065FABDDAA2A26851C96CA8E3455B76E32AB24DC7FC9D8118D4316CE9943F6C7A44FB6ECAB089B4CBFB1723AE29B781460499D73B0D6FA69B
C:\Users\john\Favorites\MSN Websites\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: BB226F6F538F779AA565138A9E55E447
  • SHA: 6A9C2BE5C136BD1A8DD3ABEE4834029646B08A69
  • SHA-256: D028C1FF67354BCB8E67C9E2BBB030366B88D6A5A77128AAC2EF5552CC84FD3A
  • SHA-512: 2949208BBFBE7EFBF47AB066C27C72126717EA0C37D02F164BEA16E481443D573F563DB54149C700677C13169E3D3DECBEE0F7F5E08CD2FCBD7A37529DD3A063
C:\Users\john\Favorites\MSN Websites\MSN Autos.url
  • Type: data
  • MD5: 986D9DDFED40D92D2ABE428BFFF073AB
  • SHA: 6075AAFE09049E879773E9FAE663884B4303B3B4
  • SHA-256: 527E6A924BB6879E2F8AA75AE5C799CC11A737D9FD97AFE4BE2E13D5005721E4
  • SHA-512: 0551EF6A27BCFC8CD76FBB7C0CC43C3F24F1E1B7E876253EA120DAE40D27CAF3F4E4E22F062D051E1AAD71F1341B5F6DE45E2B502E1DBB713D53917499578F3D
C:\Users\john\Favorites\MSN Websites\MSN Entertainment.url
  • Type: data
  • MD5: AD8C2DBB7CD5D615B0660A5029A2CC53
  • SHA: 0E985F4191333A81013A2CCC8B38890704796B2E
  • SHA-256: F9907CD02E514B5585CD780EFFDC87B92A173029DAB6F18D049BE304619530D9
  • SHA-512: 106BA3DF9C620A335A3EE1C4A8C28FA6B8DECB1B3202CED8E80FB224FE69CC7323BDEB0C3BF4081D043E8CC91B3D1DCDF858F7A371200101D5A0BFE39A4FADA5
C:\Users\john\Favorites\MSN Websites\MSN Money.url
  • Type: data
  • MD5: 52F7EF9B0449D5A553AAA36F37B29F69
  • SHA: C598B93822F7E819BB1A75D124D2DA4BB2A27BB9
  • SHA-256: A83706C8348260E493F3CA1727FF71AF807602386923AB85FBB13AC6FA4B5DAB
  • SHA-512: C7447DBEB5D78CE2267EC4A8DB32F90A389DFE5C6C007072A1DC1247929D9A7B91FA94456BC2E2F74F722FC23EE168278A05B375F849CD63E43F7D376427560C
C:\Users\john\Favorites\MSN Websites\MSN Sports.url
  • Type: data
  • MD5: E143C67FBAB6632875A4D95E62868801
  • SHA: 12FF21429C3C496EF7F7D40BA32B8ACE4FFE721E
  • SHA-256: 4D9A31ED0AE22FBD8D8EB4AEF18DBF7C0B0F0DBF31E4FDE0D08DD807FBFF9222
  • SHA-512: 5BD22BD29E990FB3706F3ED8CD10867C633028D72ED9BDC50000E4A07E6AF0FE3E5DD1BD2D590DBDA4D15592F863B6DF4884612EDDDA5F23FCBF823821B3D0A1
C:\Users\john\Favorites\MSN Websites\MSN.url
  • Type: data
  • MD5: 82CC3F7E74CEB1F0DA79B6065EB78F92
  • SHA: 2C7C273D96D851C123F4C889A0C2B75B619B6E13
  • SHA-256: 4D8865E5B794307E09B7D14D82ECDB073EED9AF2C5F8EDC7BA04A92F84444F5E
  • SHA-512: 5FE108A277EDC5C47E8741929584EDED1703C6C638DD3D1D1F902717790468F1232A211DCD66A9414058CDDEF3E27FCE0E3681985ACE8180812490F8971B78FA
C:\Users\john\Favorites\MSN Websites\MSNBC News.url
  • Type: data
  • MD5: FE78D4858C586A8D3BFF118B0FEC9E01
  • SHA: AAD647248AD916942D15FDFA584A1523A4B9204B
  • SHA-256: 5EAC1AE447E1A8AB0F520FE08BF095F383703180D806819927C304EA46F7A04D
  • SHA-512: 29FB596A98F509916C2990593D11F346868347E17FE0ED6CA28B7B3E690A11A605CC2F583EED220601EFCE9E7B61273CB740AA36962A47E1A17F3D80C2CEC112
C:\Users\john\Favorites\Microsoft Websites\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 436F30C530172F77D0E25B57FA4E5DE3
  • SHA: DF9CC5B84340A491C8AE5B646CA5B4DC671D5E77
  • SHA-256: 9064D490FFB54DB9B4B60BF972AEB327AE3AE189CB0957376404E92CC435ADC5
  • SHA-512: FD52660C5BAD2608FAC52FCAF67BF2BD2057004CD32D5F9589B4C40846D95DF8B8598A0E25333A1C8FFF97A4744A11EF3597E755F64B194AB67A49EB12D35B66
C:\Users\john\Favorites\Microsoft Websites\IE Add-on site.url
  • Type: data
  • MD5: 75AE9161F79F50243A2FC78B6AC22A18
  • SHA: 1EF43A5580C80BF7E37EF01B8AE4558D6B5DCCEF
  • SHA-256: DEB3241DD73DDD0D2EBDE63DB0E2D3E2FDF4B17A11C60B2F5503ECFA57193937
  • SHA-512: 229EA0618451F689C9690F211E92AC75E76A027260AC7E623D7B5E954417F2A209AD1D240514E5F723D00826E606E0D34AD5BD97EE7116BFCCFB069C64B15C3C
C:\Users\john\Favorites\Microsoft Websites\IE site on Microsoft.com.url
  • Type: data
  • MD5: 6E7411CD2C2E05F89D9496B3F9FFB779
  • SHA: 55036641C841564F0832B8E558C3F8C00D83645D
  • SHA-256: 1FB05856F337B076DAA0B785CE53199C0E965C85A1D86D29FDC7A32A9B0C9C63
  • SHA-512: 6D4FDCF5C7215354CE94C8A7840F2EF180EB9E2C70D8D9D74DE8799D954D1240C26958FC8B255178E0FDA51479D3D334ECFE8114E5F27A5681E6A19631D83317
C:\Users\john\Favorites\Microsoft Websites\Microsoft At Home.url
  • Type: data
  • MD5: 89D59A5CADA5B182A4EB06B4C5002722
  • SHA: A6CBA15BA4692F8197E37C55A6FE9F11A55F67B9
  • SHA-256: 85C9BE8B8ED25B3D011A71D2F42A4E0D07D538C0C4288F9D42C23C4532A13032
  • SHA-512: 4D213BFA2D2B9C687D951937BCFE70AB9F306C074978304FD49BB478349918C4CA5CB825CB9BD3E9AD3F480DEF5A2B1A7283D303EB05EF5F5E870029FB9C990B
C:\Users\john\Favorites\Microsoft Websites\Microsoft At Work.url
  • Type: data
  • MD5: 94980FEF928CB0E02A5A80C844CE2DBD
  • SHA: 894622405DCB026DCBD6722A915666E5D67025B2
  • SHA-256: 34F1871A2CAB45105B7EE5AF8173045D68953427873F6F4E14F9A942EDA0CBE9
  • SHA-512: B72555689BDD7609221156977F9E8ABA3465F9362B60FE959780F3755536A5A1A5C90B972EFD8776899CFC4607D5C32A3481AB5CA75FCE37142386925FA33C13
C:\Users\john\Favorites\Microsoft Websites\Microsoft Store.url
  • Type: data
  • MD5: A5A72AFD9C3C4A76973D0A05BFCA4063
  • SHA: 64FF19B602A8E55280FA00FEE431290E48101DEB
  • SHA-256: 645D0EC7B8C0BB405568E14086C23316643940331E7C22294DE13039D8C1D2C0
  • SHA-512: 670C117D3805929BCCD93D4C4570721D6F6108C8CB84018A76A5D9A2FCFCD0D72A7FF8F9B19B1C76FE745A913FCCBFF254F0587EA01F618FAB7CFD8886363E74
C:\Users\john\Favorites\Windows Live\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: BB226F6F538F779AA565138A9E55E447
  • SHA: 6A9C2BE5C136BD1A8DD3ABEE4834029646B08A69
  • SHA-256: D028C1FF67354BCB8E67C9E2BBB030366B88D6A5A77128AAC2EF5552CC84FD3A
  • SHA-512: 2949208BBFBE7EFBF47AB066C27C72126717EA0C37D02F164BEA16E481443D573F563DB54149C700677C13169E3D3DECBEE0F7F5E08CD2FCBD7A37529DD3A063
C:\Users\john\Favorites\Windows Live\Get Windows Live.url
  • Type: data
  • MD5: FA73571E9F339B3B2D576CFC1194D1AA
  • SHA: F9ACCB37AD0190080A5032E00DFF549613A1EB61
  • SHA-256: 2D801146122680C974508899385AC2A737EF29CF78F79A09DABF834F6FBB6D40
  • SHA-512: 3780568F9B1591226102125E714CA45A18B378BCF5AADF4789FAFD6DF27570069F6FAB0D05322E780DAD0722A41CAA5789DDD3432DD54D8222B9E907CFE1763B
C:\Users\john\Favorites\Windows Live\Windows Live Gallery.url
  • Type: data
  • MD5: 52AE3EB81EA1DDB3510E7B5750599DAD
  • SHA: 72D0C7920C9D71F68B3F876CD298A99FA5EB9488
  • SHA-256: C31A200416ECB88D8F66936A008B5A9D98B4744E3A228B8C81983895B4B6ABD7
  • SHA-512: 9AF2D213E51F24D3C774409B1E7719091F8D9A1A47E560A53E4BFFB5940AF63A20AA3A1941631386331F500712436BBD2A33FA5C2EA81DD3AC74C3E058456EC5
C:\Users\john\Favorites\Windows Live\Windows Live Mail.url
  • Type: data
  • MD5: DD96A60582F97FEAF87BF97AFDC2D380
  • SHA: 099158CFE00DC49A8EB038F8EECF8277B8CEA002
  • SHA-256: 3B350B6EC688E2CE070E09D66407ACF6E1EB8C47930AED317BBA90A091F40D5B
  • SHA-512: 6100CA7CA8AB29E43DF28E514D3AECEBB047D1B71EC09B2EC8E23A9382741A30B39279AE6332E3924422F9FFF4F76AE1FE4B8635A30F1B5BFB8F49A963E65029
C:\Users\john\Favorites\Windows Live\Windows Live Spaces.url
  • Type: data
  • MD5: 5E3D41D58BD382AD681621CC185ED50E
  • SHA: 096B8CCAA13718BDC3D6BE00FCC732CD76739E84
  • SHA-256: 0F18D534B282E168E17906DD34E2E42D07C599F8BDF15E9DD16E6B148984A238
  • SHA-512: 55C4E11AD2D7E68CFD96E793CDBE4E82FC1FCD258D26CD325F4A47FC3F0F72A0A305D7B598700634E16D164444B22F8D7499C65F16A66C1A332FF5EC93DC1FA6
C:\Windows\IME\IMEJP10\DICTS\DECRYPT_INSTRUCTION.html
  • Type: HTML document text
  • MD5: 58D28EF0108BAD955A3DE4EE45BF4FBE
  • SHA: 906443ABB5004C39C5AACB1C885315F623C7193F
  • SHA-256: 01F97A7CE83D6F881AF2A0895D42F147DA6A488FDCF667575F4D4ECE08598E94
  • SHA-512: E12365587BC17B765291E8CD6EDA96EE4090BC0775F9BB0840E55CE8F638947106D8D8D7E43CC65DE8D8CA8487DC2037C15BD4AB6543C7719CAE7DBEA423CB7C
C:\Windows\IME\IMEJP10\DICTS\IMJPZP.DIC
  • Type: data
  • MD5: E11B9DAF65744BD6B65B0FA46175558D
  • SHA: A0B276228FAA2F8B1DCE4502FBE190B5BAB0E519
  • SHA-256: 8F77B296E906C3C8457971AA493BDD3B9BE23B54DF8C6CDB6A7462CE844ACACF
  • SHA-512: 7AED2A5CE1176ED869CF45ED88C83DC86C4790F7263FBACDA384CD1960A1445E113CF94D8459A909CFA497C910B5CF90667F8576622CBB7D4F8278196E89762E

Contacted Domains/Contacted IPs

Contacted Domains

No contacted domains info

Contacted IPs

No contacted IP infos

Static File Info

No static file info

Network Behavior

No network behavior found

Hooks - Code Manipulation Behavior

Statistics

CPU Usage

Click to jump to process

Memory Usage

Click to jump to process

High Level Behavior Distribution

Click to dive into process behavior distribution

System Behavior

General

Start time:10:46:08
Start date:07/02/2015
Path:C:\Users\john\AppData\Local\Temp\download.exe
Wow64 process (32bit):false
Commandline:unknown
Imagebase:0xed0000
File size:208902 bytes
MD5 hash:A14F1C1DC020BED807A1E666D154D89A

Disassembly

Code Analysis

< >

    Executed Functions

    Non-executed Functions