General Info

URL

http://www.palemoon.org/download.shtml

Full analysis
https://app.any.run/tasks/0bbfa086-9275-4f2a-8f4f-be360a90b45b
Verdict
Malicious activity
Analysis date
4/14/2019, 23:28:57
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • helper.exe (PID: 2256)
  • setup.exe (PID: 476)
  • palemoon.exe (PID: 2512)
  • setup.exe (PID: 2400)
Application was dropped or rewritten from another process
  • setup.exe (PID: 2400)
  • setup.exe (PID: 476)
  • helper.exe (PID: 2256)
  • palemoon.exe (PID: 2512)
  • palemoon-28.4.1.win32.installer.exe (PID: 1888)
Downloads executable files from the Internet
  • chrome.exe (PID: 2112)
Executable content was dropped or overwritten
  • setup.exe (PID: 476)
  • palemoon-28.4.1.win32.installer.exe (PID: 1888)
  • chrome.exe (PID: 2508)
  • setup.exe (PID: 2400)
Modifies files in Chrome extension folder
  • chrome.exe (PID: 2508)
Creates files in the user directory
  • helper.exe (PID: 2256)
  • palemoon.exe (PID: 2512)
  • setup.exe (PID: 476)
Modifies the open verb of a shell class
  • setup.exe (PID: 2400)
  • setup.exe (PID: 476)
Application launched itself
  • setup.exe (PID: 476)
Creates files in the program directory
  • setup.exe (PID: 2400)
Reads CPU info
  • palemoon.exe (PID: 2512)
Creates a software uninstall entry
  • setup.exe (PID: 2400)
Application launched itself
  • chrome.exe (PID: 2508)
Changes settings of System certificates
  • chrome.exe (PID: 2508)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
56
Monitored processes
22
Malicious processes
6
Suspicious processes
0

Behavior graph

+
drop and start start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs palemoon-28.4.1.win32.installer.exe setup.exe setup.exe palemoon.exe helper.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2508
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" http://www.palemoon.org/download.shtml
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\samlib.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imagehlp.dll
c:\program files\winrar\rarext.dll
c:\program files\microsoft office\office14\olkfstub.dll
c:\progra~1\micros~1\office14\mlshext.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\program files\microsoft office\office14\visshe.dll
c:\program files\common files\microsoft shared\office14\msoshext.dll
c:\program files\microsoft office\office14\msohevi.dll
c:\windows\system32\mf.dll
c:\windows\system32\shdocvw.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\syncui.dll
c:\program files\notepad++\nppshell_06.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\stobject.dll
c:\windows\system32\cryptext.dll
c:\windows\system32\colorui.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\palemoon-28.4.1.win32.installer.exe
c:\windows\system32\credssp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\mpr.dll

PID
1472
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=73.0.3683.75 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fa60f18,0x6fa60f28,0x6fa60f34
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3152
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2512 --on-initialized-event-handle=308 --parent-handle=312 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_watcher.dll

PID
3520
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=3371255444247321053 --mojo-platform-channel-handle=944 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\73.0.3683.75\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\73.0.3683.75\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\73.0.3683.75\swiftshader\libegl.dll

PID
2112
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=12080993940091732549 --mojo-platform-channel-handle=1472 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
2456
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --service-pipe-token=7515547154716479252 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7515547154716479252 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2044 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2668
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --service-pipe-token=3899802289305524328 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3899802289305524328 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2108 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2836
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --service-pipe-token=1743374913038084342 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1743374913038084342 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2284 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3836
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=17591662907029426469 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17591662907029426469 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3168 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3128
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=12015900225665944380 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12015900225665944380 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3352 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2908
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=12640031669869330546 --mojo-platform-channel-handle=3248 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2100
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4241628589196967332 --mojo-platform-channel-handle=3308 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3304
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=605093162346012024 --mojo-platform-channel-handle=3304 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2608
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=10938935293689372297 --mojo-platform-channel-handle=3596 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3272
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5852858129124797992 --mojo-platform-channel-handle=2824 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2368
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=1798368084640851762 --mojo-platform-channel-handle=3776 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
3340
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=956,7004968012746500257,8454955085027539141,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=15898576863034901017 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15898576863034901017 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2640 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1888
CMD
"C:\Users\admin\Downloads\palemoon-28.4.1.win32.installer.exe"
Path
C:\Users\admin\Downloads\palemoon-28.4.1.win32.installer.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Moonchild Productions
Description
Pale Moon
Version
4.42
Modules
Image
c:\users\admin\downloads\palemoon-28.4.1.win32.installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\local\temp\7zsda83.tmp\setup.exe

PID
476
CMD
.\setup.exe
Path
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\setup.exe
Indicators
Parent process
palemoon-28.4.1.win32.installer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Moonchild Productions
Description
Pale Moon Installer
Version
28.4.1
Modules
Image
c:\users\admin\appdata\local\temp\7zsda83.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\system.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\appassocreg.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\shelllink.dll
c:\windows\system32\linkinfo.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\applicationid.dll
c:\users\admin\appdata\local\temp\nsbf976.tmp\invokeshellverb.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\zipfldr.dll
c:\windows\system32\fxsresm.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\imageres.dll
c:\windows\system32\netutils.dll

PID
2400
CMD
"C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\setup.exe" /UAC:80130 /NCRC
Path
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\setup.exe
Indicators
Parent process
setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Moonchild Productions
Description
Pale Moon Installer
Version
28.4.1
Modules
Image
c:\users\admin\appdata\local\temp\7zsda83.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\system.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\cityhash.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\shelllink.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\pale moon\palemoon.exe
c:\users\admin\appdata\local\temp\nsofe97.tmp\applicationid.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\appassocreg.dll
c:\users\admin\appdata\local\temp\nsofe97.tmp\litefirewallw.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\netutils.dll

PID
2512
CMD
"C:\Program Files\Pale Moon\palemoon.exe"
Path
C:\Program Files\Pale Moon\palemoon.exe
Indicators
Parent process
setup.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Moonchild Productions
Description
Pale Moon web browser
Version
4.1.8
Modules
Image
c:\program files\pale moon\palemoon.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\pale moon\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\pale moon\msvcp140.dll
c:\program files\pale moon\vcruntime140.dll
c:\program files\pale moon\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\pale moon\ucrtbase.dll
c:\program files\pale moon\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\pale moon\api-ms-win-core-file-l2-1-0.dll
c:\program files\pale moon\api-ms-win-core-localization-l1-2-0.dll
c:\program files\pale moon\api-ms-win-core-synch-l1-2-0.dll
c:\program files\pale moon\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\pale moon\api-ms-win-core-file-l1-2-0.dll
c:\program files\pale moon\api-ms-win-crt-string-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-math-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-time-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\pale moon\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\pale moon\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\pale moon\lgpllibs.dll
c:\program files\pale moon\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dwrite.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\program files\pale moon\browser\components\browsercomps.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\audioses.dll
c:\windows\system32\macromed\flash\npswf32_26_0_0_131.dll
c:\program files\java\jre1.8.0_92\bin\dtplugin\npdeployjava1.dll
c:\program files\java\jre1.8.0_92\bin\plugin2\npjp2.dll
c:\progra~1\micros~1\office14\npspwrap.dll
c:\progra~1\micros~1\office14\npauthz.dll
c:\program files\google\update\1.3.33.23\npgoogleupdate3.dll
c:\program files\videolan\vlc\npvlc.dll
c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
c:\program files\windows media player\wmplayer.exe
c:\program files\pale moon\softokn3.dll
c:\program files\pale moon\nssdbm3.dll
c:\program files\pale moon\freebl3.dll
c:\program files\pale moon\nssckbi.dll
c:\program files\pale moon\mozavutil.dll
c:\program files\pale moon\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\apphelp.dll
c:\program files\pale moon\uninstall\helper.exe

PID
2256
CMD
"C:\Program Files\Pale Moon\uninstall\helper.exe" /UpdateShortcutAppUserModelIds
Path
C:\Program Files\Pale Moon\uninstall\helper.exe
Indicators
No indicators
Parent process
palemoon.exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Moonchild Productions
Description
Pale Moon Helper
Version
28.4.1
Modules
Image
c:\program files\pale moon\uninstall\helper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\nsf4fb4.tmp\system.dll
c:\users\admin\appdata\local\temp\nsf4fb4.tmp\cityhash.dll
c:\users\admin\appdata\local\temp\nsf4fb4.tmp\shelllink.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ie4uinit.exe
c:\users\admin\appdata\local\temp\nsf4fb4.tmp\applicationid.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll

Registry activity

Total events
1882
Read events
1623
Write events
255
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2256
helper.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Pale Moon\TaskBarIDs
C:\Program Files\Pale Moon
A3665BA0C7D475A
2256
helper.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\64\52C64B7E
LanguageList
en-US
2256
helper.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\64\52C64B7E
@"%windir%\System32\ie4uinit.exe",-732
Finds and displays information and Web sites on the Internet.
3152
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2508-13199750947662875
259
3152
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2508-13199750947662875
0
2112
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2508
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2508
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2508
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
aggregate
sum()
2508
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
S-1-5-21-1302019708-1500728564-335382590-1000
1
2508
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
aggregate
sum()
2508
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
S-1-5-21-1302019708-1500728564-335382590-1000
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13199750948756625
2508
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2508
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aapocclcgogkmnckokdopfmhonfmgoek
D6684D0206BACA3896802E440F257ACD829E9639151C28EB011098244FED1000
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
15B1C3FE35F29528448F36A72A4DFBC58A8083C7190559D25865779166D220A2
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aohghmighlieiainnegkcijnfilokake
6B63F4C3BE646A45F40A3CCCAE7A87076ED982C1233841988B295A6089097D5E
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
apdfllckaahabafndbhieahigkjlhalf
570BFDE6929E7FF7A7302872CDF417977A105E9FD90F30D163D4DBCCFBD12DD2
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
blpcfgokakmgnkcojhhkbfbldkacnbeo
22A488C9A9E5C576AD7CE807648CBC29E9619033C994263DDC2D0B05B082F240
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
felcaaldnbdncclmgdcncolpebgiejap
A0239290E87B13629435E959FC0E28D467372068BE3E8DF59BF31AAF249FAC3A
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
D6B079666F209503A09486C70AC09307652A0F7F783166A999B27C99D0DA79E2
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ghbmnnjooekpmoecnnnilnnbdlolhkhi
9F794B17D6CEF6102EE6C6A4303C4C934A2E40758AEEDCA19F73A9E5AB85A566
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
00175B8120231631976CA8B862A3416996C9373BA3D289F0619DDA992973DDFA
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
63355C14E8C7DF9A075F2EDDEA6F2807DC8166B83F96F4C975B9B6554C6324D7
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
0E265BFED6F1C7D5F0A9BD790C50BB30E78E959631D51EEBB8BB0DE73E65763C
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
04A45240BDA55E8777FA04357712CA6DD942253A21323E4C7D3CCF769B34BFED
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
EFA63CBF982B82CF44E63E567FF3BB95FE3F51570D9A0CED8846E77B13199169
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
A81EDAC7072204D814CFA5614C0A04EB0B0E528D4866EAE723126A2CE4835FA9
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pjkljhegncpnkpknbcohdijeoejaedia
C5C338E1FFC30E9D352569D2CC450A8F4954969421C435C7ACF12914E311D822
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
713575C5B7A17D28989028E7AEE676C99060EA170B9B3CA7569CDCCAB315FE58
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307040000000E0015001D002400610200000000
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\EAB040689A0D805B5D6FD654FC168CFF00B78BE3
Blob
030000000100000014000000EAB040689A0D805B5D6FD654FC168CFF00B78BE31400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB040000000100000010000000DB78CBD190952735D940BC80AC2432C00F0000000100000030000000435FE6564241D6B3828352EF9BE443D511C21F0AFB325C4038A5820F00D87774A8EF2193DDAAE065B2572FAF2BF0EE63190000000100000010000000EA6089055218053DD01E37E1D806EEDF18000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C20000000010000007B050000308205773082045FA003020102021013EA28705BF4ECED0C36630980614336300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C050003820101009365F63783950F5EC3821C1FD677E73C8AC0AA09F0E90B26F1E0C26A75A1C779C9B95260C829120EF0AD03D609C476DFE5A68195A746DA8257A99592C5B68F03226C3377C17B32176E07CE5A14413A05241BF614063BA825240EBBCC2A75DDB970413F7CD0633621071F46FF60A491E167BCDE1F7E1914C9636791EA67076BB48F8BC06E437DC3A1806CB21EBC53857DDC90A1A4BC2DEF4672573505BFBB46BB6E6D3799B6FF239291C66E40F88F2956EA5FD55F1453ACF04F61EAF722CCA7560BE2B8341F26D97B1905683FBA3CD43806A2D3E68F0EE3B4716D4042C584B440952BF465A04879F61D8163969D4F75E0F87CE48EA9D1F2AD8AB38CC721CDC2EF
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
2508
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
F190062D361E409AC9BC3DF981B82F617EE2DC2800525D7C946CE135C102E8B0
476
setup.exe
write
HKEY_CURRENT_USER\Software\Clients\StartMenuInternet
PALEMOON.EXE
476
setup.exe
write
HKEY_CLASSES_ROOT\.htm
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.html
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.shtml
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.xht
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.xhtml
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.pdf\OpenWithProgids
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.oga\OpenWithProgids
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.ogg\OpenWithProgids
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.ogv\OpenWithProgids
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\.webm\OpenWithProgids
PaleMoonHTML
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML
Pale Moon HTML Document
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML
FriendlyTypeName
Pale Moon HTML Document
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML
EditFlags
2
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML\shell
open
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonHTML\shell\open\ddeexec
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL
Pale Moon URL
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL
FriendlyTypeName
Pale Moon URL
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL
URL Protocol
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL
EditFlags
2
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL\shell
open
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
476
setup.exe
write
HKEY_CLASSES_ROOT\PaleMoonURL\shell\open\ddeexec
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp
URL Protocol
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp
EditFlags
2
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell
open
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
476
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\ddeexec
476
setup.exe
write
HKEY_CLASSES_ROOT\http
URL Protocol
476
setup.exe
write
HKEY_CLASSES_ROOT\http
EditFlags
2
476
setup.exe
write
HKEY_CLASSES_ROOT\http\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
476
setup.exe
write
HKEY_CLASSES_ROOT\http\shell
open
476
setup.exe
write
HKEY_CLASSES_ROOT\http\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
476
setup.exe
write
HKEY_CLASSES_ROOT\http\shell\open\ddeexec
476
setup.exe
write
HKEY_CLASSES_ROOT\https
URL Protocol
476
setup.exe
write
HKEY_CLASSES_ROOT\https
EditFlags
2
476
setup.exe
write
HKEY_CLASSES_ROOT\https\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
476
setup.exe
write
HKEY_CLASSES_ROOT\https\shell
open
476
setup.exe
write
HKEY_CLASSES_ROOT\https\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
476
setup.exe
write
HKEY_CLASSES_ROOT\https\shell\open\ddeexec
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice
Progid
PaleMoonHTML
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
Progid
PaleMoonHTML
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice
Progid
PaleMoonHTML
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Progid
PaleMoonHTML
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice
Progid
PaleMoonHTML
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice
Progid
PaleMoonURL
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Progid
PaleMoonURL
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice
Progid
PaleMoonURL
476
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
476
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
@sendmail.dll,-21
Desktop (create shortcut)
476
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
@zipfldr.dll,-10148
Compressed (zipped) folder
476
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
@sendmail.dll,-4
Mail recipient
476
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
@C:\Windows\system32\FXSRESM.dll,-120
Fax recipient
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Favorites
007C01000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000007601000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C000000007801000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C00000000EE00000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4D7D5911005461736B426172003C0008000400EFBE454B864A1C4D7D592A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032007A0800001C4D59592000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C000000005201000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4DD15D11005461736B426172003C0008000400EFBE454B864A1C4DD15D2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200FB0600001C4DD05D20004F50455241317E312E4C4E4B0000540008000400EFBE1C4DD15D1C4DD15D2A000000E6C600000000010000000000000000000000000000004F007000650072006100310032002E0031003500200031003700340038002E006C006E006B0000001C007A0000001D00EFBE02007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004F0070006500720061005C006F0070006500720061002E0065007800650000001C00000000F800000014001F80C827341F105C1042AA032EE45287D66852003100000000008E4EC0AB11005461736B426172003C0008000400EFBE454B864A8E4EC0AB2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160090003200360400008E4EBDAB200050414C454D4F7E312E4C4E4B0000480008000400EFBE8E4EC0AB8E4EC0AB2A00000073DE0000000006000000000000000000000000000000500061006C00650020004D006F006F006E002E006C006E006B0000001C002C0000001D00EFBE020041003300360036003500420041003000430037004400340037003500410000001C000000FF
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesChanges
10
476
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesVersion
2
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
Pale MoonInstallerTest
Write Test
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon\TaskBarIDs
C:\Program Files\Pale Moon
A3665BA0C7D475A
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\Mozilla
CurrentVersion
4.1.8
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon\28.4.1 (x86 en-US)\Main
Install Directory
C:\Program Files\Pale Moon
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon\28.4.1 (x86 en-US)\Main
PathToExe
C:\Program Files\Pale Moon\palemoon.exe
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon\28.4.1 (x86 en-US)\Uninstall
Description
Pale Moon 28.4.1 (x86 en-US)
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon\28.4.1 (x86 en-US)
28.4.1 (x86 en-US)
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon 28.4.1\bin
PathToExe
C:\Program Files\Pale Moon\palemoon.exe
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon 28.4.1\extensions
Components
C:\Program Files\Pale Moon\components
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon 28.4.1\extensions
Plugins
C:\Program Files\Pale Moon\plugins
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon 28.4.1
GeckoVer
4.1.8
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon
4.1.8
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon
CurrentVersion
28.4.1 (x86 en-US)
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
Pale MoonInstallerTest
Write Test
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
Comments
Pale Moon 28.4.1 (x86 en-US)
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
DisplayIcon
C:\Program Files\Pale Moon\palemoon.exe,0
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
DisplayName
Pale Moon 28.4.1 (x86 en-US)
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
DisplayVersion
28.4.1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
HelpLink
http://www.palemoon.org/troubleshooting.shtml
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
InstallLocation
C:\Program Files\Pale Moon
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
Publisher
Moonchild Productions
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
UninstallString
"C:\Program Files\Pale Moon\uninstall\helper.exe"
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
URLUpdateInfo
http://www.palemoon.org/releasenotes.shtml
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
URLInfoAbout
http://www.palemoon.org/
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
NoModify
1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
NoRepair
1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pale Moon 28.4.1 (x86 en-US)
EstimatedSize
86402
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML
Pale Moon Document
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML
FriendlyTypeName
Pale Moon Document
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML
EditFlags
2
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML\shell
open
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonHTML\shell\open\ddeexec
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL
Pale Moon URL
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL
FriendlyTypeName
Pale Moon URL
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL
URL Protocol
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL
EditFlags
2
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL\shell
open
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe" -osint -url "%1"
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PaleMoonURL\shell\open\ddeexec
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE
Pale Moon
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\DefaultIcon
C:\Program Files\Pale Moon\palemoon.exe,0
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo
HideIconsCommand
"C:\Program Files\Pale Moon\uninstall\helper.exe" /HideShortcuts
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo
ShowIconsCommand
"C:\Program Files\Pale Moon\uninstall\helper.exe" /ShowShortcuts
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo
ReinstallCommand
"C:\Program Files\Pale Moon\uninstall\helper.exe" /SetAsDefaultAppGlobal
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo
IconsVisible
0
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\shell\open\command
"C:\Program Files\Pale Moon\palemoon.exe"
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\shell\properties
Pale Moon &Options
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\shell\properties\command
"C:\Program Files\Pale Moon\palemoon.exe" -preferences
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\shell\safemode
Pale Moon &Safe Mode
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\shell\safemode\command
"C:\Program Files\Pale Moon\palemoon.exe" -safe-mode
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities
ApplicationDescription
Pale Moon delivers safe, easy web browsing. A familiar user interface, enhanced security features including protection from online identity theft, and integrated search let you get the most out of the web.
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities
ApplicationIcon
C:\Program Files\Pale Moon\palemoon.exe,0
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities
ApplicationName
Pale Moon
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\FileAssociations
.htm
PaleMoonHTML
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\FileAssociations
.html
PaleMoonHTML
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\FileAssociations
.shtml
PaleMoonHTML
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\FileAssociations
.xht
PaleMoonHTML
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\FileAssociations
.xhtml
PaleMoonHTML
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\StartMenu
StartMenuInternet
PALEMOON.EXE
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\URLAssociations
ftp
PaleMoonURL
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\URLAssociations
http
PaleMoonURL
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities\URLAssociations
https
PaleMoonURL
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Pale Moon
Software\Clients\StartMenuInternet\PALEMOON.EXE\Capabilities
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\PALEMOON.EXE\InstallInfo
IconsVisible
1
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\palemoon.exe
C:\Program Files\Pale Moon\palemoon.exe
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\palemoon.exe
Path
C:\Program Files\Pale Moon
2400
setup.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AppId_Catalog\048C468E
2400
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2400
setup.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Pale Moon
OldDefaultBrowserCommand
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
2400
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
EnableFileTracing
0
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
EnableConsoleTracing
0
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
FileTracingMask
4294901760
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
ConsoleTracingMask
4294901760
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
MaxFileSize
1048576
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASAPI32
FileDirectory
%windir%\tracing
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
EnableFileTracing
0
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
EnableConsoleTracing
0
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
FileTracingMask
4294901760
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
ConsoleTracingMask
4294901760
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
MaxFileSize
1048576
2512
palemoon.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\palemoon_RASMANCS
FileDirectory
%windir%\tracing
2512
palemoon.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2512
palemoon.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000072000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000

Files activity

Executable files
138
Suspicious files
119
Text files
434
Unknown types
51

Dropped files

PID
Process
Filename
Type
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: 2f10f2255271b09d58af75f58476899c
SHA256: 24bc147f7c8a2dfcbe9296d83ce75a1f2c02076d8f6e6c81f6032c927ed5888a
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 65fe48962755451a1a5bab26e6fd978d
SHA256: 5a3d9a0a2c1f9b14cb52d9cce92b761ec1fe0460ea7d994179c96648455ead84
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: 538057da2c6ec8b927904346bb808792
SHA256: f8720e9250c5d5aace6918e1f67f6105f2cd08c0cf55633d2b6b28032d904e9a
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: bc75b80a80802146e79c383c94542f06
SHA256: 81a7a98e11ae94236f34a82a0d450a1100a9b8e752205248de0037a764b91a07
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: 2f10f2255271b09d58af75f58476899c
SHA256: 24bc147f7c8a2dfcbe9296d83ce75a1f2c02076d8f6e6c81f6032c927ed5888a
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: 4aa747ecc612240d522c23b51a8be7c1
SHA256: ecc116471ccfa09c599d389d71a574ebed01260b9760021a40665c4d8a22257d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 65fe48962755451a1a5bab26e6fd978d
SHA256: 5a3d9a0a2c1f9b14cb52d9cce92b761ec1fe0460ea7d994179c96648455ead84
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: aad41d33906cfdb31681ce8276648481
SHA256: 242cb185643df586a5f55735e8810b8d2b6b095c78be206e42cdaae7665bb2cf
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: a3eccd7f2f2c45d1553055593278645a
SHA256: d51dfd972e6df5e8185dce0b4eb26dccb0527c5f1c63bc081677335f69b92b67
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: 94e386a317faa200aa1dc270ce54e5fd
SHA256: e4ccd13d5861e3e28984fc7263d79b580a0bc7bbe0d234ed8f1a69706ef908f3
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: c8f1a3b19e5103751202010805bce5c9
SHA256: d5e2fb8495bbbfb66b2612cd5179c1a5f4746dcdd043ecd474363ffe4a8deb4f
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: 4aa747ecc612240d522c23b51a8be7c1
SHA256: ecc116471ccfa09c599d389d71a574ebed01260b9760021a40665c4d8a22257d
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: d5c4b8f7260563f72150a84fe884ee31
SHA256: 02839f3b2bdf6adfc89d2f800cc8acda59a40c3e7ce14ef3026f4c72e202297d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: b7e1023ebbf0e5018c58b5488c03a643
SHA256: e7238f5e38d3991e9d6219255e8cd951d6dd431402c4b4b295a68bd43efa3d48
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: e0aeba2d9d9ae584d6c1aa0f5929526b
SHA256: 4eca5b9e5be5750b0bc03fd74b6d5e351cb6d70fd63d5f740a1a122f906390e0
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 96d9965ea02eefeadf1f122dfa724449
SHA256: 4f31b2888ca82bd1ff40d71e2d11500456b99940dd469bfb097fcd304676fa38
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: a13048905fc64cd2103094c871c6d826
SHA256: fb23439a5982e723e8e4ae1a5a35f9bbbfba1e76feb4596668f57093b231da6b
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: bc75b80a80802146e79c383c94542f06
SHA256: 81a7a98e11ae94236f34a82a0d450a1100a9b8e752205248de0037a764b91a07
2400
setup.exe
C:\Program Files\Pale Moon\d3dcompiler_47.dll
executable
MD5: 8d5695f0b0a0330fe07802e4f3576b15
SHA256: a3a79c73a56e0c0e192e3a8fae32eeaa1f9f0f7b42fa86c92b6a737196d261c4
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: b7e1023ebbf0e5018c58b5488c03a643
SHA256: e7238f5e38d3991e9d6219255e8cd951d6dd431402c4b4b295a68bd43efa3d48
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-string-l1-1-0.dll
executable
MD5: e57ec98e69961e45cc7a4e0666d26b7d
SHA256: 52c9b061c4c74eeb70019edde2b690c7e9d9744979a3b718d6687b3a83f00def
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: 1028042a84aefe816280f22a4517dc68
SHA256: 4a88f73cae12080b9a637f76f8ab1b8ac29829817ff03ddd611a25b6981ee573
2400
setup.exe
C:\Program Files\Pale Moon\freebl3.dll
executable
MD5: 185cc04a0b7a77f221b243ed80cdad66
SHA256: aadc631a94b0c741e7c4be0f425d9995b2ccd7eca3256fe2e6987f803b0383c7
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: e8ccecac4f06679b9d5e77333d216ee0
SHA256: 2cf24c6aac48261ab04eb616e85dd707417697764f860fc29dd3955dd2c49226
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: e4110aa5c8a32b63de2c85e0bc297c54
SHA256: 01bb32d692b86ebb39a76893125e0f3aaf957c6e4bd682fb46eac32f6fb65be7
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 42153324a982f848d7a49bb7406125c2
SHA256: fcd8b213e2e9962b84d1eec4296bbefdf4465398a235e118be12c878fdc08c05
2400
setup.exe
C:\Program Files\Pale Moon\lgpllibs.dll
executable
MD5: af45276ea795221c11eed15920d5a78f
SHA256: 7b487453310fd90c2776662d0eb63d41a55608cba04273761e5764cc06f0e113
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: c8f1a3b19e5103751202010805bce5c9
SHA256: d5e2fb8495bbbfb66b2612cd5179c1a5f4746dcdd043ecd474363ffe4a8deb4f
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: a472bd416bdc12668523670360650910
SHA256: 48dceeea29558966c391cda34e5755386c2e7e252ea0a03d8d1f21e3cb370c5b
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: e8ccecac4f06679b9d5e77333d216ee0
SHA256: 2cf24c6aac48261ab04eb616e85dd707417697764f860fc29dd3955dd2c49226
2400
setup.exe
C:\Program Files\Pale Moon\libEGL.dll
executable
MD5: ff6ba5d92f7a3a0290b2fb792ef0188b
SHA256: 970135ef346b9e24cc50d89d67f3c6987acf0bdccbe71470366e06314fdcbfa6
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: a3eccd7f2f2c45d1553055593278645a
SHA256: d51dfd972e6df5e8185dce0b4eb26dccb0527c5f1c63bc081677335f69b92b67
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 00b548bf3eab7a6debce296ee5e877de
SHA256: d592b91a087c001f9ea38dc5912a90c78fad3a368879d04fd7e5650ed374c8dc
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: aad41d33906cfdb31681ce8276648481
SHA256: 242cb185643df586a5f55735e8810b8d2b6b095c78be206e42cdaae7665bb2cf
2400
setup.exe
C:\Program Files\Pale Moon\libGLESv2.dll
executable
MD5: ea192fdf69400adf4e3551bcc9c772cb
SHA256: cd61f447ba367b674d0313221cb8be342ac554866f92fe1cb374307f6e3e6ec3
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 032a139ea3cc41f2bb801cd580759a75
SHA256: 905f86530c56c9b453dd8bd9770440de0f6f35aa84b171de747a04d112e35aad
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: 0ee9e0c830a7534dcfc9be72146796f9
SHA256: 8f3f0fd765a37f48162f0bd00c3047e79b4eda355223bfcbed4d35b51349cfcc
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 032a139ea3cc41f2bb801cd580759a75
SHA256: 905f86530c56c9b453dd8bd9770440de0f6f35aa84b171de747a04d112e35aad
2400
setup.exe
C:\Program Files\Pale Moon\mozavcodec.dll
executable
MD5: 8cddae0d36f1f9c2115b60f2c1044c5e
SHA256: 1caa0ca9b817d9b088fdfd47975b473d27e9956b472ffc89fd2a3a3741e465b5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: 1028042a84aefe816280f22a4517dc68
SHA256: 4a88f73cae12080b9a637f76f8ab1b8ac29829817ff03ddd611a25b6981ee573
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 2a61e4e21bf255107884b6520af5bbcc
SHA256: 64742ee0729cbe72555247b0165fae03bea7a6b0147869253dae3bb0072173e8
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: 94e386a317faa200aa1dc270ce54e5fd
SHA256: e4ccd13d5861e3e28984fc7263d79b580a0bc7bbe0d234ed8f1a69706ef908f3
2400
setup.exe
C:\Program Files\Pale Moon\mozavutil.dll
executable
MD5: e3c4af756d15e764a822e177ca145cc4
SHA256: 8741ef17bfbe4a64d44b27608f5cb577855f532184535e57b8a0855966539c69
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: 538057da2c6ec8b927904346bb808792
SHA256: f8720e9250c5d5aace6918e1f67f6105f2cd08c0cf55633d2b6b28032d904e9a
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: 525a156e0ff61306fd44bf7937cacfae
SHA256: 41c69b545d931045a280f83b2f5fbe0ea18c35ac42dfca54b661b42fe8e4f982
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 00b548bf3eab7a6debce296ee5e877de
SHA256: d592b91a087c001f9ea38dc5912a90c78fad3a368879d04fd7e5650ed374c8dc
2400
setup.exe
C:\Program Files\Pale Moon\mozglue.dll
executable
MD5: 5eaca966a027d670f57ed16d419bb74a
SHA256: f52c871b071e4e89c146b9e58632a15183cfd57693d72ac747e5e100c03287da
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: e0aeba2d9d9ae584d6c1aa0f5929526b
SHA256: 4eca5b9e5be5750b0bc03fd74b6d5e351cb6d70fd63d5f740a1a122f906390e0
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: f61b9ecb79cd20fc2e8fce87286cfe43
SHA256: bfa24f94ba095174b82d3657f8ecc689eab8ff380c69b1c9a7e311eb70d66386
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 96d9965ea02eefeadf1f122dfa724449
SHA256: 4f31b2888ca82bd1ff40d71e2d11500456b99940dd469bfb097fcd304676fa38
2400
setup.exe
C:\Program Files\Pale Moon\msvcp140.dll
executable
MD5: d25c3ff7a4cbbffc7c9fff4f659051ce
SHA256: 9c1dc36d319382e1501cdeaae36bad5b820ea84393ef6149e377d2fb2fc361a5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\browser\components\browsercomps.dll
executable
MD5: b7f1b8181ad74461fb498bcae91cd7d6
SHA256: c0be066da9d6a9c20f6ba8a31fa94b82c67315c59275f12df656d448453e2923
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 99572ae21d1c8afe3d02f1124979e911
SHA256: e7d39dcb79d739ec030e9a4e2165b264a24c400566056e1fda267fdd1a8b36bd
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: a13048905fc64cd2103094c871c6d826
SHA256: fb23439a5982e723e8e4ae1a5a35f9bbbfba1e76feb4596668f57093b231da6b
2400
setup.exe
C:\Program Files\Pale Moon\nssckbi.dll
executable
MD5: 7aa46a6de888482a3175c69662769e06
SHA256: 1314a4df79e317d5d2584060a73a294fa9151f365a3c94f31d67649fcdcf81ab
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\d3dcompiler_47.dll
executable
MD5: 8d5695f0b0a0330fe07802e4f3576b15
SHA256: a3a79c73a56e0c0e192e3a8fae32eeaa1f9f0f7b42fa86c92b6a737196d261c4
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: 1557093add722d1c5a97c359bfcd0d77
SHA256: 3a20635a223e68418c22858413e8c603aac25723de1cb0f54dd675349ec3213d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: e4110aa5c8a32b63de2c85e0bc297c54
SHA256: 01bb32d692b86ebb39a76893125e0f3aaf957c6e4bd682fb46eac32f6fb65be7
2400
setup.exe
C:\Program Files\Pale Moon\nss3.dll
executable
MD5: 55ded131e66c06f0963ee0474af5ccb5
SHA256: 672ffbabca84a8670258b4d7a4b046eb0603e8759b041107955fa54bf96592ca
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\lgpllibs.dll
executable
MD5: af45276ea795221c11eed15920d5a78f
SHA256: 7b487453310fd90c2776662d0eb63d41a55608cba04273761e5764cc06f0e113
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: dbb81fcc74c59490008ee59bffff5a6d
SHA256: f33e6ac5d3e1c4f1d89564fb6aeeac170486c073b67694380755049dbc48eec1
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 99572ae21d1c8afe3d02f1124979e911
SHA256: e7d39dcb79d739ec030e9a4e2165b264a24c400566056e1fda267fdd1a8b36bd
2400
setup.exe
C:\Program Files\Pale Moon\nssdbm3.dll
executable
MD5: cfcc34df2be58373ef27a65ee9d1cd97
SHA256: 73ab03cf52dfd7e1b99596f6be4c8210c840ff531d279468204ced9dd552c4b1
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\libEGL.dll
executable
MD5: ff6ba5d92f7a3a0290b2fb792ef0188b
SHA256: 970135ef346b9e24cc50d89d67f3c6987acf0bdccbe71470366e06314fdcbfa6
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 64978e199a7239d2c911876447a7f05b
SHA256: 92b947f1d6236f86ed7e105cff19e23c13d1968861426511b775905e1d26b47a
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: a472bd416bdc12668523670360650910
SHA256: 48dceeea29558966c391cda34e5755386c2e7e252ea0a03d8d1f21e3cb370c5b
2400
setup.exe
C:\Program Files\Pale Moon\palemoon.exe
executable
MD5: 0ff6ba4c108561a196df0bd76c8c30f6
SHA256: 3ea5e6dfd57a337893d86d024d2faf16c934ad819b081ca65739b19d03387708
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\freebl3.dll
executable
MD5: 185cc04a0b7a77f221b243ed80cdad66
SHA256: aadc631a94b0c741e7c4be0f425d9995b2ccd7eca3256fe2e6987f803b0383c7
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: e33f52e89dfc376eaf7aa655f260ca76
SHA256: 0bd03e89a539aaa3100e2f7d9a058964730320e55aee1f85be8fd243eea7017a
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: 525a156e0ff61306fd44bf7937cacfae
SHA256: 41c69b545d931045a280f83b2f5fbe0ea18c35ac42dfca54b661b42fe8e4f982
2400
setup.exe
C:\Program Files\Pale Moon\plugin-hang-ui.exe
executable
MD5: ccab9f7623ef9a2bb5f74ecfb89051a3
SHA256: d13e8044b9a3ea4186d67361d4fec1c5fd722c5653f3389160b60090c16b8fbe
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\libGLESv2.dll
executable
MD5: ea192fdf69400adf4e3551bcc9c772cb
SHA256: cd61f447ba367b674d0313221cb8be342ac554866f92fe1cb374307f6e3e6ec3
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\setup.exe
executable
MD5: 49bbf4358ef0a2526504e16dda1d9d96
SHA256: 2b877508a408ce6587c23fd503bfbf10d26e41bf63256b67f480012ae55c972d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-string-l1-1-0.dll
executable
MD5: e57ec98e69961e45cc7a4e0666d26b7d
SHA256: 52c9b061c4c74eeb70019edde2b690c7e9d9744979a3b718d6687b3a83f00def
2400
setup.exe
C:\Program Files\Pale Moon\plugin-container.exe
executable
MD5: 034c310070f95a95b174a8e0b8d018af
SHA256: 0cd808d45665ec59bb7efef561f364bf13062aa429c751b4c7ac48c0e02b9767
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\mozavcodec.dll
executable
MD5: 8cddae0d36f1f9c2115b60f2c1044c5e
SHA256: 1caa0ca9b817d9b088fdfd47975b473d27e9956b472ffc89fd2a3a3741e465b5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-console-l1-1-0.dll
executable
MD5: 11e55839fcb3a53bdfed2a27fb7d5e80
SHA256: f6bdc8ffd172b44f4d169707d9a457aeef619872661229b8629ee4f15eefff0d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: f61b9ecb79cd20fc2e8fce87286cfe43
SHA256: bfa24f94ba095174b82d3657f8ecc689eab8ff380c69b1c9a7e311eb70d66386
2400
setup.exe
C:\Program Files\Pale Moon\softokn3.dll
executable
MD5: d370e31a910e091bce013c12b3c3d5c0
SHA256: 9a4450e8d6431fdcb6b9e72eac695df7ea03533347a97e029915574086927ef2
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\mozglue.dll
executable
MD5: 5eaca966a027d670f57ed16d419bb74a
SHA256: f52c871b071e4e89c146b9e58632a15183cfd57693d72ac747e5e100c03287da
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: 6a35a52d536e34ba060a19d06b1dac80
SHA256: a369ef130749bf8cd9f67055179e6f537f200c060af47493d49473912a95021e
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 2a61e4e21bf255107884b6520af5bbcc
SHA256: 64742ee0729cbe72555247b0165fae03bea7a6b0147869253dae3bb0072173e8
2400
setup.exe
C:\Program Files\Pale Moon\ucrtbase.dll
executable
MD5: 015b30309491a911e75748ad69c9e680
SHA256: dd32570b8183a8b117233333153da29cc8d2ac5b1c868440dd852d9c3f77baf5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\mozavutil.dll
executable
MD5: e3c4af756d15e764a822e177ca145cc4
SHA256: 8741ef17bfbe4a64d44b27608f5cb577855f532184535e57b8a0855966539c69
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-file-l2-1-0.dll
executable
MD5: b9287eb7bcbfdcec2e8d4198fd266509
SHA256: 096409422ecd1894e4d6289fd2d1c7490bd83daff0c1e3d16c36c78bd477b895
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: d5c4b8f7260563f72150a84fe884ee31
SHA256: 02839f3b2bdf6adfc89d2f800cc8acda59a40c3e7ce14ef3026f4c72e202297d
2400
setup.exe
C:\Program Files\Pale Moon\updater.exe
executable
MD5: d5940bd7a8a775a2dd8936f861b78b36
SHA256: a2ad6dccc011a67154fecf2a3a1108c1797ec1997a0a261735430bc36b4a048e
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\msvcp140.dll
executable
MD5: d25c3ff7a4cbbffc7c9fff4f659051ce
SHA256: 9c1dc36d319382e1501cdeaae36bad5b820ea84393ef6149e377d2fb2fc361a5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 48a5e206d92f3102256ec65e8d570ee0
SHA256: a272ae4fc60e511f48950b08f106fcdd3bc86831df908ee78d630f1ae921880c
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: dbb81fcc74c59490008ee59bffff5a6d
SHA256: f33e6ac5d3e1c4f1d89564fb6aeeac170486c073b67694380755049dbc48eec1
2400
setup.exe
C:\Program Files\Pale Moon\vcruntime140.dll
executable
MD5: a2523ea6950e248cbdf18c9ea1a844f6
SHA256: 6823b98c3e922490a2f97f54862d32193900077e49f0360522b19e06e6da24b4
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\softokn3.dll
executable
MD5: d370e31a910e091bce013c12b3c3d5c0
SHA256: 9a4450e8d6431fdcb6b9e72eac695df7ea03533347a97e029915574086927ef2
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\updater.exe
executable
MD5: d5940bd7a8a775a2dd8936f861b78b36
SHA256: a2ad6dccc011a67154fecf2a3a1108c1797ec1997a0a261735430bc36b4a048e
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: 0ee9e0c830a7534dcfc9be72146796f9
SHA256: 8f3f0fd765a37f48162f0bd00c3047e79b4eda355223bfcbed4d35b51349cfcc
2400
setup.exe
C:\Program Files\Pale Moon\uninstall\helper.exe
executable
MD5: 6896f53772938b18383630bd00956bec
SHA256: ab20c7f10f7364df712f733b26dc9c1d8b548668e5efefbe3733699bc2ae44af
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\nssckbi.dll
executable
MD5: 7aa46a6de888482a3175c69662769e06
SHA256: 1314a4df79e317d5d2584060a73a294fa9151f365a3c94f31d67649fcdcf81ab
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: 9d74d89f2679c0c5ddb35a1ef30bd182
SHA256: e207ffc6fef144e5d393e79de75f8f20d223f1ac33a011eeb822d30fa2031046
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: 1557093add722d1c5a97c359bfcd0d77
SHA256: 3a20635a223e68418c22858413e8c603aac25723de1cb0f54dd675349ec3213d
2400
setup.exe
C:\Program Files\Pale Moon\browser\components\browsercomps.dll
executable
MD5: b7f1b8181ad74461fb498bcae91cd7d6
SHA256: c0be066da9d6a9c20f6ba8a31fa94b82c67315c59275f12df656d448453e2923
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\nssdbm3.dll
executable
MD5: cfcc34df2be58373ef27a65ee9d1cd97
SHA256: 73ab03cf52dfd7e1b99596f6be4c8210c840ff531d279468204ced9dd552c4b1
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-file-l1-1-0.dll
executable
MD5: d826d27c73d9f2420fb39fbe0745c7f0
SHA256: c0e5d482bd93bf71a73c01d0c1ec0722ea3260eba1f4c87e797bae334b5e9870
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: e33f52e89dfc376eaf7aa655f260ca76
SHA256: 0bd03e89a539aaa3100e2f7d9a058964730320e55aee1f85be8fd243eea7017a
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ShellLink.dll
executable
MD5: d62d3e349689811f838dd10fb216eba1
SHA256: 5d103419245e2a5f124a96cace25d6836b2398edc0aa3919829b0fd6ad8b5d6a
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\nss3.dll
executable
MD5: 55ded131e66c06f0963ee0474af5ccb5
SHA256: 672ffbabca84a8670258b4d7a4b046eb0603e8759b041107955fa54bf96592ca
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: 9f3cf9f22836c32d988d7c7e0a977e1b
SHA256: 7d588a5a958e32875d7bd346d1371e6ebfd9d5d2ede47755942badfc9c74e207
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 48a5e206d92f3102256ec65e8d570ee0
SHA256: a272ae4fc60e511f48950b08f106fcdd3bc86831df908ee78d630f1ae921880c
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ApplicationID.dll
executable
MD5: 439928666a6baa4f9d2a1b0fb92265ec
SHA256: d43896c0c02bec598b7513b9a8815bb301c6b73da0fb2e0aee99146b4bd5e287
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\vcruntime140.dll
executable
MD5: a2523ea6950e248cbdf18c9ea1a844f6
SHA256: 6823b98c3e922490a2f97f54862d32193900077e49f0360522b19e06e6da24b4
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: ee5c2fb7bc23bfd06ff32556cc7c3b4d
SHA256: efc9f0e32bce971900ddf66a1a9e68daa3bfb2099a1ba9f24c6ee82da2cbd6e8
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-file-l2-1-0.dll
executable
MD5: b9287eb7bcbfdcec2e8d4198fd266509
SHA256: 096409422ecd1894e4d6289fd2d1c7490bd83daff0c1e3d16c36c78bd477b895
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\AppAssocReg.dll
executable
MD5: 1145a8e66064f36640e62e7ed58472bd
SHA256: 386c19010f04c04a3a0071cce09f7a2c10393392c7ca5877becc437ad9d31d37
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\ucrtbase.dll
executable
MD5: 015b30309491a911e75748ad69c9e680
SHA256: dd32570b8183a8b117233333153da29cc8d2ac5b1c868440dd852d9c3f77baf5
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-core-file-l1-2-0.dll
executable
MD5: ec4f2cb68dcf7e96516eb284003be8bb
SHA256: 3816bbb7dd76d8fc6a7b83a0ed2f61b23dd5fc0843d3308ee077cb725d5c9088
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: ee5c2fb7bc23bfd06ff32556cc7c3b4d
SHA256: efc9f0e32bce971900ddf66a1a9e68daa3bfb2099a1ba9f24c6ee82da2cbd6e8
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\AppAssocReg.dll
executable
MD5: 1145a8e66064f36640e62e7ed58472bd
SHA256: 386c19010f04c04a3a0071cce09f7a2c10393392c7ca5877becc437ad9d31d37
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\System.dll
executable
MD5: 3e6bf00b3ac976122f982ae2aadb1c51
SHA256: 4ff9b2678d698677c5d9732678f9cf53f17290e09d053691aac4cc6e6f595cbe
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\palemoon.exe
executable
MD5: 0ff6ba4c108561a196df0bd76c8c30f6
SHA256: 3ea5e6dfd57a337893d86d024d2faf16c934ad819b081ca65739b19d03387708
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: 6a35a52d536e34ba060a19d06b1dac80
SHA256: a369ef130749bf8cd9f67055179e6f537f200c060af47493d49473912a95021e
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\ShellLink.dll
executable
MD5: d62d3e349689811f838dd10fb216eba1
SHA256: 5d103419245e2a5f124a96cace25d6836b2398edc0aa3919829b0fd6ad8b5d6a
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\UAC.dll
executable
MD5: 113c5f02686d865bc9e8332350274fd1
SHA256: 0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\plugin-container.exe
executable
MD5: 034c310070f95a95b174a8e0b8d018af
SHA256: 0cd808d45665ec59bb7efef561f364bf13062aa429c751b4c7ac48c0e02b9767
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\System.dll
executable
MD5: 3e6bf00b3ac976122f982ae2aadb1c51
SHA256: 4ff9b2678d698677c5d9732678f9cf53f17290e09d053691aac4cc6e6f595cbe
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\ApplicationID.dll
executable
MD5: 439928666a6baa4f9d2a1b0fb92265ec
SHA256: d43896c0c02bec598b7513b9a8815bb301c6b73da0fb2e0aee99146b4bd5e287
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\UAC.dll
executable
MD5: 113c5f02686d865bc9e8332350274fd1
SHA256: 0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\plugin-hang-ui.exe
executable
MD5: ccab9f7623ef9a2bb5f74ecfb89051a3
SHA256: d13e8044b9a3ea4186d67361d4fec1c5fd722c5653f3389160b60090c16b8fbe
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\InstallOptions.dll
executable
MD5: f8d9d9418e6e1827ed2b53dd930e48fb
SHA256: 2a2878b54550178144665d4c5f67309f71f1089679ae0f84fa419b8a309a88e4
476
setup.exe
C:\Users\admin\AppData\Local\Temp\nsbF976.tmp\InvokeShellVerb.dll
executable
MD5: 1a6e1ea7e90e50d9a18e034e7cde41a6
SHA256: 2fddc8b8ab4bf4838ea374d25e4cb9e83362c3f1cb24f380137d14c814d56169
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\CityHash.dll
executable
MD5: 737379945745bb94f8a0dadcc18cad8d
SHA256: d3d7b3d7a7941d66c7f75257be90b12ac76f787af42cd58f019ce0280972598a
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\uninstall\helper.exe
executable
MD5: 6896f53772938b18383630bd00956bec
SHA256: ab20c7f10f7364df712f733b26dc9c1d8b548668e5efefbe3733699bc2ae44af
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-file-l1-2-0.dll
executable
MD5: ec4f2cb68dcf7e96516eb284003be8bb
SHA256: 3816bbb7dd76d8fc6a7b83a0ed2f61b23dd5fc0843d3308ee077cb725d5c9088
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\liteFirewallW.dll
executable
MD5: 2c8980aa8fad2477864defb3fde39ca4
SHA256: c58dc0e0ef677f88290ce8bbd014d0ef3f70e4fa07f484993e26352102462c2c
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: 9f3cf9f22836c32d988d7c7e0a977e1b
SHA256: 7d588a5a958e32875d7bd346d1371e6ebfd9d5d2ede47755942badfc9c74e207
2508
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 379605.crdownload
executable
MD5: 81a4cff97c5b322ebe6e8a49d57d7299
SHA256: 3e965a880dff47d3862c61483003b072ec9e9b9bd05f95566ffa0e16778a252d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: 9d74d89f2679c0c5ddb35a1ef30bd182
SHA256: e207ffc6fef144e5d393e79de75f8f20d223f1ac33a011eeb822d30fa2031046
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-console-l1-1-0.dll
executable
MD5: 11e55839fcb3a53bdfed2a27fb7d5e80
SHA256: f6bdc8ffd172b44f4d169707d9a457aeef619872661229b8629ee4f15eefff0d
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 64978e199a7239d2c911876447a7f05b
SHA256: 92b947f1d6236f86ed7e105cff19e23c13d1968861426511b775905e1d26b47a
2400
setup.exe
C:\Program Files\Pale Moon\api-ms-win-core-file-l1-1-0.dll
executable
MD5: d826d27c73d9f2420fb39fbe0745c7f0
SHA256: c0e5d482bd93bf71a73c01d0c1ec0722ea3260eba1f4c87e797bae334b5e9870
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 42153324a982f848d7a49bb7406125c2
SHA256: fcd8b213e2e9962b84d1eec4296bbefdf4465398a235e118be12c878fdc08c05
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\37CEF210B79D19B2751C2D7BEBF5087F4B621A3B
image
MD5: 3cfcdd80c6cdc30aea33242c134bccc7
SHA256: f4c7cc51443cbef71158c64ba3c8367ff84e693258e65ad97d5b76fac55c48b2
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\B48F586F28F8404BB492D959BCE9511B3B23E410
image
MD5: a35ecb6c172aeee1597b6c5b32af92db
SHA256: d8a66fee78c91147544a89e2b79240252d4adf67ebab14ac6c8f6b8f93f0bc3e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F14AAEBFB67CA4E141F4F5506E5CDEBB89CC4263
image
MD5: acde81db0bf894757b3745db0a1c7ddd
SHA256: 9bcdd4391b84a88bf65cd3f4353d059f299e1f8697341e7b69e8f19929b60c07
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\17BAE4E6805DA76CC8DFBAFAD536E01A2A8C660F
image
MD5: 71a186331049136570638e3caef59b4b
SHA256: add2a78b0c9b9847fce458f9a6b50601145676f5c0fc119b808a2f076be9ecb8
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\1989DBAD50C4D3B32D723E77AF943E507CA756B3
binary
MD5: 674372bbf78b4e89ed10a741c0feb055
SHA256: 422f18f19760664535ba7ffd9e89d27aaa54e7fad10d033bdba7a09a94c59309
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\49E3BCE15F97A080D165269F3758C08AEE6D8CDA
image
MD5: d36af1d2d8657e5f142f690c54216585
SHA256: 38829fae2b9b637d8897a0c08e29db2bcd88772abaa4f62099a5068d0d79cc74
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\51EF46481B684F80FF92EAE2F6F8077EF3C6D083
image
MD5: 616172828f23906a1fb5a3f091f8e843
SHA256: 812b7fefb32a5de15b4b677d800b6393baf55c4b1fe2e343ba66eebdb00ef002
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F08A145A7C05ED4AD9A0B36951B3EA0E9D0EF84C
image
MD5: bc46763c737f28a4c5455231497f7041
SHA256: 70089a6097f434922990b86b260b39cbf8e8242c0de0a79564166c01bed1de58
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\6C427D1D856D29F300C0A71366755521F4651E4B
image
MD5: 8fbdb37b608f49f3434f07dbf9e19adc
SHA256: f62c64b773cf71990f1d736fc8b253088210b6308bb412e57628d26cdaccd076
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\46AF1E93EC2C52002CF8D9D74B0B4B992E1E82D9
image
MD5: f480c9cf75ef39f8666a58674fa582f9
SHA256: 6893d79cc2b515805e5dcb2734d679edf8b21a9e522174807cf8e3d3112b4bda
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\sessionstore.js
text
MD5: 1756f14680e292e9a48f796983a47a6e
SHA256: 5e860011a6f98cd4d7a91ad3b7f96554dc70dc6fa8553abf7faebac2ce36569e
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\sessionstore.js.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\40EE271575613E4683C3ED81D432086F46F1E56D
compressed
MD5: 54d03569dab991bb23b64bf55178ad71
SHA256: f8ea2430f4245462dedd6f9cadf7ef345e78559f9befc87b42618e8f1dc83e16
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\thumbnails\2e66350a233b95c4e0347f82cd1fcbbb.png
image
MD5: 274daab5d39cf320ad38f97d3465825a
SHA256: 5c95ec3271432edaa95974971e81371e334a9ad1db7774cb55bd9a1cb0fc6b44
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\thumbnails\2e66350a233b95c4e0347f82cd1fcbbb.png.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F209F8851C2B26A6103F288F3CD95FCB76C3C514
compressed
MD5: d0af3e95cfda81af977e58846d215df3
SHA256: ca75b0485a0b07cd31ed309fcbc3585410b1b98bccb9007d8a7c1f752df6934b
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\6B4E1A47A28BFB2C820D7E80AA1A8B058D5BF027
compressed
MD5: 48a866af6cb0740441d12ecaf692c4e4
SHA256: dfc31488a94d0bde4eedec96850c36e750defa5860e9343e1ef32e3b0026c73d
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\0362A7B3C24C3C965B7062FA94A05DC70DD60F62
compressed
MD5: 02f92e911c3489abc3afff9a79fbf94a
SHA256: 305a6e4b05235c01c9cb44c3dfd740604cf2a3f47518c6731440c27685ec1d77
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FA0420FEF217A325A28D1968492140F268E05BA1
image
MD5: 60132c5637a563450bddadae2a639b54
SHA256: 05600d0a0da7b3b80d7a70cb49a2c98e5e76ed00a7c037de61ffc5b6c484463d
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\A05D5404F0FEAB2E3EFC3A309973EC71C66B21D5
woff
MD5: 30fd0df5c9323ee4d50f7f45cc94cf14
SHA256: b755c96a6757abdb2ace406aa30570a78420ba446fda8ff745512497553613af
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\27FCD29FF867ADE35D79717618AB4B394538C9B5
woff
MD5: c50adbf9774145250ea12ec1d3389861
SHA256: ba0c0ac92c54d94027e901e64c504347638bd87667dd7925c7c1bcd18c6ab55d
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4848A5C33129D8B2E0CFF02C23E8797E728FDB20
image
MD5: 4970c519a75cd45a6aee9567eac72ec3
SHA256: add6a989880b3557c3be41d9ad5ca0b0a87a1ccd4cedb9c29343c97d6028285a
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E18E07DA4B0912174C2A3275AF8E56BE9AF1315C
compressed
MD5: 24d4e6e0abe3e855035512fc961fe5e6
SHA256: 4fc134442c79a6a0101610369d0f828cd13a1b697e6d70077b85b583d337d464
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\9378F3DE01359198A34BA4F13325BAFCDF331062
compressed
MD5: 28dc3da1940e39030ea61ce1784edf7e
SHA256: c3689484b725ddeca6534297963c6d672304228a960691f0a865c3e84e3b8b94
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\DE44D2D8F211AE631E74521E8A21B98B157DF66B
compressed
MD5: f5caad9cf0eaf08e61494b2803a230f2
SHA256: 16d67864a0b3dd9f982d6c1ac3bbd5e9366d87aebb4299666e6de739096c078d
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4BA6CE5AF5B5C050D71612AAE36362B8668B4198
compressed
MD5: f63ebd5657d31b8154b7176a32825135
SHA256: 0fff24ec121eec6af601911eba1924d540869f64ee5e883699776055aae677f0
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\B15C8F386571107C4C1150D2DE262077307B6EEB
compressed
MD5: c4aedf5c7d0efbd48fb07e1a35fec977
SHA256: 2916d8d35db775cd94975b75123a3fa5a6b072eac5e4115ec6e2a051e6a860f1
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\search.json
text
MD5: ac92b528d07a9b586352b8c87b8bac5e
SHA256: 2a03d508f4d9c0f05d2074257f72e59e2e6cdff479ba2bebd9f7bceafded8e69
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\search.json.tmp
––
MD5:  ––
SHA256:  ––
2256
helper.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Pale Moon.lnk
lnk
MD5: 7b422e4e678b45a45ef6ee2962de902a
SHA256: 6344a37a41d38e60dff16735d221bc354ea431b509210e0eb3646ef0c29d878b
2256
helper.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Pale Moon.lnk~RF11509e.TMP
lnk
MD5: 7b422e4e678b45a45ef6ee2962de902a
SHA256: 6344a37a41d38e60dff16735d221bc354ea431b509210e0eb3646ef0c29d878b
2256
helper.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~ale Moon.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\730967BBAEECAEA7CF5A86C5873CB0FE96D2918F
image
MD5: 99b8cc8155bbdcf21e4716bfe4caf48f
SHA256: b371252e6d9d5316cd72a4063b0bf44e677e429643adddc47c50f45985b8a9e7
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\146B284A9A3C02C16324FC52F425AF9197E03336
compressed
MD5: 294e3f757a6e158c68e257683d45cbb5
SHA256: 27e2fe0baea0807374e9e6d69748b2c94b911ed1ad63b04cc976dc2ea875f6d1
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\EED0FE19220A259E82DE6FA941C8D0A20D80E1C5
der
MD5: 31af3f61be644182f340fc4fb4613737
SHA256: e2f0af26eb7f36d259ffa43d4ebab443b0b317881908369acc195674ec93735a
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\1882BBAF761918261783CFCD760A2953C3AEE10A
html
MD5: be408e226e6ff98ac747e68621ae01ea
SHA256: d317a4b884e29d1f34fef590c3a41c3db4333af21798300443405b7a549ff89a
2256
helper.exe
C:\Users\admin\AppData\Local\Temp\nsf4FB4.tmp\ApplicationID.dll
––
MD5:  ––
SHA256:  ––
2256
helper.exe
C:\Users\admin\AppData\Local\Temp\nsf4FB4.tmp\ShellLink.dll
––
MD5:  ––
SHA256:  ––
2256
helper.exe
C:\Users\admin\AppData\Local\Temp\nsf4FB4.tmp\CityHash.dll
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: 2515bcbe87e0cab895ca266662879799
SHA256: b71ae50dd6bfd280f952917fece5ee0b363dd15ae983ebe481f0e573980ffadb
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
binary
MD5: ad237876c7911da7b06e55d9374272d5
SHA256: c6534ea393612a3f70892829fab84ad71be593c6afe2f580967af67dd9e35f59
2256
helper.exe
C:\Users\admin\AppData\Local\Temp\nsf4FB4.tmp\System.dll
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
binary
MD5: 294b272ec30bc2a51a8aaa7b2a4a7861
SHA256: 72a8824d22517294264c158309218cbcf1926809eae618253ddd43e00955fe6c
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\.metadata-v2
binary
MD5: c501702ee85874929c4c1a1df4f98d40
SHA256: f31cc527cc490e6a18679c406fc4d012f93bca3722c10776577260ce299f207c
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\.metadata
binary
MD5: e6c300dadc9fceca188cb9fc18636499
SHA256: 4fdc9e09ef4f687004efcf467f71897f7983a2dd1dbc7d4e5c0c9f788ad98a63
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage.sqlite
sqlite
MD5: 9935f334ee9c58bcaaa724fca10e59ea
SHA256: 3a2b67a8e65e48a995dcfb4bca4a9725df7123c91b12f438b0e4ec13e28d0620
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\webappsstore.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\sessionCheckpoints.json
text
MD5: c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA256: 00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\content-prefs.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\prefs.js
text
MD5: 451b64d1c31bee3853dbffa12cffd350
SHA256: 7fcc25ea024f958254ed65643c0f420bb6280998d310e51cc3ec65c44ad78185
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cookies.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\extensions.json
text
MD5: 4f71d0b1ed32e10488adeed1ea0ee785
SHA256: 2c543254a9786fffa32367832399b452afef7a14c5ac16733db8c4fd8949068c
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\extensions.json.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\prefs.js
text
MD5: cbae6f233de26a25f02116be538ccf6a
SHA256: 256381be0440250674652b3b04426a997c9f17852f670216478bfed9144bfade
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\sessionCheckpoints.json
text
MD5: ea8b62857dfdbd3d0be7d7e4a954ec9a
SHA256: 792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\secmod.db
binary
MD5: e447afb28aa9a8452d8e730f47229b98
SHA256: 382116ab9a0907f1043ff875602ceb95178f2edc4962627a5a9eed471b22f5ca
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\pluginreg.dat
text
MD5: c26bdd4361543aa4da050d2eb4863096
SHA256: e71e2f8c23f977c1beb2482f9f1e824db65aaa171f304138b0c1c9389af6930c
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\pluginreg.dat.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\places.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\localstore.rdf
xml
MD5: 4686bf229bb25eebffdf8aab79478aee
SHA256: fb2ff0bfa46621749337fdd3616b5e7e94b005eca999637e3321de041dda14e9
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\prefs.js
text
MD5: 6d50d2f4edf2839f9d155aae28b454c1
SHA256: c0ac56ef4b7b0035375c7a3942bbcaff2dc6b2874cb7204919e4ebd6f1799dc7
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\extensions.ini
text
MD5: 50efd378831beb3809b4235b9545b1ae
SHA256: 82b89d2532fe8b8504699fd4c2adb92fa0c2b5bd9a3dbd4614bca1a4262d2dcf
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\extensions.ini.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\blocklist.xml
xml
MD5: 5cf76b33a858baf31ea821159bf47062
SHA256: 1e7b5bfea1a4ae7579bf3bb08bd131331d646166070adc77fc051fa9dbfc5634
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\times.json
text
MD5: ce050ecb6b742627261009049569ead7
SHA256: c64e85dff20ee6a50993e6936f68976c26cb2692838a2233812c50a932e81a95
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
text
MD5: 59c6a4f790467acf274de9e4a7b940b8
SHA256: 4f0ad4f3446df212bba5053ee97ddc689fa03f8670a195fb8e380a4bfc134c33
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\compatibility.ini
ini
MD5: aa6a18e3f0d431655bb67210d9c0a46c
SHA256: 5405839f68ecd80f349c3d43341236862d4bbb6768b544539bb2e62934daeef8
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ioSpecial.ini
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ioSpecial.ini
text
MD5: 51f26955623f4f37ce2dffa3c07815c7
SHA256: 0aca51ccb6b07d59bda761c97ef7cdc5796283c54c455e85e690160ff7b67d79
2400
setup.exe
C:\Program Files\Pale Moon\install.log
text
MD5: 969fa5508ec2fdacfefd821f1fce526a
SHA256: deb88133e583093d4ad633b2f37c492401c3830faba6cbb836ab7a44f0f77cf2
2400
setup.exe
C:\Program Files\Pale Moon\uninstall\uninstall.log
text
MD5: 3f0efac91c5b6707ae4d1f83e53bddad
SHA256: 30027eb628cd0247e783c87c205d738b312fdcd80a29882879a2f86a7325c3b4
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\prefs.js
text
MD5: e09095c97d28211b9a86d7055f249e19
SHA256: 0f1174679d1ddcd0e2283bd78937c78fca39df074edaa3627e69cbdccb548e1f
2400
setup.exe
C:\Program Files\Pale Moon\uninstall\shortcuts_log.ini
text
MD5: 79f5215e1169bf9fc6f6e1cf0919c956
SHA256: b4ba96ce59ad5951a332b9506668d0d7df29aa25982cd01bad613f3a680e1349
476
setup.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Pale Moon.lnk
lnk
MD5: 7b422e4e678b45a45ef6ee2962de902a
SHA256: 6344a37a41d38e60dff16735d221bc354ea431b509210e0eb3646ef0c29d878b
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\xulstore.json
text
MD5: ff720e72a5786219f02b78c8caf6972f
SHA256: 3dada8af89fb80e8d30b636ca682f24470bce91a03cffe0ebc1d569f1c47e935
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\xulstore.json.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite
sqlite
MD5: 901a5f9bbd33ad0979089a7e56ba8766
SHA256: 9a79c17cce02170a4416b1f7c2c2cf188eef1175bd414cd770b060655b4d4d22
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite-shm
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite-wal
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\Users\Public\Desktop\Pale Moon.lnk~RF111961.TMP
lnk
MD5: 98e2c39a4fa0fb6fcf682c717208beca
SHA256: 0dcde6b8e25d1b5b98a8388e56370539ceb6d2b4bf081e35259ad3ab0cf07097
2400
setup.exe
C:\Users\Public\Desktop\Pale Moon.lnk
lnk
MD5: 98e2c39a4fa0fb6fcf682c717208beca
SHA256: 0dcde6b8e25d1b5b98a8388e56370539ceb6d2b4bf081e35259ad3ab0cf07097
2400
setup.exe
C:\Users\Public\Desktop\~ale Moon.tmp
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk~RF111942.TMP
lnk
MD5: 7b422e4e678b45a45ef6ee2962de902a
SHA256: 6344a37a41d38e60dff16735d221bc354ea431b509210e0eb3646ef0c29d878b
2400
setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\~ale Moon.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Temp\mozilla-temp-files\mozilla-temp-10990
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk
lnk
MD5: 7b422e4e678b45a45ef6ee2962de902a
SHA256: 6344a37a41d38e60dff16735d221bc354ea431b509210e0eb3646ef0c29d878b
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: 0be23292fdcb1a9b7f8074c1c6037568
SHA256: 81aec3245e30d9fb2990a2ec5cf04fc8177752d5f2ea2c486fecc2cd20b45766
2400
setup.exe
C:\Program Files\Pale Moon\uninstall\shortcuts_log.ini
text
MD5: eebe15e5b7305f16550f0ec49c657261
SHA256: a2dbd47f84b74642069dab41ce701eecec47ea259c8611f2ab603febfe960b70
2400
setup.exe
C:\Program Files\Pale Moon\browser\components\components.manifest
text
MD5: a81e655e381a16a79c5bc34893bf6014
SHA256: bd640c499611185b722bc733b20bbcd3f8d54c8fe9e5bba0017a8d702c1f6a79
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\Program Files\Pale Moon\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
binary
MD5: 2ff2a902dd2231eb333e67b3c19f684f
SHA256: 3f341ca939e74e9034ee40798e4d40ad0874ea82b1bc4ded7d2f7749b3360cb6
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\yahoo.xml
text
MD5: 0a8d49cae37e8c7b8f08a759e468883e
SHA256: f624b885af63afe970a4130c184a5f45be394d93f3b4dbba18d412e8eb3f081e
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\wikipedia.xml
text
MD5: f3f3178cfd2b90b41e693a233303afc8
SHA256: 0277bc0e46b89ecc3f2fa24a36412246cceec900dd06e95f28585b6e64f48e13
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\twitter.xml
text
MD5: ab2fe6f2aef80adafb70ee102c5e6997
SHA256: 27fc0f34ff0aa5edbf23c65829374496bc244c0731f5a24d0e416aa1758a89cc
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\ecosia.xml
text
MD5: a8ee140e79a3ae99cf05a7ef3b3ed39f
SHA256: 8ed094f7367e5db313fc6b6c5e8871a530d4f1b6d73dd3aa317ee3c6c0894481
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\duckduckgo-palemoon.xml
xml
MD5: c768f002aac1c68ab0a54b1b188e2cec
SHA256: 62abe626270d672d70008b94f7970698bed2c86faea4ef2af32d1e40c50d9d53
2400
setup.exe
C:\Program Files\Pale Moon\browser\VisualElements\VisualElements_70.png
image
MD5: 48135e965002dec3a7bb0b2120e28d36
SHA256: b0572a7b2df697c5080cc7601c0c03c423078094c5457075546f525ecd3ecadf
2400
setup.exe
C:\Program Files\Pale Moon\browser\searchplugins\bing.xml
text
MD5: c4a77bd5022fc2f45aa78f203f8be2f5
SHA256: e42648da84d4ad1f8f5f6cde3238528468020d69b1987f949217b0c94ecca56f
2400
setup.exe
C:\Program Files\Pale Moon\browser\VisualElements\VisualElements_150.png
image
MD5: 724137342e4b45ac00ffa6d0aba43a52
SHA256: 8375d461ccef694eedea17fd7e40166bbd5bea57e4b6cdbe9debf6efcd7e421d
2400
setup.exe
C:\Program Files\Pale Moon\browser\omni.ja
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\Program Files\Pale Moon\browser\chrome.manifest
text
MD5: f9b700918938fec0a3730ce8d29d01b3
SHA256: 29058fa9a14b0d4b2b9a90da000fb5fcca5a20ee38e18b9af7eece7f79a45432
2400
setup.exe
C:\Program Files\Pale Moon\browser\blocklist.xml
xml
MD5: 5cf76b33a858baf31ea821159bf47062
SHA256: 1e7b5bfea1a4ae7579bf3bb08bd131331d646166070adc77fc051fa9dbfc5634
2400
setup.exe
C:\Program Files\Pale Moon\defaults\pref\channel-prefs.js
text
MD5: 0c5a44fb5df34034f9207ebe29d6e1a2
SHA256: fff550a4eb81cd521cb14fef779f7da40a74df114cdc3a74a9d0cb26883b167e
2400
setup.exe
C:\Program Files\Pale Moon\dictionaries\en-US.dic
text
MD5: 3e2b987ef017c150d1ab4ad47057e908
SHA256: 4f5aec9a91c6e44a95b1115891fa04415e241e676150977b8e8964e409d6b2fc
2400
setup.exe
C:\Program Files\Pale Moon\dictionaries\en-US.aff
text
MD5: de7d2fb2a926fd13f49b784f9272cd65
SHA256: 3e13de9b20b1a2e7c21b73979d748fe255d789031793857d750bda9966d9d6b6
2400
setup.exe
C:\Program Files\Pale Moon\fonts\TwemojiMozilla.ttf
pi2
MD5: f933f7536fe175e16c0f1a12facbb539
SHA256: d542a28467319c96998b0b1612fba6180793abd9d59a99f74c48523084e16740
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
––
MD5:  ––
SHA256:  ––
2400
setup.exe
C:\Program Files\Pale Moon\xul.dll
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FD55830F82AD7468B179CD44AF83AFFF090C8B31
binary
MD5: 9cc3afd9cf8b61d45a3f1120aa9be152
SHA256: 05456b5b80faf333584f9e1c387ccf0eb0f690438048c5f4984cbc78d39181f4
2400
setup.exe
C:\Program Files\Pale Moon\updater.ini
binary
MD5: 6bb96118eec34c7bd2de8556faa95bfd
SHA256: 6c5e45be9b9aaa00a2d44ab9834af160a518d658f4165a46cbba7982a6a07229
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\BB19D98D7D64CF25C251627065E4461EA2FE64A1
binary
MD5: 7bed76a43c678b809d260aa5b7352ba0
SHA256: f882be98f7173581fcf66217d2364fda436d134f32f1f756a7ad2be48b9af025
2400
setup.exe
C:\Program Files\Pale Moon\update-settings.ini
text
MD5: 51ad6aa0ec1527c394883f35f2a63d67
SHA256: adb4a6712b039dccd43bdadc67c375573bb5bd7ae807e79de9a3e3b5dcb58a2e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\69B9E1D50E607B99671585D83BC72D358E5EC2B7
binary
MD5: 7f1e6f088bd115da9ffc26b0d3f2739b
SHA256: 23d0047d46154bd012119264bb077dc8019bf28da0e766974594bf5cbdb19e5c
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\326E78FEB08EA5868EA054E8DA361EDDFFA58317
binary
MD5: 0dab337c89d008e02a1c032b4f531ce1
SHA256: e47ca3d5e3f6178890765c66f325754ccc153f15aaa86004d93c23f39530c6bd
2400
setup.exe
C:\Program Files\Pale Moon\softokn3.chk
binary
MD5: c28f32f3756bedce68608d4a58b77092
SHA256: cde199c8097153395d15551d81e0ff3d91cc419ffd1bd444912bf455a24963bd
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\120E9B91DC4DD57BB972FBD3642846271236DC07
binary
MD5: d2f96f7c9f9a225425ca01ff1679592f
SHA256: 5bcfb01826e49e9e2bd5432a5b03720016c416424269d3d19e6b5ea4e04b5f04
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\70541300CC4FD4CE7BD539087847DA5431005C8B
pgc
MD5: f93bd1ddb2b61ca483d4db0f43ee4c72
SHA256: 87db6554b9ece9210d56093c780448dabcda273952222bc6f132eece26e2bddc
2400
setup.exe
C:\Program Files\Pale Moon\palemoon.VisualElementsManifest.xml
text
MD5: 90b08f0fd1f90172a0cf6ded86fcdb57
SHA256: 9a31c0745bb595155ea04da38820784e0b337e065d43dfad2f01eab12593579f
2400
setup.exe
C:\Program Files\Pale Moon\platform.ini
text
MD5: 470b1a76e23c9f3ec22ba4b891db6c6d
SHA256: 5a791cbb4360268dd2f46b950e45f5aa182668d8a9e98b4b8d9d90a9d8a8dfd9
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4377A5F0B11F0BF33B7F869491718CC29CC8F885
image
MD5: d35b9a019666b9e749317c51811b5a86
SHA256: 3e14c12c09834f7f31f637dc673242dc6381d33650885961cca7e3ea78100036
2400
setup.exe
C:\Program Files\Pale Moon\omni.ja
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\91A6E157DF2DB4C61FEC247BB222CEE023BA9E66
binary
MD5: 9966bbab3fd593cd9a99b148120cd015
SHA256: 8b65ffbce0196226bef426c421313b9b31dba38b48e159ffac8aeb9761c4b9e4
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\3F6880B0B25FEB7CD3A05CD9D3872BABA5FF899E
binary
MD5: fc75c537992c7c01e156d48c2a671269
SHA256: d6971b6e52b09f08832063898951123b96ca54586c6d00baf8afebab39b7553e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\thumbnails\6f797f77bcd6032d3821207828c5217e.png
image
MD5: 9065db15f50ec817dd6c4aa7dbe0107e
SHA256: 9b94710e9d7517599090939dd0c33755941ce8259c5470964e4b880ed8bdc2e0
2400
setup.exe
C:\Program Files\Pale Moon\nssdbm3.chk
binary
MD5: 44ff8d7ae8e8c7b95b6468ac5aaa1282
SHA256: 534e95d8abfa064372500774fa5b94d1c50d25df9775d4c203703eb82332a1c5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\thumbnails\e3d8faff1b905b58dd633029a63baffb.png
image
MD5: 9065db15f50ec817dd6c4aa7dbe0107e
SHA256: 9b94710e9d7517599090939dd0c33755941ce8259c5470964e4b880ed8bdc2e0
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\thumbnails\e3d8faff1b905b58dd633029a63baffb.png.tmp
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\324D56D97166AD8ADBE90945E43D81A680B25C85
compressed
MD5: 8ea93fe8ab83b5b861d23aecbf65a622
SHA256: 422213f11ac3932bcad8aa42700ec98f8b509bfcd687170e27703bd940ad4bd8
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F1636898FE8769E7620ECBF11CC6C3ED543D084A
image
MD5: dd7638e69992a4e841ed247643452a51
SHA256: 95275d1b1c4fe8d3a96c624e5e3781df046af7823d978a9d43133913cb858726
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\0CF197F302DFC8085C683A2FECC8AD4BA84BE09F
image
MD5: 9051405c333fc153d99fb16f6d2735d1
SHA256: 85b5ba810cd5c3ea8602873bde1e84c4c1bb88f07e69f798fcc1671ab5e76546
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E61DAD31B5396D660ABA479E4B8EEB62AE591E6C
binary
MD5: c55a3467a3fa9bf0132dbb23ceba8093
SHA256: 0d1c5ee19ad54d54ad72905ea62347aa0e6d7338689c6e8e8a25c6bfbd0717a3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5E3D5F663EC84D0FFE5B615A12D8B1345E90D96C
binary
MD5: 53daccf9ebe52519af27c277c05d6f4b
SHA256: b255ea70dff8d055f467d26cbdf844aa2b014d01f899bb0566ad8640f386f83c
2400
setup.exe
C:\Program Files\Pale Moon\freebl3.chk
binary
MD5: 45139a8a0ca5fa16add9bbe069b1b718
SHA256: 1367d27e1f9649c304a4002c399ef5b661dd630bfb067942abeb24f8fbdb664e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\10A7A0A6F0329449E65B6D3B73E8D2E7CE4CD770
image
MD5: 703583e8eb3682079ff30cbcd74d0806
SHA256: aeb4361c6765b0de5955dbb306e01afdb53465b66ccbb5dda538397d9084f055
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\7367A43B4DE203D0196F86439B4AEAD6A96FEA04
image
MD5: 4663f22e1eaff83f199b9e078771fe5d
SHA256: 1bd61e6a3defd3ce7741f51f06fb3ff67a4b08d51673d539153b880d1a4a9048
2400
setup.exe
C:\Program Files\Pale Moon\dependentlibs.list
text
MD5: adb769a683919136c2b835a7f034f918
SHA256: 3e2446357496f0d5c2872694a2561441c037b4ce9971bf3d7b0e0f4d65d90956
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5ACCCB147AA4F9816BC398BF9C45F34A5D65920F
image
MD5: 1a92c3bd53f35b18ecf7e6fcd922b966
SHA256: eb8b4b48b7014630d0ad93196e594de942a6a5d2daea514c83760dff3ab475f7
2400
setup.exe
C:\Program Files\Pale Moon\application.ini
text
MD5: 18a4c0f138e35136f15ee69560192cb3
SHA256: 162a5fbe7cb4951fde567bde57c41c4d0b5b3a233589371ec9c3f3120add2eef
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\B0972356A5C5D4ED641A9BD243B7F90143BA1AF3
image
MD5: 50184ffed20fe295a08490293a195e37
SHA256: 2806f47baa3cb4e6d3f9029dfcb00877ba8b615283310223d6f80343f3e2afd3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\47A1B1183D8E6634B22ECCEE6626BCA7259FBFC9
image
MD5: f337ae1d7547eb9084d81f6db118f53c
SHA256: 9efccc9ed29358513042cd11bbb197874bdb38df21ae43b9c47d5507f35a93fc
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\DA0436CDD09DFA170C097E6FB3F92859E890B5CA
binary
MD5: 1667375cd5da2257c09957590702a5b6
SHA256: 47b8dc69664c4dff9cdb5f770732c7079c60b9348b917f3d209334fe61e6df35
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\BFF9FE55D41A60F213FBEBE9A6E1BA83EEAE3FE8
binary
MD5: 1a24542f2bc82955265a29d5deeeddd3
SHA256: 1c6e5870c1665d70f947f539e2e334f7a90ff4852f39670a9c8aa737f60a3917
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\431B630E3CCF4B2CB53647795411B3C7C9B06A06
der
MD5: cfcaa20a814f10693dfa4cd55ad3b55c
SHA256: 4a829790fa8499433f84c0ef2a5d06edaeca82d891d7691d8bfd70f2a519b35c
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\088AFB851C028D9E256D0B7C68348F277FC77557
woff
MD5: 1077015dd7208324ed9c9c84edeae0a4
SHA256: 4b2342a52576c674562d55ba8b01d0d23835c8176a504d96c72bf7b15d3ab1f7
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\48599458D6618282BFC38D5F5DC62CC6E5D83ED1
binary
MD5: be274172f522aa14409f85b04677ef0c
SHA256: 7f2bd4e28e42786d7be030ae514709ea6dbb1c03664e0f62b7c7342b800c1c92
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\226034A6EE996D68E8A12D41A3D527E9645B1E24
binary
MD5: d46695b27659288bc94dbe425c3865ee
SHA256: 7b9f05c6e446019d8d4a30e5fa3f2530cb4575471703560d7a5390cd8f739d6b
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\648C5FC8D5C2CB828ED86E44DD9E5FB3A6430332
binary
MD5: 1f70ffac9fe2093413ed34ec52a44c23
SHA256: e9fc40f8c9a6f5fdfbd72844e524a38cb07cf2630b7e5d31b6dc98e4d21d15b3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\EEBBB694A51586FC2EB10AEB902DE544D79ABEA1
compressed
MD5: bdc20d3e9dd1a27564dad20423616441
SHA256: 29c63c1c277c132b9aa40d51b97609c106d1fd1df5dbaf5952ecf3f7d9bb5065
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5938E11ADA14DF914CA8164237AF5812AFA418F1
binary
MD5: b2190210bbf4942507b5f13bb2d3836e
SHA256: ace4189b723356a06bb2db5520955b0c766c4933283819667b66220414ab0bbf
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5748F0CEE3AC87243E7EA593F7212A743D3E8084
binary
MD5: 522b158ffdc68c190d4ad93fa798b0d7
SHA256: f387fd01bc9ee88755171af7d97374ee617d122fe8f5a26385cea7e8f968b6c7
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\35148DFB29C380E96E45A50B946F34767A005D10
binary
MD5: 11df25bfef5d4509cc365d54a6d8baa9
SHA256: 5ee2eed64e527b5762c061576bb5c28d92683d79702230ed5afc35c030571be3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FB2594CC4D6EB5DD30C8E9E9784A7C14A10BE59B
binary
MD5: c417460b45c6fbea457b6bec38a5b969
SHA256: c85ea6f9d91a324289e8ed6bfaca3cff3b83126c30dcf6057fe80e701316fbaa
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4090A9E57E9BA1475CF18610BDE4162E66E4BEC9
binary
MD5: a6d7455ae24fdba88315d70191469039
SHA256: 6de7fb7aab50a9c9008d2b1c67cb9eac7eba968be70c83209f378e968e0b3ec5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E41810CFFE0F33A32C1E19E6F98B3C9F0833FE13
pgc
MD5: a0e8ff6201aba4364669eedebfc216f3
SHA256: f962fa6c49232ec15fabf157e8c23f771f316958be856690c4a9801521bf8c5a
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\C5906DFA22959459690D52A7F5D2B498444E4452
binary
MD5: d28d52418ad87bcdf0da978ad56501de
SHA256: 5b37b3333956f486d8577ad6770de3da1709c5b95132d556097a254a733d581e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5211FBD3D24D9D16D70DE0459D1F2CEDD67BDF7F
compressed
MD5: 7502d9d41ababc72a3b9a88c8b99fbec
SHA256: c86fc3c007dad78891bc1eedf62e7190fe5e53bd3255e709e226018a1e87dfbe
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\51EF46481B684F80FF92EAE2F6F8077EF3C6D083
image
MD5: 9be473295cc85c4f598393e7d6728f85
SHA256: 3af02a1380e40f1e12a1ccf36a38033f03107333a1f8007acfd4086f2aa30c23
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\113042359C8882965798CEF3682A4297C9198BA5
woff
MD5: 4afab7bf290b540f1ecf5c400fe84401
SHA256: 257aeb65c403dd77ea62891d7b9af9c028d2160b5eb7cdeef57731794887ca13
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\doomed\20610
image
MD5: 616172828f23906a1fb5a3f091f8e843
SHA256: 812b7fefb32a5de15b4b677d800b6393baf55c4b1fe2e343ba66eebdb00ef002
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\2120014FFBF9FC87BD8C32E5D503361121B4E60D
ini
MD5: 1f467cef38cac48c9698e50a64fd2e9b
SHA256: a7528c2554ec6e771b5dad5853dda16c022b4eec46c93a5ba2e83b4fd4f4f4d9
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\DCA539D5E06264FEAEC96B4A3F2189D0EA593D43
ini
MD5: 166bfedf2ae775783d412044a0e219f4
SHA256: 93712333e20e46e83ae59415bb2b0694c671af5bcf3fedfdf8b883a0015ccec0
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E61DAD31B5396D660ABA479E4B8EEB62AE591E6C
binary
MD5: c639cfff9c4957d238395e6e0638bf78
SHA256: 054c1161ac99f40f82bf98275e69e3d3789d88b88b02a93c244dd162ed110cec
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\3BBE0DA2340E3DB93021CFDE6C7F1E0045FB9944
ini
MD5: 51bbfa520128ce6b4a19edf92bfe9e0d
SHA256: 5f1261fdc97e0eebc9b0d33b20e7e00ddb254e27f69998f2e7d63e853e1dac40
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\D17E414092AEB3B72333B897ADA637EEEDD95EB7
binary
MD5: c1b852f78b66df7fde15759809dbf67c
SHA256: 6da37b48c59994c56728a8d967a38ecccb2acd566485cc0eab0bc3a7edf837a2
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F80198C3A363679F1764FC23642A8B6BBFC3663A
binary
MD5: 1b5a10e712186edc9891073101809a1a
SHA256: ed96a863f41bc15c1b7fb2f2ef6adf0d7959b7ba09ab9f7a0f6b600ef657cba4
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\2113FD84D75B6DDAD41B8DE58BED3C3D2863187E
ini
MD5: 3ccb450dea3d4c4332d158909f1d757e
SHA256: b65db59cd306bf5187bb4261fbb81ca6cf8b6e32542a077e93018498e651016e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E7BCD960B052D3803206B5ADC8D641F6E45A1FF5
der
MD5: 3861572dae6838316d956fb9de97fac6
SHA256: 590426445dfcae5d615fe65031cfc0779f947e46ea596118217226c782549f5e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\90692A2C74F0E2D84DC96DB64FF6E46D048B3DD3
der
MD5: 15079b054a29377438902a47ca25de31
SHA256: 90408e195db8edc90765950b2e9231f1c8458501993b107a1856843d7ec5e637
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\04CDAE48C66C51C1B0C12508793EDD597B25C381
ini
MD5: e74c2a3202bf2f1d186268652dc15294
SHA256: a94566eeeff222d85051ce4b7a3a8bf11e5b75aae31bede0e9f5a9058974807f
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\9898013D360F2DCC1A8B967AD2B83E3BBA9BE69A
ini
MD5: b237c00151c18cdce2243d6937b5593e
SHA256: 0b508462a7e72e43c09c77b7c8df5248bb1284161513846d86eef577a0f1e702
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\77565D512C7538CF486E424480184BF0C03A5A8C
binary
MD5: df7303ae8013fef2d8fe8b3b771685b5
SHA256: ef3ce4fc26c353965eab86fac2e8e33aba87c679dbae4c22cc31f072fb5fd98b
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\A2435F2E1E32433207D3C132A4263DD7528A16DC
der
MD5: 63576fb70e0c443d7039eba48b21a209
SHA256: aca027ee5ff1de6ff513ad576ed1b077047cca4f2ab57565a1aee7b71196e01e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\9FDD58AB28649155F67B51CACC5F5D5ABD8517FF
der
MD5: 73c82d6cdbf13b65e2824194dec0374c
SHA256: 07d939722f58a662ab2577514dd27f0dbde27cb9da3c2fd377dc59b910527407
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\62967F2891EC18B7E8B96BD5A92A6FFE4C35E9BE
der
MD5: 6b523ec97907033a3db860f831c5594e
SHA256: 3540d35726b5c6c2e0826d7391d746e56fd06ec3f0958d3d4c26306068548111
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\5E4954707B44E5A4B4ACF5F22B52219A1DCA477F
compressed
MD5: 49b1198d18a6b4d0418495afd32dfd0a
SHA256: 7dc5e0377d2d84351ac084cb3789472fea7085b6050f7d828f2e1bf70d45cce2
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\324D56D97166AD8ADBE90945E43D81A680B25C85
compressed
MD5: c06b7058732929f4dc48d7a5fd7fe288
SHA256: f479a43d48740fdcdd9039a24125269954875773cb65187df8f34120e587833d
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\781FBEDEF4D611E2FFA77D4749FAB84E64F1A919
image
MD5: ae9e3d50253ff3556327237e6d38c5d9
SHA256: 5c455cde6fb0710cdcf1fcdebc34484aa2337f5e10192657b918d826b16ea4ed
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\90D45F9235E5237B9A1090807FA842DC0B4CF540
image
MD5: f0b82a326da205e4779d01357943cfb9
SHA256: e611a70b3aabcd01c031849331eaabca4ab70a5d0f100094e09df883ae7a2af5
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\summary.ini
text
MD5: 66a34877a951cc9c9bba97e64b0ce360
SHA256: fa9565942e0bc2ace2f08ded361fc6f249d7201dbc347630fb6f99f5a0c88c28
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\summary.ini
text
MD5: a14bb9a90590c3f1661390fa37feaaa7
SHA256: 4e9e0d51aaf7882d0046e41846f2a6716ad20eaf47f06fab0aefd7d8625d87b5
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\options.ini
text
MD5: 9c40c8d22be4a51c81b13f4d2ee9747e
SHA256: a764fd79f33692f45e1deda22a6a766e80b2850f3c033060e8ee388e925e82f8
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\options.ini
text
MD5: e587dc4fa6d582cf8863f19583482c4a
SHA256: 9621d5912f88052fe4f10dcc0c7b7dd58ec89d844dcf386a8963ae3a16828964
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ioSpecial.ini
text
MD5: cee8d58b44ec59685d18a7cef7d33138
SHA256: 48837faa3a48f06f4eca9e48c587cf318b22195704f7e6ca0d1368ec54c7e4a2
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\ioSpecial.ini
text
MD5: 1177ec72d72142515b4fb1e6ab89654c
SHA256: 0ff9222402822b79df39fb8fc56872e3eace8f7566a13587707260534d3d39db
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\modern-header.bmp
image
MD5: 6afb3056bc805b4ee8c97a2d364040b6
SHA256: 03d7ec52147c90401619bdbea562990b9a5af6d756c828b5759f1a641fdad8e0
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\modern-wizard.bmp
image
MD5: 80a60674509dc5a0ddfdae573f1c941e
SHA256: 6b853ea7b2e7b0786a734aff764cd87109a3a6a1a2bfcb1ae2d193227683e2cd
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FC10E032A2F438ABBAB82F07C1F8EAA77020C2E7
image
MD5: 4260b70299c9216ad5d38b0ad0d1d51e
SHA256: 538df69029736db230cf7e11bf2a37ce6b0cfc4d75796e9872c32e18820de3c4
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\options.ini
text
MD5: 9f45bffe7d0247cf0d20b1c60cdab9a0
SHA256: 711bf570e2511fe0b29ead2701284f987a312ca4587cbbb9918b1bae7c625dc2
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\shortcuts.ini
text
MD5: d3aaf1335c8a028cb494f48010317351
SHA256: 22eacf828685a6f420591063668f387e8dd8db9748380fa89e09c485b44942be
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\components.ini
text
MD5: 7306b708c80ba5b73a682cc456c1a54a
SHA256: 3480bec9d6bad2de34f66fa436c066cb7a09349b7a09b78d9a762cabd6a09bfa
2400
setup.exe
C:\Users\admin\AppData\Local\Temp\nsoFE97.tmp\summary.ini
text
MD5: c9b5d86a9a0f014293b24a0922837564
SHA256: 775c85f3552754ad3794b88c0cb6d6fc43d412cd9a87a4b9e847386a5bd0a9c4
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\569BE43F206D50BD47AA1D900FDF69208E1396E5
ini
MD5: c57fa5aacc9cffd53726a181075bfe4e
SHA256: abf75bd41f447c19e5044a13aceff30cc5602200a61ce7507e295607fc1bcf26
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FF4D0F935CB8D5383B6B2E7557177399F14E74CD
image
MD5: a1d1598e0a6be2800c0e096dc7af3502
SHA256: b66c518b2d2501aa848488f069c01c7aea54c4bef09b642ef12ea70efe00a1dc
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\2FD35B643E4AF22BA96DEE780EBBB822398B1601
image
MD5: 76df15486335d8b064b64f9270f04ddb
SHA256: 9e534d530b407582d24822694d124c21196f78a6644186e4b14d9038a00f8cf9
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\2FC0CD865D09CC7CDF503F182E2108A5F28AF1B4
image
MD5: ae46d81967592748528c8599295119b7
SHA256: 70479441acfbaec6bb74f2b15b074b76acc2c29a572e7503f6ced4aa91e0c5c4
1888
palemoon-28.4.1.win32.installer.exe
C:\Users\admin\AppData\Local\Temp\7zSDA83.tmp\core\xul.dll
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\8BD503E2B4DC6D5986D63DF805E022C1E74EB0A1
image
MD5: 7d08b9d61b156dc521236cf84e19cba7
SHA256: b04fc218c608643597de982e3a42371b75bd091910ac70b68b12f2e4625c778a
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\A31374F46B8A599C19233C774DF73ABC128CA276
image
MD5: 35d335256f48a3016d8baf5726cae58d
SHA256: 96191c9a69d8130ac21ef19d042047dcdbb5b84ae0490ce019196555b5e33bfd
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\35858FFFB8BC4C5F5A2430FFC0862C3238331596
image
MD5: d5334b0ee4c5c8ec62c3739421b12194
SHA256: a22d705babf14ae44adca0f77024e88db4ad889611178a34b74217c86ed4f019
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\18199E0C926EFA79A1D96A378073F7E3BE253AC8
image
MD5: a00652c21b49fc483ccb2b4dfc6eda0d
SHA256: b8679bc5d4650cada296318abce8de32c07661b3f5129cfb867c3e6b9e8979ed
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\BE5C3B4873967F2458692836A09B421DEB6BE41B
image
MD5: 2cf71853163ac7eb727bc5a367740fee
SHA256: c2560c605252d818c7948813ded28b3abde84327d1d0437d38c5cd45a5dc9152
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\B3825EAD1AF031179457A1C8CBF7CC219420831D
image
MD5: 085458b7f16ce2b927b39ec22c9a7d63
SHA256: 62e625d14329b0d2f206c692d1ea3a2cc5ba43b836ace7c2030a0d1d1752c897
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\A1F1C57184DEA1B266A29B46D9CCB1E737B18A57
image
MD5: 84b3b7aceac0dc253d6333151765c1cc
SHA256: a6d8cc1529e986e4c0ed1e644ad19ad113cb34ab9d128adced9ac8bf4a9bc540
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\15AF38894142FB41E63B7CD4EA2398C8F2267752
image
MD5: 8eb0d48b1864836ec12c6c0580d00f77
SHA256: a36c0548ba54c961bbe9d252fdba349c87cfc392ae6998b3c49f68226d6407b5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\8CDEDD1786AA716EBFFFAFB1B77BB4C9364D5F35
image
MD5: 31965ed8a2e15257b727ea2ba0d9cd26
SHA256: c3374ab8b80c9d9f30b9428a34c9ec2745d8fb0045f37e79d7d34dade1a32114
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\381DAAB3238E925300584DA39BC763FC9F1B31D6
image
MD5: 760113616a54f0dac452367cd0116a97
SHA256: fd67955cd1ac4cbdbf382c8df376808ae3076bdd136950cf01b9c93f04394649
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\199628FC208436074645AF1603A0AF766D50AACE
image
MD5: 9e90d3f26f07c8b2920edf4264037c97
SHA256: dc3433d4b0cf4e207ad2ac74fcab51a52f55a9b9509dc5988cfdd043f1e314f1
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\C15786C06B6D4CAE75400C2741A280BA99193F26
image
MD5: d30c5be1238fc0e5241dc0d7558d7c7c
SHA256: b9acc1457479e2cf3e0e2328a020a4fcf0626ce0521aa0a658984a4f1926df6c
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\55124397C863F797B457AE5B9A78E18E6E2C222D
image
MD5: d81874a25ae35f05b043df29743479d0
SHA256: 6b398019dca5625b7d818d2397a64115b4af47d30c08fb4f62d3ab59aa7b21b3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\82324BF0CF9DE5B8822F1662C19247FDED021BE5
image
MD5: 4477cc163d11245f47686505295f40d3
SHA256: 4f344e4bdd34103dcbae5247a3eb8be9fcc1b6c5956ac9e04963cd5b39fbec22
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\253BFB549FAC1937D8C4A112B825BA6888278518
image
MD5: b91b51064c3b8f97f0e203930ab40d28
SHA256: 1bef422323ccf45a23cf340f5febe57111340350ae86142209689c368ef5a41e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\90C647DC4675DDB2A28EE78F1BFD4EE1B52BDAD7
image
MD5: 42888aaf24d7c0e9d44715bec546f3de
SHA256: b829964c5fe664ffaba527f4b37c7fcf6b4b85846a9a1ae1e2f9bf9ca2358c74
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E0D1FCA4B58C7FC9548F1A9B2BA1ECF2DA8F9D3C
image
MD5: 7d8ffd0ea8c2eae927bbb68d70b28e80
SHA256: 29018172d4500ebf7162d82e57eff3c075a17b2c67a5fc3b8595972f8029d907
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\334416DC54BC5CA95ED1331256E70D05C5C836B2
image
MD5: 310d3ed3924755f4ab87814666823fe1
SHA256: cf958199a4f636d2387eccdd58496c1f70214f9f95168e36227e752e8146e07b
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\8DD6967F2302277E3342EC92B59A14EC8E9758BB
image
MD5: b57741819064b0734185957e61c6e612
SHA256: 5ce5bbdd2f935e6ed027ca8b834795c86e34c4386508eebf4c1c75c93b5083b7
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\E87CC67B6DFBF41A772EBCA3A1CFF3D88F90EA57
image
MD5: 64482f0ca71d4f0ac417f1e8b50f08a0
SHA256: 68e2c70297a36e6795ae39f4fde4cd16ab2095ed58ee2591da587bf0798aa50f
1472
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\DA73EB32227431A005362AB977C39755B5E2082E
image
MD5: c1a0fdaea4a29ae9a164aad97c455d11
SHA256: 63f1432fb1597e4601eefdba57152fc1476b52e11901d8a5734e38c157be16a3
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\3FB4722FC0EE32219B466E3A75617B4E96B40B64
image
MD5: 92c163dbed6ae56ad31329a7e7aa9222
SHA256: 84bd5ca5f8e7e8d8de7288250ab79019fa6f65b718dc424abf39582e5d7e88f5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\A275F5F9FC6D04E0086E5C16BFB558D01C88B1DE
image
MD5: 9ec749a55b432a79822ec36f898411f8
SHA256: 97f53928da4b22e9c0d786ea8b0eb373192c26453460f9067e68356cac0a343a
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4965C868E8BED1EB3AFAB8961B924A786ADA8EB8
image
MD5: 22215aaf7a7413879257a603bdc74d86
SHA256: 9eaafb5eb4520da3043fcf470fbd8d0a2dff03d4c22eeb8b4aacc53f125ab765
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\ACEF13E54380F644C61827809FCF1459D0BC02D5
image
MD5: a75d42bc1a730981527da09d49aa41fd
SHA256: b4a1ac1c2a693824a1706699c822552dc4e97f4fcc00641fdcd3c57f110ba7c6
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\54AC46E80DE1300F9281C6BE11D1D9DB2B45A483
image
MD5: 2462f776d9432d2b47ff5fd3a4409b6e
SHA256: 80387c45e9dcad5029dbf8897a84163ed60960951ae42fa11600fddb116f81ad
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\F6D09B5C68F971FBD70150066E8C06AAF978E3C6
image
MD5: ebc5c5b3da7af64c61a0242b4e120790
SHA256: 4af663df77e9ab296e5d4404e270c07d783dee9d259a3d38ce0a6d5c92ca4fb5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\271583765FC8F28AB613A5235F332C67735B2371
image
MD5: 23ad149121a68c41c09da9e27ca91042
SHA256: ba09908dc02a6c562267cecfad3deb74301301d398a80d502202d3d26abd2e40
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\FB60D365808383859C33E1952C56E79F5582310A
image
MD5: 58e839b461fbf85a0f8dd06201d653e7
SHA256: 121f775e46d88f38c039eac97eb1c832e276f8383e56af014c38937b3d444974
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\1A4A509B52196A98E17A1A9D7BA905510B92051D
image
MD5: 2bedafc3a645db3f3a4d92a1b700f182
SHA256: a8af0946baeeaf195fc14a2ec10860a533e413e5cec542a66613e6f77def71a6
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\EE1812B00B956D9A3B98C98D03599DF3D554BE57
image
MD5: 0f49b734c4c9e84feb74a55d0a273a86
SHA256: a1c59d69474d656531e13eae390d589fdf34173d915e2e850dbbf8079e709875
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite-shm
binary
MD5: a37715abdb297ce21a73930cb454c6f6
SHA256: 6b0e74b13192992bd362c9b5d6fb2a955702a5cfa4ece21efdf47fcb6fdc2d48
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\D5FE5DCA8725BCE9F72777D6E3A8C317DC1A8667
der
MD5: 0ffe72f19a6e742a3deaf56aa8a96f25
SHA256: f316a0de897afe76440bbee2df9f3de02b6e5ddb1792557cd66a6bb9d730035e
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite
sqlite
MD5: c1013def9fee098f3434c1c833748b12
SHA256: d751649a99d6f685f5ce68c912a7bae8fae1ab7e6bd1042f45056236e9ec041a
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite-wal
binary
MD5: 2fed713f9d417cc1d852207549b05c32
SHA256: 3dc45309b6ce23093420e943d29cd058bbe1bcfc5f36c040eaee659e05d05dc8
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\0615EAFDF4CDA826C47655575AB7445AF537EE80
der
MD5: b28e4cb5375151fd6366375ca803080b
SHA256: d2cb1f1779b66b4c26c804bd8d6591190f5d56afcace420244056ba1bb75d6b4
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\idb\3619119340leogcaarlof.sqlite-journal
––
MD5:  ––
SHA256:  ––
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\ED06ACA4DB6AFBEC508A462E1E94F0F356C1422E
image
MD5: 0459933e9c6069d158013f5cb4d4fd19
SHA256: 453c77fd191a76cea528d5809b105281f7f8bab351ad459df930e434a0aa79bf
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\4A351D22B8D8BE067E9E8A201E577A15E7535FFA
der
MD5: ef40bf08bf40234eff87e1bad56cd056
SHA256: 246f7604a6a2a4c12e4d3db341f24f948b0c3e23fc4ef1e1fca295f86e765b79
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\1D55305A70B52D651E346CFE46D2D36BC0214EE8
image
MD5: 6e1ec68f9f8b2b79e0df5493cbe359c7
SHA256: 78be9d8c15e698756fcf0c0014eeac298e428d9065cc1d529549fd4ec22eb40b
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\AEE1E8F07989E880310647EA410998C202169C76
image
MD5: b3f0fb4068d33e2f93aadeafd083accf
SHA256: 23c140c13bfdb2907da85a3b133066ab3b5bc524eb698889d11f15170e0f7753
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\23DFDEA0E53577C22132041DCC4553515F93C1F3
image
MD5: 9218b79aa02c43d32e57de9add89ab0b
SHA256: 2858fbbd1a3a0281c236c5fbcc215198f0701b61da7d9afebdb262e6069227f5
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\3369E6D73EB9E93DB14C421737551D0D04E670E8
image
MD5: e974f1c25179c56ade27103731d70665
SHA256: 61ce4c44151c99269ab6c1a2ec86405a6e2b1921827cb78b93cb31ff5bec6c20
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\554AA0930386349955A1F05276EDA95C8D2C7448
image
MD5: 6651da66257bae71084ce69eef4787bf
SHA256: 20b1458c1cf51eb0fb276f0925c3fbab28ddc122bbe8e21f81112bf66776efa9
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\9AAFEF96FDC35EC1D045E7EEB4965DAD76766EE2
image
MD5: 4162c37993297fb80d7266bf771ac3e4
SHA256: a49742fac4133047b7b23eaf0cb77ab10eba4a0dfd4fb0274d8ab11af69bc11e
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\D41F5190EAFA4B5499411E3A328AB2E5659B08F1
image
MD5: 0bf5db3a49b954505a65983a2f7a1353
SHA256: 65f4e1b3d27dbb05dcfb654a6a94aee6601ef4bd3f883aa60441ed920fd195d2
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\C6504C6828E2D18EE8BD171AF537976349D2470A
image
MD5: 52d2b7e302d73f8160582c2f45694f2a
SHA256: 629688e8b0e071dd6de770695fbd1c5babfe061bbae938d3e72b53baf7847364
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\CD84092BA6D7DE9C29C6566C9A6F20BE12CDAC09
image
MD5: 08c12203b3100b896ff10c11688797b6
SHA256: 83b9e59dfd9069a5db25504b57796b8735dbd3dc804c6ded2b08f96fed6158b9
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\.metadata-v2
binary
MD5: 002725cb1475b888f7ab98815442acf5
SHA256: 31703457991bd1e38ac59d6824a1efc4b458244a6b2f07309d49f61b9b72e223
2512
palemoon.exe
C:\Users\admin\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\storage\default\https+++palemoon.start.me\.metadata
binary
MD5: f14042d0d691871f502fd64ea2234a3a
SHA256: ccf4c55717b5824622d22f992885e92cd73727dcd60596e05782fbab0faeb7f6
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmqvzics.default\cache2\entries\439F4BA0E6ABA291E2F69F4CA9D1A47268FE1FC5
compressed
MD5: 89d5a6ebbeb1958509190ac9d4e44f0f
SHA256: 64af09b162ea560b57a89257a3baba807d419be3a6453536635a095337d332e4
2512
palemoon.exe
C:\Users\admin\AppData\Local\Moonchild Productions\Pale Moon\Profiles\dmq