General Info

URL

https://superscan.en.softonic.com/?ex=BB-765.1

Full analysis
https://app.any.run/tasks/93e3308b-b9d9-48fe-ac04-5b27ea097422
Verdict
Malicious activity
Analysis date
1/10/2019, 20:26:50
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
240 seconds
Additional time used
180 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • SuperScan4.exe (PID: 896)
  • SuperScan4.exe (PID: 2108)
Executable content was dropped or overwritten
  • WinRAR.exe (PID: 4056)
Reads CPU info
  • firefox.exe (PID: 2700)
  • firefox.exe (PID: 3616)
  • firefox.exe (PID: 2656)
  • firefox.exe (PID: 3088)
  • firefox.exe (PID: 3016)
Application launched itself
  • firefox.exe (PID: 3016)
Creates files in the user directory
  • firefox.exe (PID: 3016)
Dropped object may contain Bitcoin addresses
  • firefox.exe (PID: 3016)
Reads Internet Cache Settings
  • firefox.exe (PID: 3016)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
45
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start firefox.exe firefox.exe firefox.exe firefox.exe winrar.exe firefox.exe pingsender.exe superscan4.exe no specs superscan4.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3016
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" https://superscan.en.softonic.com/?ex=BB-765.1
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wpc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\winrar\winrar.exe
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\system32\windowspowershell\v1.0\pwrshsip.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\program files\mozilla firefox\pingsender.exe

PID
2700
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3016.0.1907529621\1609618617" -childID 1 -isForBrowser -prefsHandle 1348 -prefsLen 8310 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3016 "\\.\pipe\gecko-crash-server-pipe.3016" 1480 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\mp3dmod.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\msmpeg2adec.dll

PID
3616
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3016.6.248971301\1058499419" -childID 2 -isForBrowser -prefsHandle 2488 -prefsLen 11442 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3016 "\\.\pipe\gecko-crash-server-pipe.3016" 2448 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
2656
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3016.12.1594092730\1014574154" -childID 3 -isForBrowser -prefsHandle 3220 -prefsLen 12017 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3016 "\\.\pipe\gecko-crash-server-pipe.3016" 3240 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
4056
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\superscan4.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
3088
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3016.18.1623433417\1365668951" -childID 4 -isForBrowser -prefsHandle 6420 -prefsLen 12056 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3016 "\\.\pipe\gecko-crash-server-pipe.3016" 6408 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

PID
688
CMD
"C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/ace330bc-29d5-4655-8990-9beaf5b1a80d/main/Firefox/61.0.2/release/20180807170231?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\ace330bc-29d5-4655-8990-9beaf5b1a80d
Path
C:\Program Files\Mozilla Firefox\pingsender.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Foundation
Description
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\pingsender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
2108
CMD
"C:\Users\admin\Desktop\SuperScan4.exe"
Path
C:\Users\admin\Desktop\SuperScan4.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Foundstone Inc.
Description
SuperScan 4 Beta 1
Version
0, 4, 0, 0
Modules
Image
c:\users\admin\desktop\superscan4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll

PID
896
CMD
"C:\Users\admin\Desktop\SuperScan4.exe"
Path
C:\Users\admin\Desktop\SuperScan4.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Foundstone Inc.
Description
SuperScan 4 Beta 1
Version
0, 4, 0, 0
Modules
Image
c:\users\admin\desktop\superscan4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\riched32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll

Registry activity

Total events
1226
Read events
1180
Write events
46
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3016
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3016
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3016
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3016
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3016
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
WinRAR.ZIP
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
4056
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\superscan4.zip
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
0
C:\Users\admin\Desktop
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C8000000000000000000000000007A0101000000000039000000B40200000000000001000000
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000007C01010000000000160000002A0000000000000002000000
4056
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000620101000000000016000000640000000000000003000000
688
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
688
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
688
pingsender.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
896
SuperScan4.exe
write
HKEY_CURRENT_USER\Software\Foundstone\SuperScan
WindowX
310
896
SuperScan4.exe
write
HKEY_CURRENT_USER\Software\Foundstone\SuperScan
WindowY
74
896
SuperScan4.exe
write
HKEY_CURRENT_USER\Software\Foundstone\SuperScan
WindowW
659
896
SuperScan4.exe
write
HKEY_CURRENT_USER\Software\Foundstone\SuperScan
WindowH
572
896
SuperScan4.exe
write
HKEY_CURRENT_USER\Software\Foundstone\SuperScan
Maximized
0

Files activity

Executable files
1
Suspicious files
449
Text files
137
Unknown types
151

Dropped files

PID
Process
Filename
Type
4056
WinRAR.exe
C:\Users\admin\Desktop\SuperScan4.exe
executable
MD5: 78f76428ede30e555044b83c47bc86f0
SHA256: 03aa2e23b0e3be22ba6c7f09d4d570577f816d0ba51dd682acef7767eb39f078
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin
binary
MD5: 707c12070c52e55c2a996ac15e219b95
SHA256: 6c5410c655c8efc48d123abe708c8940a4218072c0daf85e03ab45da6d2ce6b9
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\ace330bc-29d5-4655-8990-9beaf5b1a80d.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-01\1547148494259.ace330bc-29d5-4655-8990-9beaf5b1a80d.main.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 6ea0cb0a28277f7eec4258419d6c42b3
SHA256: 1ecbe0b1d45551d729f53dd9275f7bc227aa048823e0b3efc7974304d6cc4158
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 54778a974b483c761d1e700d1bcaa101
SHA256: eabef734e5f93c9d144b0bf882cd655dfca4e6911d60d30616cee419222a7d83
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
sqlite
MD5: 19a4ffb335a14210c469f7d9973b426f
SHA256: 9faf82fa15966c32559f9e8d8bcde1e8492339656fdbc1bf44b73d1e1eec666e
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
sqlite
MD5: ff434d7ad3a7ca4f4414960e6a3d9652
SHA256: 76eb600302f3de27928abe655b7b3c127c1cb4609d00d112056359fb33de4797
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: 6b77a9f779399e95d1cee931a2c8f8ff
SHA256: 3a0285c8233ef0324b269f7291094e19fd9b77259f9419861ad796f7e9c979f3
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
text
MD5: ecb2874905c8a2b8f05462de28098b62
SHA256: a0e808a87b99cf6a3e27e4fbeb766a1ec24098da126e6986a25c3d4315f6fbeb
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
text
MD5: 1734596425a5837219d26ea5bd901f13
SHA256: e27d9a92b4fc3b5f054cb8fc018b8b7cb1c9d161081c80b2bb1890f290da39f9
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6DF9AE463ADE1E229FBE250BA7FF323BB13DABBB
compressed
MD5: 01c374415bca7e35578f15b8e295dccd
SHA256: df561cfeae745acdf9b29850c53e683c90aa9ff04f6ee9bc1515f4de6d362188
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\23EF5BCD20BD3D4A7CB6306E44CB8010A22669E7
binary
MD5: fd25323ff588153c0e974e7fbf30847a
SHA256: 512b230eb2bca03064b9311d69744504f6cbb9177b55f73cb3b41176eca1f4f5
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++en.softonic.com\.metadata-v2
binary
MD5: c4986cd2a481eb15b108fca32aa0f5ac
SHA256: 0b609c775367224b765ce72bc9a3456e5ec33bc88bc00906d533ac8245e5079c
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
jsonlz4
MD5: 3835d841dff1043535395337fba847c5
SHA256: 8cd1d0241c082db2cb5f4e6b20eb0235f853511d2c90960677fd5bc675164f2a
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++en.softonic.com\idb\993782502OBNDE__KSDISG_NLA.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping
text
MD5: 100bdee8a87c60b854fe169afbdfa211
SHA256: fb58de5513d0ed714e057352d9cb0df7c9b06f67b586875cb39a681ebcf0b558
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
text
MD5: f9eebc71634a93975b01d3b962477f53
SHA256: fee6c7910ff5ed5271e1efcf1fffb817a363bb4b7fc503d68533c3fcaa10c8f5
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-01\1547148494259.ace330bc-29d5-4655-8990-9beaf5b1a80d.main.jsonlz4
jsonlz4
MD5: 7c89ac937ab63f09f25d6f1465c3527e
SHA256: 4fe156179fc1d5f3f95d993953c5d3f90e499ad37171ea71f1ace939d6760477
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++en.softonic.com\idb\993782502OBNDE__KSDISG_NLA.sqlite
sqlite
MD5: e5115d4e84f526c8c14061d50e6580cf
SHA256: e1d74e2c425b20b530587ee4c43431636e3274c87fa227ecd3a241e5ebc7c5d7
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++en.softonic.com\idb\993782502OBNDE__KSDISG_NLA.sqlite-wal
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 024da76ae15468b48261bccd8f4eb5c1
SHA256: d3762fbf9a6495633ac496c40c823caa0a5b5506c2c152596b97e3b9d33c3287
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: 38a421f723f338ac558453db52bb78cf
SHA256: 16e0b3839d50e72f9ce9c42a46777ebd875b0baa74ea9313c3d11d2ea5122ac5
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8AAC4BC401CCACF157544B85C9656A17A3AE5426
compressed
MD5: ddbe8aa0ad9433fddea29c937ddea155
SHA256: aba82de4e399319a82896507b9abacedf538cedb6ab281549c31966eb151afb4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\182ABB341D7E259AB2DE4AB1F7E3120BEA27F382
binary
MD5: e521f267644a96f431d441d5c9065a3b
SHA256: b5ffed589fe098750a50383d018a1b506e797d25f59ec18dad588b3e819e9594
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E9BC148873699BF2F49EEF792C59747C64AA9F2B
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4732D2293D427AD351B680E444A0D13CB5698015
image
MD5: 9df55f854213f135de52f08462069b5d
SHA256: a37d37e39b66c613df7873515b511d6e1a54d5a7fa4d4ee61f91bb8b9ba6a22c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9D2074B4914E04A58E21382E8C27D7354BBA1716
image
MD5: 5beed220e8f76627de30cc16f3810aec
SHA256: 58076913ed418249587afc3c26fe96dead146867d57264ae0318cff1936a4124
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E96DAF80C13E9BCE17683FDFAA110037BF8115C2
image
MD5: 81c435ef89be811ea998d8e522b9d286
SHA256: 73b896141494edbd94bdc46b9c701e63faef8465aecd6e5c4423a06aaa326cce
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CE8274B6E0E5F95FBC6D158352CE490E9AB08BAF
binary
MD5: dcc52a5c4eb3f4dac70879dd98fe3162
SHA256: 0be3ec7b2f664bd6495eb879964b52c2c9ff833350977bc1d6b4532cdf820161
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\35A1CEADC0B87F255DA0D408BAF6A65969CBC23B
image
MD5: 94dfda80b839fbab8dba4b2000aab7e3
SHA256: 3ea3de87edd225d8b74acc4398372d259286015708e900f7d47a2dc03fa83691
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\2429
binary
MD5: e277407252a8b0905900716aee55fddd
SHA256: 04ccdfac66178043a2980cfdde89c5dd380e3afee2ba9f2025096a34075017c3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\0fb432cb10ed984b5499787ab73fd94a.png
image
MD5: e5833d7b58f443c62f8449502ad53ebd
SHA256: 606087157cce3c4a9921aaa27ef4f837bf4d8f0d243bc689377d91643fec539b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6F01DB187BB0A0EBF0784711B75FA53A766E1DE6
compressed
MD5: 5570c3eedb738f7a259d1167f7bcfc18
SHA256: 5e82f076d0b4598121489087166a778c7470884047b1cb8adfdf1a8d71ea29d8
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\0fb432cb10ed984b5499787ab73fd94a.png.tmp
––
MD5:  ––
SHA256:  ––
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5C919D9ED0875828E8C65BD3C8E3C5629028C952
binary
MD5: f0a30d90717709eef9ad7cfcce889376
SHA256: cd4c5d5bdf5cd600f30713a759ce25760b1033c54b67da836b6d675c77b8f195
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\14EC8782C049F20B1F4FB7FD675D2C377DB87B2B
binary
MD5: 3da106e502894a7b9c9a299912bc549d
SHA256: 6969189a2f84adfe5e88a24c56b914e53553532581f7cff2c149a4feae3894ef
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2B662789DFDD9C1308FF8ECD48E05F393053163C
binary
MD5: 55b9c81c4ec1d2db6741b21cf6929b88
SHA256: da9df2cf7f7f80cee2a81c69fb03877e459729d35f2b58f9945b7be7ee8911de
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2F8FF16216AA69DE29B0BE467C4B59894D7EE46B
binary
MD5: 2d61366a9cd652ddcb7e4cc325d38d09
SHA256: b24f7bad9dbbaffac8d80e19eff0cc47d64f4a40b845ccb6ae2d16d83bc794f8
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4FE50C33916B0BF0CFA64E49D3334936F763F516
binary
MD5: d49ec9050134447cfbd8397ce5ee0156
SHA256: b1b0a6ac61a932b17f2e246e6c35353ef3d6ca7a1515a497032a877228b82b23
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\76BC6ABF0265355E9F24C8453EC3CC0ADA8FDB28
binary
MD5: 0ac9c6d91fc18af2a6d8f4e5ff62bd2a
SHA256: dc52733767a9f8cc2080a93b85e796224ad75b62510d8af87df4f0cea91e01f4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\70786734730069E153F4BB21369830C8D9CCC767
binary
MD5: 27e34b3219656d1c2e5737f4989ca68b
SHA256: 6a3c2eef9318028d3e3595b962e7bf0bdeb27a347a28a34f6a76948f9fd58ffa
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8CFDA4498C8DAFC261C8FA7E048CFDCE384918DE
binary
MD5: 312e13efeed32b247bff1ab89a204413
SHA256: 70e40d92d2cdae6355dd91cd19e637a7cc40b8f45c0ea6b20c5b90688e7b6d97
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FEC0C30B589AC1069C99451D748C50F6E2C16874
binary
MD5: e277407252a8b0905900716aee55fddd
SHA256: 04ccdfac66178043a2980cfdde89c5dd380e3afee2ba9f2025096a34075017c3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\483363865760C978E87FE52F265F9B70511B5FE3
binary
MD5: dced16b7c6e7e89a32f871d6d88450df
SHA256: 264414420bc2b4ae0eb1ec483446fb6a734e397f2b4a0d50b413992d362c4fc8
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\28038B4B7FDCF4ABDDAB7F1316ACDF1D9C82CF64
binary
MD5: d8bbbf4dfdb28b49e70742fd3aea49c6
SHA256: 7ab8820836fad4ba29b9b6a7b6d2691892116987be0ba5818f22d7877b399d49
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1715FFAB25D55B6092AD4844FC67D0C3DA7E81B3
binary
MD5: 0fcae64a5e983bd0df022c29c0bc08c5
SHA256: 834b349ab36d2982a07fc200cbee95fc4f41a1180d7b18a6781ebef68e4846cf
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CD1E4C290A0CA6049439333351AA549E2F8C53E1
binary
MD5: 97452e0ad1c2a4bfb99fc145b4b27fb8
SHA256: 7c22137e5f13a0d944f830c791a10e7de3d5cade560de57eb647c90d21236b65
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\AC8F071F56237863E7EA706BE6252ADD439DF110
binary
MD5: b7be684d63158dc83f8be9549cd68ac0
SHA256: 7caacef8dd7494623923acb7935448dea6433248127e7b89a0b82a9b1582a11a
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\68E99CE94503BB1588A93AA88FB246C4033C24DD
binary
MD5: d134015acdf0358b77863f1b1555dddd
SHA256: a0d00d00ec16b4a38c99839567a118c599817c2eb8f7a978e14a8b8f881a71f7
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3A0B5DB873FF6FB94853CA97448BFCF17B6038B1
binary
MD5: 873ff9d9decc3786a14cd707babd6377
SHA256: bdd3862b840243764b616cb8e134e532cdd53bc988a3585006db76515ffec522
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5D0C075C4A2D5BA3A2C8548CED21C2318349527C
binary
MD5: 028b8f8cda0a0e4a68bcf12a13ac2a43
SHA256: 971763e45039e9b1c021ccec1800c8f3d676a962e0b0a3517deb59898392c667
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\182ABB341D7E259AB2DE4AB1F7E3120BEA27F382
binary
MD5: c197e952934c166e67dc1d2a84a43b66
SHA256: a3be42e4fc530a3e014730782b5611b62ecf5532dc2c82a00a1ede4e46927f4f
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FE3209B6EC477B730FE8EE7AF24892F0285780BC
binary
MD5: bd09a17da3e93ebbfac41f8dba205a9b
SHA256: b4fb25db204574f7399fdd6d0b2ca40bab17cc95678cb37b4f8b04b765bb7858
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\37C5621C6C91F132AFCF0929E276CDF27E7882DC
binary
MD5: f07d404fb2b9ff18c888678a20e1671b
SHA256: 37ff05c065808faf6d2a22b4770c7ed825e9dec5a848bcfba60e98199719d147
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4E0AE899E04EC13B2092B88AD571E6A97ADF73E2
binary
MD5: 6b5d9f5053525895091da9998083acb6
SHA256: 3639db2ffb788a7e508ebee058a39a6aaa73f6b52d38f02effb1cd804e9da906
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B7EBA5D1A68A0E32322D14CCB74F9D2D7E7BEFB6
compressed
MD5: 8e277d2176b7e94a600dee590bd2e238
SHA256: f2417dd3ada1c2d301a5ab5d01590295a2b5590de01119ed2916c55ea1109810
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\42E2152156D7FA1E5877E2A6E0BF2DB5F9AA2B8C
compressed
MD5: 3584eaafd7b04d7b4d02f1df29cdbfe7
SHA256: 19c12e2be1b3e8bf1276185a68350c5d41447cdc712014886bbf997152c56951
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\979A6C197D134DE6B409C1B43A98F4C0E616DE7B
compressed
MD5: 439d10dbcac6edda8f9bb9977176c27c
SHA256: 17df3225f97e8831961af6ac467f2992ba60f16f1d5a217a75ea19fb98bc0ede
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9495D63ECA56A7257629D6CA4B49A6626FF1B766
compressed
MD5: 118588f4df897c353e9535f62b152664
SHA256: 7535baeb4615e68d89eac13e43587d684c4ba1b520d70a0300863d7c96e7158a
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8AAC4BC401CCACF157544B85C9656A17A3AE5426
compressed
MD5: f1f78dc36ac4db982e4bbcf7a63337d9
SHA256: a1944b5eb129ca662a0843c8269109ad706c8a6eba30a626f0151be1ec07190c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6DF9AE463ADE1E229FBE250BA7FF323BB13DABBB
compressed
MD5: 7c33dc2b18171bb9e08b4038c62f39e4
SHA256: ad89eb58ff338fce0b60b4cf596f02f9b49fd713a561ee789437d45527eeb20b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6F01DB187BB0A0EBF0784711B75FA53A766E1DE6
compressed
MD5: 9f024a135606ce901006ef03947b159c
SHA256: f11b64879488e6ea9c6c2684f31defc1edec3249efab277e391d4d60f75fe570
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B56240A8AADB2ECF6A1F681128DE02F07E07AE1C
image
MD5: 09cfdc73bd91d0722f0f3dbc1907d794
SHA256: 8d9144e575497997fb43f773c052959e56337b4d5c60afb512443e61f4823e83
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8D193BF7B6B66A84C82265D425305F41CE1B78A0
image
MD5: e034b3001a1c633978b0d24376ddcbaf
SHA256: 65189f64a23c2162bb6857ec682bcc21c50001a1ad28075d18a040af14780de5
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B2B0837EE7960D063F06DA833799FA6DAB4ABF1D
image
MD5: 8b97e1a70e3f295527b2b950eeb64bc5
SHA256: ba6256eba2da6edeae80317728347b1053eb7e59cb75c3d259c1c0e285ccd8cb
3016
firefox.exe
C:\Users\admin\AppData\Local\Temp\superscan4.zip:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4454F8BB294085C0C182E395FAD8CB93379AB1CE
binary
MD5: efa808a51559d89e06936326cc868741
SHA256: 23df073eb2f26e965a681bbe9585b83284e42b07c9c218842be48a04344a3abd
3016
firefox.exe
C:\Users\admin\AppData\Local\Temp\superscan4.zip
compressed
MD5: 13a6483c0dd73ef8847ee0142ac5c99e
SHA256: dc01f0835207ad7264284e20b0c02048f8705c813c2c8d7071ed2f653d0209aa
3016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 050ab92dfb7e6c4afaad3cc1459601ed
SHA256: 4bc1376c7759a98987f743cca2a5fec4ecabe307ca53eaee61139c5259207c64
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D5E41702A941BD66DC0EBE026E743036FDBC47F7
der
MD5: d507040493010a08b8a254dd437d79ee
SHA256: 4d68b7fb6df0d823e7d8837c405f1d95c58cc0d9ace2ac65080ad729aec883d7
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\28ADA6D32FFF18F717A7F41B5ACA0CC9BCF4B16F
binary
MD5: e8dc59fb9ec936760bbc3324b828c06c
SHA256: d2d4c5424fe17775f64e499d97823707d33402b30be086ab6889b1667205da88
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\230547032599D406372AB74F6DD3219738ECBA7B
compressed
MD5: 969a4a04c3ac4586dcaa1dfde40f45ff
SHA256: 9cff5f6345b9284072a84edbb6548143e94969c493264fe4bb18bd4ba26b59ce
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9495D63ECA56A7257629D6CA4B49A6626FF1B766
compressed
MD5: 40438f9dabb1630f3e4e73772e2dcd7c
SHA256: ce2dc650466636001fade74262a57a829ef21d4769cab294529be13f2fc30d70
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F1BFC05054FDD8DCE77D8559803DFC878D0BE9D7
image
MD5: 82af98258371c33ddf965017880ddf64
SHA256: 1972b99731d033523bf49715c780fca6cb10778ff74a57ea98704298cd3f85d2
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\91A34DFB6B59A5A99199215198C8607C7AC2ADC5
compressed
MD5: 39baedc2ab1a2af3d0d407b1a458cdea
SHA256: abcd4220a7e4f9da72c002dcb244fe604be2314e370a536c3d5ad3d1a7cbbc5a
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EDAA5F2C062D86A9E2DDDFD351826AE9F6010652
image
MD5: 92f1dfdcc2ba75ece570daae387ab003
SHA256: e7548d450b8a1fdfe146470548cbf7a8119bc2205caf730d709ea66b5e5eb474
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1FE22ADBE7EF269383DCBAAA7CF219F322B2EB9E
image
MD5: 36d6f6eaeabfe4ecea69c6f4d0f427f7
SHA256: 68724cd75d61d28d6428e912985f5b4ece73baf418c826b58468a9b72be67c98
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B054D0D181DB2B4CA2F4FF258945F04E42A68CD7
image
MD5: 6eeb806fe2a8d66bb53d76eef32a5076
SHA256: 3937403ebb48a0401a37516289eef313ff33b04b41b59ef2992e9796e3c14eb3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E943808114935A5CDBA71A42B74154A7B6BCC5EC
binary
MD5: a591c014260c0e7b4de385c48a47f364
SHA256: 2fc1b2faacc28584f98d573c7e4230dd336608fc142fcdc9ee49f552398c9b14
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6EBFFFD195FBF74E64BB84D414248758B071259C
image
MD5: 00fd1cb79868890553683b474046ba9c
SHA256: 45a372a3dc7a4f765ff23cdbafa94b74b539e96e496548c19e9350257b230147
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\472B55F29C8E500779A3EC72A22CFD8EEB1B8D94
binary
MD5: 17ea2c70f7626cea3a98ce6f23341eb5
SHA256: 1a9b2b539fcfb61f6b54143a68a387fa6f201641b497195c59c6f74098b470a4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DCE75CA807EB92CD77D11305890F8CC72C9006E1
compressed
MD5: 74cef42beeab1efbbc149f797a5b16aa
SHA256: d3f93e1ac5117dc6db6e0af5fdb30753274c40db76442145f38738fc26988cb4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A28866236C1A7824A2960BF94CD84ED71F0979FF
m4v
MD5: 68f6ee3ea200709ee5f799a63da54a83
SHA256: 7dc57feb69d02d9aa532761c975548eb63f6985612a13faed4ec00a6fbf0ac80
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\32FD3D5878A52DE93A1B5662D261895085F14811
compressed
MD5: 7a9121396e80332fd917f20e52886a02
SHA256: 50fe416fa121564fed084d784abd2022e6ae372bf0f27da651b6d9982d0831c3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F405257B45985D459DC5A725ED9B4F4F856B1ADD
compressed
MD5: d0df22d190df8443e43ba081eb1e1678
SHA256: e607f1d5e0bcd62289b59953f7a45cd3d85826558f91c9dec628081ef62f4e46
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6A9CE54A9ABBCD4AD60111E887409BC210047FCD
der
MD5: 2a6a9d94b248f63ce81400aceeb34599
SHA256: 0741f61675d6cfd966f6606d311a455fea0d57cbf212d15aa86cacf18918525d
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FFB908579D44441EC843BB0DD9465E6C19B6EFDA
der
MD5: 3beaec15f0906f2bd5d30f9e53d3c115
SHA256: 2d96f577d538fe4f5078e8482f697dce8a95773ab3a47a440220b4dba046ee1b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2FB93A49EC8E354F5FAFBFA9D755658341844B30
image
MD5: 8319dfd41ceb57833a4f81f7f19372b5
SHA256: 86d6e2e54310badb78a7cadda9d94266a77744cbe9a40d1946c891bcee61d4ce
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FCBA22629690D2B3342AE400047A80CCFE06FD8F
binary
MD5: 88878af33a9276c076a1fae4452cabb6
SHA256: 69753a3a00998bb97d30a35ce22426bdb3314233d23eac4efaa81f15f2caefe1
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\089F502C13A158385407E3D23DFE40EE3FB57B14
image
MD5: 140364d719c9313f580020b0b965e523
SHA256: abf14e46d24727bf76a7a2762638986708b7106a99c47dc0a31f3eebb5a765af
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0F3495F234A31F8953DBADF1760D38AF03E3A321
der
MD5: 245b37ad5e38d3d69bc52900a71f4b1a
SHA256: f51f2afa1cbe8268fa7c1c6598acc647c5ca9f3cc07cd6be1395548e70feeece
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\986170C51FEB3B42EB6302FC146BFB255B56F051
image
MD5: a30ec3ef77c1ac821028a2dbc89201cf
SHA256: 536600b1a1c74c2e0c44d9254b00a3f45211af71dc80334fa3b6f3084b6d4b4f
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\934A4820A15F65F58B329B11175536146437037C
der
MD5: 018748f71f8643c2b57a3e950bad22df
SHA256: 895d0be72731ae2b0bdfeca42901a22c1de79836086263afce4b5abc93ce8e64
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6EC78A970BC4B96C5103DAC92EF6700BD6ABB80C
der
MD5: cbd492bf6b5934912407dbb60a46204c
SHA256: e0da16c53f562963bdf52dfb91ca636bf625edff9cf71f93747ee60a93fbc45c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CA5B18746D5547C8FF70D9937B4D10617ED96C36
image
MD5: 49cb52779012e77bb88f89124d472710
SHA256: db72ab84e489d74d5c5e95d335d49dc5d2efb662c774266b100e4c5b67328d77
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\10821CB4BFD4AC55854D522069FDF54ED115B1EE
binary
MD5: 23cc9679bc3883dddf86d0bc5df04d48
SHA256: 4b4b5f7386a5e4610cc439fe7c690154603a7f3241327e98b1a0b60a1cedc3eb
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5AAFCEED33E188F2121D495A2B31A7BE49F28A82
compressed
MD5: 234df7dc3aaeffb05c2395d0cb417cc9
SHA256: 20743252662e52ae61785ca65edda362cbc5976bb0d69c6ee4f668ef30bccbf4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D3A05FED7D47841B6BC4943BB567E3B0165C4D75
binary
MD5: 766bff46f83e5a6273dbbcc60f401dc3
SHA256: 9206f0707fb5f73208767a4340cc5d8d9089366e44a11a146cce30faddae2ded
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F59E28C8786734595CFCDA56DD9F7642F9E3987B
binary
MD5: 3a73e6b2995951047600a7d76e129960
SHA256: 8a1c45385771aabc257f2366ae078721a6c0d137f53a8fc8f15fd914b9c1586c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\42E2152156D7FA1E5877E2A6E0BF2DB5F9AA2B8C
compressed
MD5: 0075062196b7156de7969b3f31336204
SHA256: babff1a6f1cfabbbba482f3bf8c428a7bdfab69e38252c59e91eff936864e3f5
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B7EBA5D1A68A0E32322D14CCB74F9D2D7E7BEFB6
compressed
MD5: 21aa50b973bfe9ed27659bdec41c6775
SHA256: 8a9972a98bc04e96f1bab296202be417af863acd0019d5990e388be99cbcb73b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E769866B60C96C0E6445B55A4334ED5F7BFFE176
binary
MD5: 63cb0e75838701612e1e40f7169ba44b
SHA256: c0f8801f50a026587c037056e239b1af4a1f83b9cc24b5cda4ee9547aa403f64
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BA1462243BE977C5896549568E9D746FA240508F
binary
MD5: 15a18f7c07ede897a4cfbdcff23e4fad
SHA256: 2cecd801df73588c11fa57ac392517395fa93e0c504d56379de816eff9b82f81
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FF107320D15E05098B59C991D16847F6F5D9D94B
der
MD5: c95cb4dd81d7242683c8e74948802838
SHA256: 162e6f1540b40a33982fe26870a10409282228b606a9730b79ccb146ff8bbb65
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B2D629C3B5818EF36636EC1CDF2793961801EAC8
der
MD5: 613873acd61b30ac479745c274613dae
SHA256: f40e8dc1b1cc35fef50ebccbc075de830ff9099d0f7d3c347a74b0e9cef0d708
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4C065100BD94589F57CDF2B384E52BE0A8179C4C
der
MD5: 65ebaa649ef06ce5aff1e7671812b780
SHA256: 089f0214f4d2ff4139d250634456099c7244e702303ab764993e89725111ba82
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\15547CF8668AA3AF318CD4AC5A79C70EA4F0CA6A
der
MD5: 10872334adaeb0d4cce50b6f38a4d4e7
SHA256: 6891c54378f8e0bb38154b3480a94b0d3ae174e15e62b675ef24cd3c9774671e
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\ADCDAE847B8E1E4E87AB34DF01357DD2FEC6ECA2
der
MD5: ae946dcf5609725225fe27bb4a7417a2
SHA256: 0f095e59b4f6db54041e2a87f7321245f1804c83f0c8a579585eaa8b2ba81445
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8AAC4BC401CCACF157544B85C9656A17A3AE5426
compressed
MD5: 2eefddb36788168f0d4b6605795e1e09
SHA256: db73c1541ac228a3f47e4ec6f10e0202c2af888418941fd894a29376ff6c0d37
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0488309A3942812C3506AB4AED9E77A7DC9BA19A
image
MD5: 0f0bff4a61c13f0a499829159489f6c2
SHA256: 09fed896c7c1db95b67a11e7117a94ce1c384a45eaeddb00ac3c6f74cc5f24af
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\23EF5BCD20BD3D4A7CB6306E44CB8010A22669E7
binary
MD5: cb8931e2e9e5322f463f0d0915624786
SHA256: 8bc235163de94c6d556403583a50b79b1d814743d81201d9de7d0afdd5df0a19
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5E8B5D4DC9CC1A04D31FA3E92052F009CB17B700
compressed
MD5: 2ee241de673a6f6a7820f68404209ce1
SHA256: 62d3d073302535fa3376f50fcd002495cb69bd88a9819d6ef93e7099dec0e27c
3016
firefox.exe
C:\Users\admin\AppData\Local\Temp\fJtFBPmB.zip.part
compressed
MD5: 13a6483c0dd73ef8847ee0142ac5c99e
SHA256: dc01f0835207ad7264284e20b0c02048f8705c813c2c8d7071ed2f653d0209aa
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8FCBDC92BBA8824597F701082C235C03E1956137
compressed
MD5: 7e548dd19abfa0f6f9fcfb965088fc9d
SHA256: 7920ab03719dcf5236ea4c04fb67fba1d10ad7345866e6c806da3f83ba736721
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FBCC29EBCB7B1EBB97D41840FFB2B0BF0EF4DADD
der
MD5: 635926f99a4a7176af1accb586db3f21
SHA256: 4e465311d9ec271e54d39868642b3db82fa0148833b5339b30750a792d7ef87d
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\92322055A96579FBE396EBE851F3352F4A8DD6C8
compressed
MD5: 02e4c86c3ef8ff55eeff973004c2c96c
SHA256: b11617e22224a934e0566014ea545fb4b08a3047192bfc1f1b28c70c13c4e3b7
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4F07C939C797827EAFE4F0A4A49B677E8D0A7D11
woff2
MD5: c20528dfa8c73c4ce3962de50a3e892c
SHA256: d7ed8d55402314a03c4d20892a528b609fec060161363dd51ddf8e29705359d3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\89DF6D7B4B34EA34F5F61BE9DA927E67A166E471
compressed
MD5: 125273f47132e96739fd4bda81303bef
SHA256: 1b1743b3579bc7ee7b54024173bbeb7d5b5f8d29e39d1b90adfca31d22090b0a
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B6824EDE5D689AC6920FF8AA8C4846DF7EC3591D
binary
MD5: a5cae29b30f35599255c9387c83d325d
SHA256: 7462e1214b11bb35d977b3f888b4700c8ac135b5adab9359db9d9fcffcfd7979
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\AD91236387A840D39570DBA795E90CF62BABD27F
binary
MD5: ee9c1f1c33c330eac956d10f3746a7c5
SHA256: 8724c2defa50178e9a28e18cf6ce4e4de243a92b624dfffa27684de731a83751
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\936773263E81749D70B1D6D535048BAE2DBDD7A4
binary
MD5: 1dbc9e7d72afba29d7db66df89a38574
SHA256: b50dddfb2408579ac75cadbfe120739ce53437bb022cc04328c97257f011dfb1
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\536299A596640D9CDDC93BA083DDD92F47340CCB
binary
MD5: b5a1c4f14ee61f0afa8273ec7cca9800
SHA256: 288de9a770b59ac5e919229e5c9e441871fb427a571c80c8d81dbc9df925d455
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BDAAF34F94F77FA1D76B677B95B5F9BEE8924E8A
binary
MD5: 30595d12d4c2bb8f54e40d3f1666d1cd
SHA256: 864da3f3d68e36ba68b0c622e1ee27179e7e5a946d59b576982f01d13649b911
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\20D28E7B28370DE82126CB29EF27F2B7D663E6F7
binary
MD5: 457bc9e12d89907652198998f227b5e1
SHA256: bce9cc03ea4f481e2dae2454601a7603cef7baa1349809d634ec8665d4d9fc5c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EC77E2BBC3975B1E1B917BF1A82669D66111D3CD
binary
MD5: 28795aef9bcf208a0d71287686bf49bc
SHA256: e881e3816e5327a1b3b2fbd587b99cae163f574535e3d6684c7b929b1601b59b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C34ADCD5A4A77E374B6240073AE72DF669E87AE7
binary
MD5: 0f48aacbe08fee505fe62b540a5df56b
SHA256: 6ca3e52c8f391deaf28b0518ee73c1a5fb249b6501e8c9f8654481a29b831bf2
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1D4E3B3D2B71B3A392867437AC68540B597A8828
binary
MD5: c2001d2890b5557864e2b573f793f5d9
SHA256: 27305c38599e0e0cacc8432255e38add02ae3fa84a7da5ab1a6e095118f0a046
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CCE0C15937141FB437CFD2189834543649981B07
binary
MD5: 8cbc1a4f3d71c97d30bb1cf7a38ed8bb
SHA256: 96aa7e354d0915dd22da3d75b131e797bf65dcde571ef36feeaddd76ce94c0f9
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4E0AE899E04EC13B2092B88AD571E6A97ADF73E2
binary
MD5: 1bc160f155653ff20c2463819a77bc6a
SHA256: 53e3c68abc9e020cad8c6ff1de5ceee9858c08e43a11acc96ea4b8b30379aedf
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\899EEC8E5E97545628A1C8963DDD6417C6612F6E
binary
MD5: 5d052100877ef145d84cc9a9aa0b5f16
SHA256: 35b9df85815801e6f16070e8569e108186ec8c2e78aeb536dcce26898e872c9a
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F1C5D82456B0308C3B3C392D1433DA4599A64A61
binary
MD5: e0b3f90b8a67cceba3a17002e854dd4b
SHA256: 8509b26ec1e6db2d51e0d9eaa6e272770666aadc6f8db88d45c5dd45d6fddd79
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8EEF12EBEE7977EBAE328A9F312AFDFA12DD2535
binary
MD5: 8d9242cc11a24607f1d1a81ecc26693c
SHA256: 5bce07165a3d3d49d727c52317609185af03a3cfb5e7f634a996d2293d98e77d
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E1DEF9CC402E2C7BD9964F44859E2240FF995C7E
binary
MD5: 9498845cfc8735fc865a40f9a3a481bf
SHA256: f72417da3f66c2767543dc342e80cb4f6cb28bac8a38ee77890b0a9910902c6b
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0FACB5AAF3A6E0E73F3147C61521708E39193935
binary
MD5: 25ea0d46e9657d5731e70ae262146fae
SHA256: b97dfe36bedb14deeb6fb8b53de24757f8b58149941c0dc1b98d6b5d57f0bab3
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DFB8D623CE7C2DD67354D8580044C2836F40D8E5
binary
MD5: 3725edf4132eac3585fa1481fca66f71
SHA256: 4d758cd1876bc4dbe865b350fef131032e5c72a375ccaf1c8cfe20c103e764b7
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4D5794CB6A3C6653CB422ABF74B7FC5446F3258E
binary
MD5: b114d63f5cd8221026e3f2a5253f3e29
SHA256: 424de445504bcf901a9d5762f980567917884e41714cbc59b7a896f068860268
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F9CC340A5FF4B90D4A5CA61DAE8754CB8F77FF0C
binary
MD5: a59a28c4d2bd29f0c134e746b2bdd5b6
SHA256: d6285e76ad6542954a6ddf55d2e7caf95a845c08c56b04136e68ba566f3693fd
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7EBACA0DCFB0ECC9E2E3D42F589F58F0FD5C1521
binary
MD5: fb06dc562748f6466d7cd29f863e2c53
SHA256: d690a69b204dcd08cd509a404a90b0792d8311215958bdde50b4d85015113343
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EEF2A383A74D886882954D4DDBDA742C1CD31660
binary
MD5: ec052a55fe2dc7dd15f06ae8469a6144
SHA256: c40e477c86b7025b71c3e208e152b884c440ab4200b1cccfa007846cf8be9cb0
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\233E90839C409587F897EB582B77883C210F953D
binary
MD5: 301caca7a8a25144b11e8f1585289a4e
SHA256: 804a4fe2121eeedc4adf64e9a5132034d10d2e33a94bdf474f6b50637c55d132
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\31D204BEBA84962F546658CB3DA9235394BF6760
binary
MD5: ebfdb1a0eefc22fd7bce6f3f4e700cd0
SHA256: 2fead6963b4a0f3ff9d9b14de1633a956c81ba627ff334546f1d60e967fb8466
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\95F623B1B3AE0942FDEA03137029C44637F06ECC
binary
MD5: 956feea9d40674bf82877e0457179863
SHA256: ee1cb0115b142b70e51e73a2108a58592abb0ab7005fea1c235f43a3722029c9
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5D0C075C4A2D5BA3A2C8548CED21C2318349527C
binary
MD5: b064e8b5d5fb72bf1b7433785ba090a1
SHA256: cb71f84061c4eb0c7988dba4f3709d4f322e1da9558266c99b8ea603d0196d9f
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A42193A4E9E7D16BF0F66789C9CB82564DF92E43
binary
MD5: e87d427edd2fb744321e9cc1b6213158
SHA256: 04df5bce7776bacf278bd2747ccb101d57dc9df49490d473e81c12cb5c437074
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2B662789DFDD9C1308FF8ECD48E05F393053163C
binary
MD5: fef2f0d0781a7ee4f352b273b6c47fe4
SHA256: 4cd29d6ed277cbab95d5b90839a05f756a424942298e6428983438eff8840ab2
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6146830B201A8219454EBF9F8E939EA94D80FF37
binary
MD5: bcf790486c782fad960bb2a397b9233c
SHA256: d2a2b08ae9d42949e0d80213b02c6f664bf23feff6e59309b542c31f0b4e231c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3A0B5DB873FF6FB94853CA97448BFCF17B6038B1
binary
MD5: 9c24498c294c8621cfc21e33bdec8fc0
SHA256: 90cbae2d0edd72613306bb63445c9e3fd72127ee9f30ec2d0c5144c4ce3b272c
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\536FAB743CEF56D3C13DDF0B333B3F4069E39806
binary
MD5: 0a8937268cb0746c583a187335f783cc
SHA256: 0ecdc1c87952a5c8538f08aaad81ee37383cfae29279e13c7c0a23664e315a75
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4B24F20B3CD547DC4E9806B87070E5C62DE7D438
binary
MD5: 08b3926db6f812b07fbb13ef66ea25d8
SHA256: cfdb52962a32fccc51da25e3e47c2b899eb9864d65bdc65ac5b93eb10772b5f4
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\702580992FE051D5803D2C306C5137C71D25E699
binary
MD5: 0cbbc53ed9c0069123b409dd75b0e14e
SHA256: 6087baacce4a6b1a292d7fe19a89e9713403ce6fbdffed1ca1f3cd2345dab376
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\112860286931F5CDD42E1CF94773FAE85A66F7DC
binary
MD5: a33e7f047550d5072ac978ac35a4e51e
SHA256: 3420dd58fade1bf943e88219e96ea6c663180768553eb9d19b7c0e6cdc248bca
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2BE8EE9A8C4D1F5CAA3974D67090E36AB2C86E23
compressed
MD5: ad4506ffe6cd6667eda9ddeaa2aea7dd
SHA256: 36aa8400b3922c7d1d034ed1eb65ce972731cb6e3b81d628d73545f774244bc1
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\979A6C197D134DE6B409C1B43A98F4C0E616DE7B
compressed
MD5: 036819b6bf4241c720235ae4b4327d1e
SHA256: 493294b3e4c371d5c75fdadbb9185cf101768a9a75e314393804b4229042ac62
3016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9A2E9BFDC1225C97FA67BF22803B18904774B70B
compressed
MD5: 6b1e52fc218a1df9d9c6392d8d7419f2
SHA256: 9724c74b276368f823e1cfbcc5228f41470c9a08caf116c24eb86bd678b8b544
<