Technical Information
- D:\users\user\appdata\roaming\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\82d14eef5cdc53385f66be2067f5f0c3
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\82d14eef5cdc53385f66be2067f5f0c3
- D:\users\user\appdata\local\temp\caba12.tmp
- D:\users\user\appdata\local\temp\tara13.tmp
- D:\users\user\appdata\local\temp\caba53.tmp
- D:\users\user\appdata\local\temp\tara54.tmp
- D:\users\user\appdata\local\temp\cabb4e.tmp
- D:\users\user\appdata\local\temp\tarb4f.tmp
- D:\users\user\appdata\local\temp\cabb8f.tmp
- D:\users\user\appdata\local\temp\tarb90.tmp
- D:\users\user\appdata\local\temp\cabc8a.tmp
- D:\users\user\appdata\local\temp\tarc8b.tmp
- D:\users\user\appdata\local\temp\cabcea.tmp
- D:\users\user\appdata\local\temp\tarceb.tmp
- D:\users\user\appdata\local\temp\cabe24.tmp
- D:\users\user\appdata\local\temp\tare25.tmp
- D:\users\user\appdata\local\microsoft\windows\usrclass.dat.log1
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b3bb9c1ba2d19e090ae305b2683903a0_b89a63ac6877bd1ed812438ce82c3eb8
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b3bb9c1ba2d19e090ae305b2683903a0_b89a63ac6877bd1ed812438ce82c3eb8
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\ea618097e393409afa316f0f87e2c202_1e65fd33f74047223af4d58cbfd34bce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\ea618097e393409afa316f0f87e2c202_1e65fd33f74047223af4d58cbfd34bce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\c46e7b0f942663a1edc8d9d6d7869173_6043fc604a395e1485af7ac16d16b7ce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\c46e7b0f942663a1edc8d9d6d7869173_6043fc604a395e1485af7ac16d16b7ce
- D:\windows\system32\winevt\logs\microsoft-windows-networkprofile%4operational.evtx
- D:\windows\system32\winevt\logs\application.evtx
- D:\windows\system32\winevt\logs\security.evtx
- D:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat
- D:\windows\system32\winevt\logs\system.evtx
- D:\system volume information\syscache.hve
- D:\system volume information\syscache.hve.log1
- D:\users\user\appdata\local\microsoft\windows\usrclass.dat
- D:\users\user\appdata\roaming\mozilla\firefox\profiles\0j9e9tku.default-release\sitesecurityservicestate.txt
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\103621de9cd5414cc2538780b4b75751
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\103621de9cd5414cc2538780b4b75751
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\644b8874112055b5e195ecb0e8f243a4
- D:\windows\appcompat\programs\recentfilecache.bcf
- D:\windows\system32\config\software.log1
- D:\windows\system32\config\software
- D:\users\user\appdata\roaming\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\e0f5c59f9fa661f6f4c50b87fef3a15a
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\e0f5c59f9fa661f6f4c50b87fef3a15a
- D:\users\user\appdata\local\temp\cabf804.tmp
- D:\users\user\appdata\local\temp\tarf805.tmp
- D:\windows\system32\config\system.log1
- D:\windows\system32\config\system
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\94308059b57b3142e455b38a6eb92015
- D:\users\user\appdata\local\temp\cabfc98.tmp
- D:\users\user\appdata\local\temp\tarfc99.tmp
- D:\users\user\appdata\local\temp\cabfd65.tmp
- D:\users\user\appdata\local\temp\tarfd66.tmp
- D:\users\user\appdata\local\temp\cabfdc5.tmp
- D:\users\user\appdata\local\temp\tarfdd5.tmp
- D:\users\user\appdata\local\temp\tar486.tmp
- D:\users\user\appdata\local\temp\cab485.tmp
- D:\users\user\appdata\local\temp\tar33c.tmp
- D:\users\user\appdata\local\temp\cab33b.tmp
- D:\users\user\appdata\local\temp\tar2ec.tmp
- D:\users\user\appdata\local\temp\cab2eb.tmp
- D:\users\user\appdata\local\temp\cab144.tmp
- D:\users\user\appdata\local\temp\tar145.tmp
- D:\users\user\appdata\local\temp\tard6.tmp
- D:\users\user\appdata\local\temp\cabd5.tmp
- D:\users\user\ntuser.dat
- D:\users\user\ntuser.dat.log1
- D:\users\user\appdata\local\temp\tarfe35.tmp
- D:\users\user\appdata\local\temp\cabfe34.tmp
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\644b8874112055b5e195ecb0e8f243a4
- D:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat
- D:\users\user\appdata\local\temp\cabf804.tmp
- D:\users\user\appdata\local\temp\tar486.tmp
- D:\users\user\appdata\local\temp\caba12.tmp
- D:\users\user\appdata\local\temp\tara13.tmp
- D:\users\user\appdata\local\temp\caba53.tmp
- D:\users\user\appdata\local\temp\tara54.tmp
- D:\users\user\appdata\local\temp\cabb4e.tmp
- D:\users\user\appdata\local\temp\cabb8f.tmp
- D:\users\user\appdata\local\temp\tare25.tmp
- D:\users\user\appdata\local\temp\tarb90.tmp
- D:\users\user\appdata\local\temp\cabc8a.tmp
- D:\users\user\appdata\local\temp\tarc8b.tmp
- D:\users\user\appdata\local\temp\cabcea.tmp
- D:\users\user\appdata\local\temp\tarceb.tmp
- D:\users\user\appdata\local\temp\cabe24.tmp
- D:\users\user\appdata\local\temp\cab485.tmp
- D:\users\user\appdata\local\temp\tarb4f.tmp
- D:\users\user\appdata\local\temp\tar33c.tmp
- D:\users\user\appdata\local\temp\tarfdd5.tmp
- D:\users\user\appdata\local\temp\tarf805.tmp
- D:\users\user\appdata\local\temp\cabfc98.tmp
- D:\users\user\appdata\local\temp\tarfc99.tmp
- D:\users\user\appdata\local\temp\cabfd65.tmp
- D:\users\user\appdata\local\temp\tarfd66.tmp
- D:\users\user\appdata\local\temp\cabfdc5.tmp
- D:\users\user\appdata\local\temp\cabfe34.tmp
- D:\users\user\appdata\local\temp\tar2ec.tmp
- D:\users\user\appdata\local\temp\tarfe35.tmp
- D:\users\user\appdata\local\temp\cabd5.tmp
- D:\users\user\appdata\local\temp\tard6.tmp
- D:\users\user\appdata\local\temp\cab144.tmp
- D:\users\user\appdata\local\temp\tar145.tmp
- D:\users\user\appdata\local\temp\cab2eb.tmp
- D:\users\user\appdata\local\temp\cab33b.tmp
- D:\users\user\appdata\roaming\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
- 'b-##.bid':443
- 'gr######nursingagency.com':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMt8H%2BCcd2jFqKm21xvW6lavQ%3D%3D
- 'b-##.bid':443
- 'gr######nursingagency.com':443
- 'localhost':49158
- '34.##0.144.191':443
- '35.##1.9.150':443
- '34.##1.73.144':443
- DNS ASK b-##.bid
- DNS ASK gr######nursingagency.com
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- ClassName: 'SystemTray_Main' WindowName: ''