General Info

URL

http://iccke.mailer.in.net/user/23488636-43075-962ef7e7f031e86579d8b268bbf158d04ecb1fa8/follow/aHR0cDovL29zbG9kYXRpbmduZXR3b3JrLmNvbS9iaW5hcnkvbWVkaWE1MDAtY29tLWVtYWlsLw==:de01397cd56cefc0efca0b54713e2780?N5IeEF2YAZpNbErWr79xdJXau2v2pZ5bdtz6nI03653AJ7c55oKPQ6Tv63DbaPBOjG9kZoUv40xgd94Q1Tju1h98qD65hk2S8GB1Fej6h0aNw8u4bRYIUF9Dd6MzH8sbZdYG66mOtDUfoo5i79b45ozUYfH26AKExo7E6Y1w7Ki6JLHAU72QfNstH7TvVZTt7tI8Dc856Iri75bVu1tvHv9ocRZmeA22862IHL5S8tD81FE9R6XMwYWkF0KfWmXiATUomp9Fud32O7jNj5yD1P7d9n6B3l13kWXk7fA16uqAyYoDQ7MJ47p7Y1i2p9z2LykDxXgBGcp8wP7P3mELsoeu7dA2r8X3l0i0nDUczaj83e3Kx4RO7D0nP8HuS7w9Fyx1Z4pY4Rm1wmuWCi3H99Xfj1XXlhH81ma8wM9Q4duNflaKOV6Hok9VG77Q9ULAPVO0s17nQV63UP8H2Hh4C7sU2C488p4UnH75ANRsh508XvMh85QbO6j5cTov3Wq7teQBN9ITO4j2usYZYK3iZl37W0zaN0mc7yCv0Z5V5YEcf4FP35589orZE0x7Hl7q4xd9GLCM48Cdz6n0N1p6sKjmJNC9n445370y00In0C0223xqd438s9a00Xj58WR3gDFIU88p2xyYqRwG8dirrU891kL7Sw18BN89vh82vIQ5ufzEHA85e4vbH2A532q00H9Ft5PuKzof9Q1V7i9XrO4irF5D56A4M9q05uejBx328J6vH3js6Yg2O8IKN0Gi73Hn7yEFDSDe9Y0TCDcCi1e7TAtiLfip7Ql4R9fqYrEZjlAtBhN0HmLNp88QItRNWa97M2Sd5AS0V4lId5z957RhADA4eY2P9xpF7TPd2ef6R54B3TN8HfRpRozIJxwMeq462QTg8kzSGg21WNbCP5YEJp3Ec81OJUCqH9UBo6T1A34iSuc7lZTfZ270E7ATvaig3cUSbN6K9Uv7utm7KyA9Db57sVd2Z24h2QGdzMrDY07IFb774Gw2BTcNl8E3RtEpuSg7Jna2cvbHgUVF1e4N7lyrO7h7TRvp3Fir9u4bhakSo669R2uqAd1QOCcYi7JE00Jq577696IVWAzFjLz7skP9X3esi4nqX8V30H9X54IeIFXpBlpRo2venz1K25q3ixPQg3P59jz0boA07q0Ac0Ay35WL8WU6O8bfx3PYrJR46Rit669c8uZCEm4R082z4s4QCsoB85C4OubPLjZ43vequ7n6Ab5912I7R9IfXF4T4qFEX93CNw4zJ9Nrx1m3pkW24S0J2oGJo2ujfRfGNm30W2pZDH9jN4UV37Rbs74UNN6f5I3crxjfu8cme6QsHnVk920bBb63xuWwt9ddqc9ZY48cGrqrFJA3eesW4l290H4b91q0vI27iRpZ5vsqGxWf0Loakl2z69GXZk6GCOW2x59J62wH9V704f5WN4a257900R5u5oTDvaoCsi7HLhIv3y9g934Ai2vra5z622s3v92Oxk60ft3j5ER7AwK1qvh82g69C3wYipX5JBt80vY8Toi9rMS1Y7XgHD9H1sEkco335Ga6pt26RgH1XPsc3uV95nykDgnV6a9Yg0Yqjiyp5H2CLB5u6euaGUQG9ZUtzSQ7N4kOOlSTeCr7bapL9YA7Y6Jupkz8F49IsIEvHMDilk4L6fsvJ78AF91FXG3j28w8f6ilag82AxZMX7S1b9pUN0vD4a58wX8SB664FAK7m8r6cfrrl88U8nQC7nAXlLod00PcEuEG9R477ujlS6IJ65lkVmgapA2Kql2BYO0Mwt5PWrJ6Vbn6K76YTrSj5w7R53b94ty9cZ103ou0teA

Full analysis
https://app.any.run/tasks/ca74ffc4-8a21-4f38-9029-c5783d7ad69a
Verdict
Malicious activity
Analysis date
1/10/2019, 17:37:35
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • SearchProtocolHost.exe (PID: 1428)
Executable content was dropped or overwritten
  • firefox.exe (PID: 1008)
Reads CPU info
  • firefox.exe (PID: 3004)
  • firefox.exe (PID: 2232)
  • firefox.exe (PID: 2584)
  • firefox.exe (PID: 1464)
  • firefox.exe (PID: 1008)
  • firefox.exe (PID: 2488)
  • firefox.exe (PID: 4048)
  • firefox.exe (PID: 3348)
  • firefox.exe (PID: 2888)
  • firefox.exe (PID: 3800)
Application launched itself
  • firefox.exe (PID: 1008)
  • firefox.exe (PID: 2888)
Creates files in the user directory
  • firefox.exe (PID: 2888)
  • firefox.exe (PID: 1008)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
45
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start firefox.exe firefox.exe firefox.exe firefox.exe pingsender.exe firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe searchprotocolhost.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2888
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" http://iccke.mailer.in.net/user/23488636-43075-962ef7e7f031e86579d8b268bbf158d04ecb1fa8/follow/aHR0cDovL29zbG9kYXRpbmduZXR3b3JrLmNvbS9iaW5hcnkvbWVkaWE1MDAtY29tLWVtYWlsLw==:de01397cd56cefc0efca0b54713e2780?N5IeEF2YAZpNbErWr79xdJXau2v2pZ5bdtz6nI03653AJ7c55oKPQ6Tv63DbaPBOjG9kZoUv40xgd94Q1Tju1h98qD65hk2S8GB1Fej6h0aNw8u4bRYIUF9Dd6MzH8sbZdYG66mOtDUfoo5i79b45ozUYfH26AKExo7E6Y1w7Ki6JLHAU72QfNstH7TvVZTt7tI8Dc856Iri75bVu1tvHv9ocRZmeA22862IHL5S8tD81FE9R6XMwYWkF0KfWmXiATUomp9Fud32O7jNj5yD1P7d9n6B3l13kWXk7fA16uqAyYoDQ7MJ47p7Y1i2p9z2LykDxXgBGcp8wP7P3mELsoeu7dA2r8X3l0i0nDUczaj83e3Kx4RO7D0nP8HuS7w9Fyx1Z4pY4Rm1wmuWCi3H99Xfj1XXlhH81ma8wM9Q4duNflaKOV6Hok9VG77Q9ULAPVO0s17nQV63UP8H2Hh4C7sU2C488p4UnH75ANRsh508XvMh85QbO6j5cTov3Wq7teQBN9ITO4j2usYZYK3iZl37W0zaN0mc7yCv0Z5V5YEcf4FP35589orZE0x7Hl7q4xd9GLCM48Cdz6n0N1p6sKjmJNC9n445370y00In0C0223xqd438s9a00Xj58WR3gDFIU88p2xyYqRwG8dirrU891kL7Sw18BN89vh82vIQ5ufzEHA85e4vbH2A532q00H9Ft5PuKzof9Q1V7i9XrO4irF5D56A4M9q05uejBx328J6vH3js6Yg2O8IKN0Gi73Hn7yEFDSDe9Y0TCDcCi1e7TAtiLfip7Ql4R9fqYrEZjlAtBhN0HmLNp88QItRNWa97M2Sd5AS0V4lId5z957RhADA4eY2P9xpF7TPd2ef6R54B3TN8HfRpRozIJxwMeq462QTg8kzSGg21WNbCP5YEJp3Ec81OJUCqH9UBo6T1A34iSuc7lZTfZ270E7ATvaig3cUSbN6K9Uv7utm7KyA9Db57sVd2Z24h2QGdzMrDY07IFb774Gw2BTcNl8E3RtEpuSg7Jna2cvbHgUVF1e4N7lyrO7h7TRvp3Fir9u4bhakSo669R2uqAd1QOCcYi7JE00Jq577696IVWAzFjLz7skP9X3esi4nqX8V30H9X54IeIFXpBlpRo2venz1K25q3ixPQg3P59jz0boA07q0Ac0Ay35WL8WU6O8bfx3PYrJR46Rit669c8uZCEm4R082z4s4QCsoB85C4OubPLjZ43vequ7n6Ab5912I7R9IfXF4T4qFEX93CNw4zJ9Nrx1m3pkW24S0J2oGJo2ujfRfGNm30W2pZDH9jN4UV37Rbs74UNN6f5I3crxjfu8cme6QsHnVk920bBb63xuWwt9ddqc9ZY48cGrqrFJA3eesW4l290H4b91q0vI27iRpZ5vsqGxWf0Loakl2z69GXZk6GCOW2x59J62wH9V704f5WN4a257900R5u5oTDvaoCsi7HLhIv3y9g934Ai2vra5z622s3v92Oxk60ft3j5ER7AwK1qvh82g69C3wYipX5JBt80vY8Toi9rMS1Y7XgHD9H1sEkco335Ga6pt26RgH1XPsc3uV95nykDgnV6a9Yg0Yqjiyp5H2CLB5u6euaGUQG9ZUtzSQ7N4kOOlSTeCr7bapL9YA7Y6Jupkz8F49IsIEvHMDilk4L6fsvJ78AF91FXG3j28w8f6ilag82AxZMX7S1b9pUN0vD4a58wX8SB664FAK7m8r6cfrrl88U8nQC7nAXlLod00PcEuEG9R477ujlS6IJ65lkVmgapA2Kql2BYO0Mwt5PWrJ6Vbn6K76YTrSj5w7R53b94ty9cZ103ou0teA
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wpc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\sspicli.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2adec.dll
c:\windows\system32\slc.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\pingsender.exe

PID
2488
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2888.0.371004064\669345918" -childID 1 -isForBrowser -prefsHandle 1440 -prefsLen 8310 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2888 "\\.\pipe\gecko-crash-server-pipe.2888" 1504 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msmpeg2adec.dll

PID
3348
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2888.6.255140475\265724514" -childID 2 -isForBrowser -prefsHandle 2304 -prefsLen 11442 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2888 "\\.\pipe\gecko-crash-server-pipe.2888" 2480 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
3800
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2888.12.756071981\869299423" -childID 3 -isForBrowser -prefsHandle 2968 -prefsLen 12017 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2888 "\\.\pipe\gecko-crash-server-pipe.2888" 2984 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

PID
2256
CMD
"C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/bfcbbbec-1be9-47ee-8ecb-b3c08876adb4/main/Firefox/61.0.2/release/20180807170231?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\bfcbbbec-1be9-47ee-8ecb-b3c08876adb4
Path
C:\Program Files\Mozilla Firefox\pingsender.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Foundation
Description
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\pingsender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
1008
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\macromed\flash\npswf32_26_0_0_131.dll
c:\program files\java\jre1.8.0_92\bin\dtplugin\npdeployjava1.dll
c:\program files\java\jre1.8.0_92\bin\plugin2\npjp2.dll
c:\progra~1\micros~1\office14\npspwrap.dll
c:\progra~1\micros~1\office14\npauthz.dll
c:\program files\google\update\1.3.33.17\npgoogleupdate3.dll
c:\program files\videolan\vlc\npvlc.dll
c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\progra~1\micros~1\office14\outlook.exe
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2adec.dll
c:\windows\system32\slc.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll

PID
1428
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
Path
C:\Windows\system32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\mssph.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\notepad.exe
c:\windows\system32\wshext.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.dll
c:\windows\system32\msxml3r.dll

PID
2584
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.0.792883147\135088669" -childID 1 -isForBrowser -prefsHandle 1448 -prefsLen 2358 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 1680 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
4048
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.6.955938277\524527550" -childID 2 -isForBrowser -prefsHandle 1472 -prefsLen 2403 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 1932 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
2232
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.12.796714045\116896165" -childID 3 -isForBrowser -prefsHandle 1632 -prefsLen 2403 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 1472 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
1464
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.18.529617218\1269350938" -childID 4 -isForBrowser -prefsHandle 2508 -prefsLen 3727 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 2520 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

PID
3004
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.24.1186852738\79532143" -childID 5 -isForBrowser -prefsHandle 3108 -prefsLen 8492 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 2600 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
61.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\hid.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

Registry activity

Total events
1106
Read events
1084
Write events
22
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2888
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2888
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2256
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2256
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2256
pingsender.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
1008
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1008
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1428
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
1428
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\system32\notepad.exe,-469
Text Document
1428
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\System32\wshext.dll,-4804
JScript Script File
1428
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\System32\msxml3r.dll,-1
XML Document

Files activity

Executable files
4
Suspicious files
204
Text files
131
Unknown types
151

Dropped files

PID
Process
Filename
Type
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll
executable
MD5: 0ff7bb9561a7934441d4e44c68c8dfd7
SHA256: 123ad18bb0d19cedb94c02a9e90fcc89ec39e3d1813595088c80924fd3b4659d
1008
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll
executable
MD5: 0ff7bb9561a7934441d4e44c68c8dfd7
SHA256: 123ad18bb0d19cedb94c02a9e90fcc89ec39e3d1813595088c80924fd3b4659d
1008
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.dll
executable
MD5: a2deba04f36b39c63d9079389fcd6b8a
SHA256: 5431279ab15d99b71360075d1f221fcb1ce7bd64ce1695050222ca9cf70b1587
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-gmpopenh264\1.7.1\gmpopenh264.dll
executable
MD5: a2deba04f36b39c63d9079389fcd6b8a
SHA256: 5431279ab15d99b71360075d1f221fcb1ce7bd64ce1695050222ca9cf70b1587
1008
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\pkcs11.txt
text
MD5: 7649bb6f105448170e7e447e66d8cc3d
SHA256: 687ac2de1316be0e875e2fbbf7dee4547fe0b4eff7987517d216534ef2bbc3c3
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\23CF1D80D9F78098E2D6C23C2B96002BB02086EA
der
MD5: 395138d8c8392e43e790d89a2f02ab39
SHA256: 2273f9fc2f37306b75af2724fa56ac824edf57b82ac2b3f7482b0bda4d7f0cf9
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\AE3B6285E847D8338B8D40AD5B0DF406513B0CEB
der
MD5: 9f37f9a9579d6f59d3f090d392e3eea2
SHA256: e8aab2ca90028461b31bd572b250eb917a988849d83278793811c0f4264df392
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\aborted-session-ping
text
MD5: 0ce32a4205109212b4d3f82083d7e1aa
SHA256: b9ed58f5ac10684885144470d84f47727ce19f2e85a1b23db678dfd21df8fe9a
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\aborted-session-ping.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\session-state.json
text
MD5: d6baf6be64e94cda36e625eab47a71b3
SHA256: 777e83c1ca0139014e8c59b8c18277e07c82be5fa29aa8fbe70d6b8d8cc6718e
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\session-state.json.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\CB29EDE1FD7262A61FFAB793A382D515CAC77D01
binary
MD5: cca140ba97a49e003d27d79761e2b7da
SHA256: cf4e6e204c0565a326a519ccf4f94ef2c4f7d7d4d98640587ce402daaf9cccbf
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\crashes\store.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 19b095e1acfe35fbe70d678bd136ef26
SHA256: 37944545e694a2b5cd4a6df95a68dfb1973640321937dfcaec479e6367b3fe1c
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
pi2
MD5: b1e59508c855ef1cbc7fb89f3a1a6d4d
SHA256: d05bab1e36c62ddce10dcd930d4dcf2095ba654e0747b8a0609a7418aa1c5d26
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-wal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
obj
MD5: 82122a5f7794f29a393fa67307940514
SHA256: ef691278374fa5a25b1b0049a8473683a8c7309280ea838ecbeb736ca873c687
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\manifest.json
text
MD5: 5c15c32fcf4ac1a5d5c9c7a6b092ece0
SHA256: da88859b0fbf2ae545fe4ecacf709ffe348738b377ad341d727a8915fdbcf9d7
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\manifest.json.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Temp\tmpaddon-85e7d0
compressed
MD5: 03972b0e546f3402dcc4378d0d3a4f09
SHA256: caeba4788350bf038c4495b3e9609287390e50e2803524f40014e19237cb9635
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\D4352F6C8FDF3145E8DEB81A79F7D990E18BE0B4
compressed
MD5: a60c7cd82831775ec523febaea573f9d
SHA256: a5e360be927175e5b0761e03b65543d30a5b3f6490ac85f5fd9811068940625c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\1957E6D77010264C42A926426A908792F0F31FC6
der
MD5: 5c04bccc25bf33fd256b60a087a607e8
SHA256: 6fd0dd41104777c1d8dce93c09c36b7370f4f53a94005f384210dda62b128287
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\40294E49E5BADC82ED277C6AC709458BB6880A41
der
MD5: debbb8b658f9c5c03b4a0ef6983c427b
SHA256: 73a414696b95d0f5bbeeebed02b5c7b7963ff35ae294d0f07bc3b5d077d8dfd9
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 1631e1506ba24f6a80dd427ef67a67e5
SHA256: e48cb2d6f24da9b284c13498b60c06e9b15164b71a7a2c66ddc97f2f30a8ca95
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-gmpopenh264\1.7.1\gmpopenh264.info
text
MD5: 18dcab996bc5fde1b1699c4b5c115e29
SHA256: 4e350386f5eeb397e2f0b663103edd5321b4144f78a6df15150888386e2256da
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: c0af0811a3b4b559559787dc053101c6
SHA256: dbced0086253fb9446f9f2cfedc209087632f79958db9209b83793fd6d5f27c3
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-gmpopenh264\1.7.1\gmpopenh264.info.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\gmp-gmpopenh264\1.7.1\gmpopenh264.dll.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Temp\tmpaddon
compressed
MD5: ebfa9973cf862a250c21536b634e6e62
SHA256: 8c0ce8fffa8d772fcbac4518b960669c11b9b7f4edc231161e2277355ea20003
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\BECD304A637056FEF951190F025A99EF8380B42F
compressed
MD5: 7f39c7cebbf14a60212fd47a3751a51a
SHA256: c1987fefbc0548f61822d6ce1425224149fa79784b81ad4b1a62df9571cd8331
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 0d0970a25dd60a558996d4c6d86915ba
SHA256: 5758f603894388fcf07f4257f3a8e41b59b5bec95e39a1d670d2ee8521c3d9fa
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 00d0f0e00c7e538d9224711fef39be56
SHA256: df0e60680e79b008c8538606e5dc85cc4abd688c300cc83dee1b3149cecfcb42
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: ba07ea0f05d9a35ce19f32717db596fc
SHA256: 4e4ca6a2c8858d74370af765975449f77a63607e4a81bdf9c6ef573fe4e82ec7
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 0aa761a16e769a5bfeb0d6e9c87bde4e
SHA256: f2df26112ced5d8d2e37a4b1c27f83d23d3e48e74d5f0d58d19efdfe9fe0b953
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-backup
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-downloadwhite-proto.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-badbinurl-proto.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-unwanted-proto.metadata
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-unwanted-proto.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-malware-proto.metadata
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-malware-proto.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-phish-proto.metadata
binary
MD5: d5ec29bf9cc1a0d46402b579fa793968
SHA256: 7729cbc24c67dde0fdc83927debe0942fc1c395bea68a947a204e15620af1ccf
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\google4\goog-phish-proto.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 7d33c2013ae8d288ca006e619ccc4b8f
SHA256: 545f1f89cfd3402255c7dd0db2b7f7cf73f80bee26aa698744c28f2615aed6e4
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: f8a348bd274efd7d504ccff56b843d2c
SHA256: 9c90d3aee0fab7144a0160eb4ad4d668327ae9ad8165e361fa63e08cc860b7c8
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\recovery.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-unwanted-simple.sbstore
binary
MD5: a5695cc64d77967232b0c1344c6e72b3
SHA256: 042a22b8681d754671d2018ba109b31a53ee3728d48c6379043f8e3394e7fbad
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-trackwhite-simple.sbstore
binary
MD5: 65e942614eee70680464ac4be75019fc
SHA256: 34395085da32c8b4efe9959e3b0d756b43ffed17694d66f39b966cd331bd9a94
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-unwanted-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-trackwhite-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-track-simple.sbstore
binary
MD5: 95f28ede25c301301f25fbbd9a3c56ec
SHA256: 87763df78772f7d750b0fa5a31eec23e931fd3bd1cbb33beddfc61889da36478
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-phish-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-phish-simple.sbstore
binary
MD5: 3d1ce5e50208f0cb3b979186043a548f
SHA256: 1e13d05d482c3d533dc6035af2b2d6e84749412a5748d1435b70cec8b312340b
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-malware-simple.sbstore
binary
MD5: 3675254e341df799d4307c1f59109185
SHA256: 23d108134bed6099793f7dd6b8b6e62081ec3b945efdbc7c5e0e779fd9b82f98
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-track-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-block-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-malware-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-harmful-simple.sbstore
binary
MD5: 051fb32dece757ba112ac36dc72e3a91
SHA256: 0806d98fb3de55f75d7c0b17e26146567e08c483031526659a4a35d09b97ef19
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-harmful-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-block-simple.sbstore
binary
MD5: e2cf527ca7550b7e7bdf7311e483a2c3
SHA256: f1e07b1d717433f47073dc54a7d98e3e87b3d0fa88e53466f93ea544af885d11
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozplugin-block-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozstd-trackwhite-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozplugin-block-digest256.sbstore
binary
MD5: d6acf2573e12afdd7939568804d3fcc1
SHA256: 5525cbf8f8dc41d19ac632ed324e55293a510ae0eeba16d0e3f33c707aa58a0c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
binary
MD5: 3653809d3956008b3cda7ee4f1fb9c6a
SHA256: 40f130dda6bbc1c51665d19488a07f90c3401bc410a9ecf48c4d3111aecee37b
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashallow-digest256.sbstore
binary
MD5: 6f85bc4b2ecb49e26b0bd83a821065d0
SHA256: c0b3bc9b3dc507ab654caf72d13c3aefa58c9b13b1e4d14dd8816712d80a7e54
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
binary
MD5: ba0009932844173bc8f9af264229df24
SHA256: 66d1c00c04d86e313e9a02775cdf906b1be8d4cd6bef423a1b9e21cc4e9f50c1
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flash-digest256.sbstore
binary
MD5: c921d8e98fa01b4f303481e112202e92
SHA256: 4ef1038730ec8bc7206713c29a936768831b922c5e6c83355fd62d7401d8c1dc
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flash-digest256.sbstore
binary
MD5: 0e8fe60ccd7e9b4c32589a5743a95302
SHA256: 2b124d4026850a3cffd28dbacb58aec28f7dcd4d40bc14e52bbe96d60ce4e749
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\base-track-digest256.sbstore
binary
MD5: 4d2613b4e158aeb6ad8281ecb27963d0
SHA256: 38d184068476e8f2da0a3e7a000b56969e685fe6a36186d76a352658921d86bb
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\base-track-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
binary
MD5: 04824a1f92353f43ebb9e7f74b7476fd
SHA256: b48e58ebab82e4c376f16150a3fff850c1111ff1f5985d68819cfd6f0db159d2
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\allow-flashallow-digest256.sbstore
binary
MD5: d886a47c89d9c49c795da345bc236990
SHA256: a03c5e2656d2f292bf5794c8eeb8d223cd6ba4f4bfb2ed1f325460e879d0bcf7
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\allow-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 2daffc00ee099592bf57f4ec777ae626
SHA256: d34e237176e1fc7f382e84875819beb23a3b9222285543cf89d868a93422fea2
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 4abce4d8fd21b155e5ba20b69fb13f85
SHA256: de7152720ce71e463a40eaeb0f6a1cdfbfeaa70e56ecd5a173c3f8208186a40a
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\A667DFF8411E5A922B357084ABF2E1644065D64F
der
MD5: 91310c2ecaeacb1c9ce9bc203b0f6b63
SHA256: 6baac0cd9c39eca8ab4265d673aa8dd83931e35bec8ee018fa063e5fae7b09d4
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 2ddd13bdc7d1b7da8d41f3ce02b17804
SHA256: 92297d040aa2b90e0622bbc1a681bf5a6ba7023c1f0888baeb3269967366f2ed
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\archived\2019-01\1547138407683.07f86161-cff0-43e4-a6f5-d5c1eb2bce0a.heartbeat.jsonlz4
jsonlz4
MD5: 4aa555fca7843f90daa2cf4bbe88784d
SHA256: 5e1d383fbc90ab99547e0091bf0001993741291bc807b12d57e5a41adbe921a5
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\saved-telemetry-pings\07f86161-cff0-43e4-a6f5-d5c1eb2bce0a
text
MD5: 10af6e4517e348568e714f878d99e5e2
SHA256: ab657e70a2daa9338739a64f898aad67ae9e2936bdcf8ab58dc27768641f7599
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\saved-telemetry-pings\07f86161-cff0-43e4-a6f5-d5c1eb2bce0a.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\archived\2019-01\1547138407683.07f86161-cff0-43e4-a6f5-d5c1eb2bce0a.heartbeat.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: a169bcc77c2759cb6ac56f5299df1811
SHA256: 0fa1082f99267511dfbb3a907c18a2052616914618464977a13362528f461cbc
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 4c4819b4a203940974f14996b4e2b4ec
SHA256: f9ca4534fefb86c895e2d93c253edfe3c727d1fbe30a5ebf91a0227a72b6417a
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite-shm
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite-wal
––
MD5:  ––
SHA256:  ––
2584
firefox.exe
C:\Users\admin\AppData\Local\Temp\mozilla-temp-files\mozilla-temp-41
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: a032620038858128a0a9912e8abc811f
SHA256: 5ac978038e256173eec330364d464183854576b666ba83940e2886f29deebd48
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: 62c58ef37f73c18c71bddccdec72116e
SHA256: c2428fda0415cddd1ba58bc01f24858b9bccd9563741a2d7bc729f0b1dd5ebde
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 394886137962db1279e821bb02f84b68
SHA256: 8f2b4861128dbcbe72591bda9ca59304b29256a3867cbea30042f0e4f68e504e
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: f4dbae03520da7df01014662f73b6d61
SHA256: 44cdeeb2e3d82299ad6c7ea71b96e66353e246879e3fd3bb455269c0ece2bc06
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: f8a348bd274efd7d504ccff56b843d2c
SHA256: 9c90d3aee0fab7144a0160eb4ad4d668327ae9ad8165e361fa63e08cc860b7c8
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\upgrade.jsonlz4-20180807170231
jsonlz4
MD5: 84dc273b0a615ed29f3fffc9ef657e82
SHA256: 12cf262fbb637ba7baf95ca0cd6aaee7f14cd4d5e40652747c3291b1564d1826
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: 84dc273b0a615ed29f3fffc9ef657e82
SHA256: 12cf262fbb637ba7baf95ca0cd6aaee7f14cd4d5e40652747c3291b1564d1826
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\shield-recipe-client.json
text
MD5: e0bc8472a9bfdf8d847311e51931b74c
SHA256: e9d503ae195a7c55ffaed015f11331da8052aa9ea42ed271ab7926af7c4f8917
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\shield-recipe-client.json.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\75A419ECC30883A6BEDBAF499E7C371BB1879535
binary
MD5: 976914736838d106c99fb8dd8f44a6f8
SHA256: 9ce9ba6367267884fce85717520307aee0870b3aa5d3d26208cb19ee8bd24a3a
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F
binary
MD5: bbfb72e2a7bc94812546f247d4aa5f69
SHA256: 778849032c1dfae87a40bf71413a6d3ca8cd0bbb69d36af2065ef97f9b7f88dc
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\E910D1FCE8BF27F5536B88567A4DC32624377CC3
binary
MD5: 5b4f1ab71da139bfd10ebad5f64fe6a2
SHA256: 222854f0277420306f8d6db47365054e6d04c198c4096dd3af3bf85301cf2c4a
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\4C33DFFB1381778E6AEAD5216BBF540003A31AAB
binary
MD5: d71709159df41615e91c2d083fb84815
SHA256: 912c0164329106db784504a759c18eb2bf18c3c01bbd457eb7a8b8efffa0ced9
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 450263109716f47a867057e736b844ed
SHA256: 016b74cb3d65aa46b9b40945d674676dd10889739310512bf55443cdda076def
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: d431d9232a83875ea5d57830c11f3bc5
SHA256: a7d59c9cd860dbc047258fd94e6d75bbb300dd26101c5fb73858627a82d90981
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-wal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\active-update.xml
xml
MD5: 872707a8b7099b145a78e722abca5565
SHA256: ed09e0056a7e270d2e76ce266d26a3930e2e53c9f29e0336e9ac1a0788eae46c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\active-update.xml.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\D6826391FCF9D85587CDDFD7D5A578414024122A
compressed
MD5: 6b3598476037526f33abbbccc10058a1
SHA256: 2d40275bf64b03aba9e990cc82c5ffcf62d74431a5c1ba9ded60d02ab15ae67b
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\B0DD178A11131E48E4990A279306A0B674B34383
compressed
MD5: d6e2821e2d2db9795d41dd663e706db3
SHA256: feea4ebd7d857a55d4842c47fb56c631a9398b1f94cf93ec6c4c060443757ec0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\7D909C26FECC24BC7415ED64B3E8879A6CD4C2A4
compressed
MD5: c976d3460f0d1091046aedd09805a6b5
SHA256: 525725e397ead9892caa7551a84fbb5d0785ef590f074f29100d085ab40774f2
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: 5c36a3d197f055fc8bf179859a2322f7
SHA256: b98ad4395c439e215c54e4c73e1a63a796850597197f8eec6c8c6a7128587b4d
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\96E3CDF8FA4A0DCBB81F0A922B22FED61FC7D2FB
compressed
MD5: a426faac5e23ca6f0ea932f564ad82cd
SHA256: d01a25dc4e033c7327c6ddf53a42fdbaa47adf3c262fbdab38d8a204d5caaf78
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\C7BCCD2D2CA294B38AE834D818CF5D5C0C7A65BE
compressed
MD5: 9d2bf94834e3fda3d4e2654a57787d5e
SHA256: 4080058616a76302b8b93e21f4b4fd5e7aa03fb660f3f66649b4daf8b4fe0f28
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\F8AC72083E334F70A553AE68455FBDF0E65C5221
compressed
MD5: 3f82482fded303bc4516d326978ece61
SHA256: 35ab267e57bb533171507a7d483c4e68fff52a4c410191e1c5a758205d1821fd
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\E325B486B777C14C29762600D998974140F8FD34
binary
MD5: be3a0601e23d8ba201b9269a8b577dc7
SHA256: 7c82d656abfe1b2baad5d9a4cbfc6c69142938b625a5ed02dc531361c09cfde3
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozplugin-block-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozplugin-block-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\handlers.json
text
MD5: b025c44725094e95ec3a5bb155d2d6ab
SHA256: 3fd74d94328cd6da3c487eb496e413ec5111b6abf2559474c47c19e6f19d2e07
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\handlers.json.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\base-track-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\base-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\containers.json.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\containers.json
text
MD5: 893b402c9ee27b4086494190d6fa20fa
SHA256: e699874523444c2d75dbff04b73234a4f4d253c5b8ca9b0561fb31ac3b635cef
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\5E4954707B44E5A4B4ACF5F22B52219A1DCA477F
compressed
MD5: 2259fcb24afbb663ce0d31b3aab20922
SHA256: e71b3e65dd716f63274902942c068df6010de1e9c0eb1ed75b4cca43262505db
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\19C7ECC3E4CD8610945BB004746E3F2853D223C1
der
MD5: 31cd59760db103b755ca706310e83c28
SHA256: 2d45c1a10634513546c1a69c8aaa2045aca1c2550975e1c025dc684740b41e46
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\12A65D276A2524EE4B18A265EA7D9EA172F82B91
binary
MD5: 53704a90a8afbb18de3e9b5e6a225de1
SHA256: 99b86603e8e89f9cc7fd7a587f4c4ba84e5f51dbf9b1471f3b20975a7a13ba18
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozstd-trackwhite-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\saved-telemetry-pings\cf01d896-e1c8-429c-b392-1fb053c2fbdc
text
MD5: 83aa956c14b9f782b37602418170f314
SHA256: 3e269bbd3157fb86125260ef38cc257866bd9bf34b71aaa61b6ecad9de0fe8b3
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\saved-telemetry-pings\cf01d896-e1c8-429c-b392-1fb053c2fbdc.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\archived\2019-01\1547138391181.cf01d896-e1c8-429c-b392-1fb053c2fbdc.update.jsonlz4
jsonlz4
MD5: b3d21771f4b997905912a649ce2752a5
SHA256: 015fa3a243c162a44a89b4eac72e7b768ea96809fdccea461367d8bde100846c
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\datareporting\archived\2019-01\1547138391181.cf01d896-e1c8-429c-b392-1fb053c2fbdc.update.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\allow-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\allow-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\except-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\update.version
text
MD5: da193090a82bc1561ba6b10870d049c9
SHA256: c12884d5e3a0d7651db1588f8f1454da3345ea531125c7a91fe8a53fec9ab72c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-unwanted-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-unwanted-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\update.status
text
MD5: 683e7c0dae508462e3c1766330b83eae
SHA256: 52d26753462488ad21852bc6718e21b84835f53765304d0a1e1b89d05a2a71b1
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\update-1.status
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-trackwhite-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\FFB4D7B385C536ACC6A48289CB65A096C8921E39
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-trackwhite-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\update.mar
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-track-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-track-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-phish-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-phish-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-malware-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-malware-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-harmful-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-harmful-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-block-simple.sbstore
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\safebrowsing-updating\test-block-simple.pset
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\doomed\7144
binary
MD5: 01c6cbcdc6aa68c04c17461923870fc5
SHA256: acb28c6b6ab4adfa8f527150a2e57b52edf9877f6da36982eee8cd378d11333b
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\thumbnails\ad5a4453bea49203135688a7b8db842d.png
image
MD5: 5c5ed1f7fe4ffafe1e9667355b096d9d
SHA256: cb95cdff756be616be7eee9ed5bbba3181edc938e04388ede5b26f717643c2dd
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\thumbnails\ad5a4453bea49203135688a7b8db842d.png.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\F873B6D9501E69C5B130DFB9D28E7D7BF92802B2
binary
MD5: 6caa2154e48df33b71d4c1ca521b7857
SHA256: 6c666665b72641835460564e84a37015304a15626168fa65e82c598a9825e17e
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\CABCAAB05AE00AE3D417253164E05D3B4E345F10
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\66F684AF9CC570C6247262B47C769C601C2A338B
binary
MD5: 5fc7ef05492915d4cf21107c4dc75663
SHA256: 33fcd4d22b6157f9691eb02801f2c2cac30b815bc948e5eb97201047e6e2a2f3
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: 9055863b0ef956ff57c506c694c089d9
SHA256: 90a8da97512af415931d0730363317d7c4da95b39c93b19e5def5d6bdf30da76
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: 82a0277f8eff5bc2305a4efb5b17a469
SHA256: aead3e96dd50f1c820a7a5b742b7214d851c594283c2fdf9200b8ae865840a98
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: fb8b55ac7d2f282e9e7a64ebf3196cd2
SHA256: 1594fdc55ed303edb98265cba9fe4e69f94d57c5048db76e33918bd9b2dce1ac
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\C9F4245770A850F150B443DD94FA194A073E6DB6
der
MD5: 465f2fb3f4f473e3e4379fe5626c0677
SHA256: 452add1d319649e11bd403a3d3f9cd2cbef5e9f5ee19dceb2542aee4957d421f
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: 22fffa13fccd47c54d9b9f912c0a53e7
SHA256: 65f79b0f76c77703455b9586b9679ab80a1e8ca64f2cc9d0d5842565a6edfe71
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: 9b98cc2546713ec566775267d708ba5c
SHA256: 8ce516695b3fc9eb2a13498cf3d0e9d4c24d881171e926be147c4cfa2641305e
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\162BDAA0391079DE536E0ED1CD11B422E27454DB
cer
MD5: ca520c6138d70d9cd680917038b223cb
SHA256: 3d97cf9d79ce6549e06b2e141e0730824343ed8c1752b511c5aef0fe752a4a1c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\9A5EF06F16171A9BDA90EE71C06F89A0C79BF17C
compressed
MD5: 9f0d38bef26f18e964a08f4034c6c5ff
SHA256: 4a097cb68c52f3d8514fe7b116b77707dc2c59a9fab9965ee3efde33da4083c3
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\208FF1130D26FA0CD3BB41CDC42FA496B6D1C0E1
woff2
MD5: 75e56ed07a410dd4dd12c3f3e36f9c32
SHA256: 549ef32a3d527207d57cab9b3598c1b7e77c6d80a652048057f28d6222f5e5de
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\2FD2E2A71F89E3A92F68CB796207228217259289
woff2
MD5: 501f7ef5f3b5a0e20f89bbd86902c6e4
SHA256: caeb836834e57a5df8948f2dfd21812f861cff52b8450e34b57a0339bbefe867
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\2C9A1D353B38A1D3AFF37221761B7C666F1B5C93
compressed
MD5: 4747bb9a06ae16839d0c4a38f929d96b
SHA256: a26e273dd64b55f07c980d13f61c05670700f0ec995d411c511561ce42e59bde
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9
woff2
MD5: e8573ff9c7789aac628dbbadd980bc65
SHA256: acb817ec093e4e444e67e290d8f78238727b1f8a09968e5215c47501ac784f08
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 1eed6a11b62436831e2c2998b066ae0c
SHA256: 85f319ccde3ef65cee0443a51943de29792e486f8bb2330e644e16c446b44087
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\A698B6CF98F43F9B0EE1C1DAF3F2CB9BFF09A47C
image
MD5: 49c5d67d6c888b2d8f3991533b7c8300
SHA256: 5a250fd10b3282cd24945644dde72fc4fc7cbe079ffdee5c206901383999d788
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\3C65B887EA29E617091A5AE14B0D7268FA2053A2
compressed
MD5: db9ebef5b42dd90497f7790ba92d69e8
SHA256: 468e7a13dd767788353605b807d96b8c31ff0f03b04b6bb2d88bacc4e0e206b7
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\6D730121FD763F5F1F5C0FA06E1E8AC73C97591D
compressed
MD5: 99d275ad767e37d1e33c69787d365de9
SHA256: 182fe884b2e85087c84d99f8e194d4dbca010b4607268a33683d2124d401cced
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\57B158DEF1DDA4EB8D7E463C132782854F5F2A22
compressed
MD5: 830292d962ff46f7531d7fb15483d16c
SHA256: a037b835250f6c4fbf7b90dd934663d37b5a9c4244d04added0c898600a57a90
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\E21F074DBAD1CB7994F383C419228B689766FB1C
compressed
MD5: bca6dd7c67af133e536211a73e7f3eaa
SHA256: 6c4fe605a9641a7f007b4c75a7cc234740879fa3083414cac5f375ab2375e06e
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite-journal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\A02D5AC48AAEBEAFEED63256030E5B9CD1889379
compressed
MD5: 7f82b3bc000b1c2fb15e339eacbec3b7
SHA256: 10ef4d881f46322c54eada20faec845daabd708b2648a1642be210079ef7a767
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\.metadata-v2
binary
MD5: b33524be96bb39cd3702541a613998fb
SHA256: 678ffb12a6998612e1551f9c45c5de6564b4f92d35f52291ba72a2f95d4b31cd
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\.metadata
binary
MD5: c63b32690fdf9b41c2887ce9d7d22c6b
SHA256: 260edb24f84018508f1f4006d109de131b947569533c68b2ba4bf1dc2f1e093e
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\.metadata-v2-tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\default\about+newtab\.metadata-tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\prefs.js
text
MD5: 34c26b9485513a15300663e9db2899a2
SHA256: 05b3d98da995c1affca3f83df6f8d5cb47a163ad39e9c2af4cdfc6347d38f3bf
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\startupCache\webext.sc.lz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\startupCache\webext.sc.lz4
binary
MD5: 01629b56362ee6018854c6a663334979
SHA256: 9531b56f684fa950b4a9fca8fa74461795cf0d185d22d562daf84b8e278de076
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\698AC159A6BCBA0D13FE6F10F1A38E498F826F33
compressed
MD5: 79055151141cf1db26c9a589a2178e4c
SHA256: 279df191e0849098d4314bac015cda696b0d95dcce600ebdd4e5509e09d74816
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\D5D7B247774E63182A9E2C82B62424AAB64C79A8
image
MD5: 03fdd07afb2a1a134f45adcf2b4ab097
SHA256: 1eb7fc83a966cdf244db8c9e3847c1a5bf0e60b256f0421ad10b110a7b0c51ef
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\C7BCCD2D2CA294B38AE834D818CF5D5C0C7A65BE
compressed
MD5: 8c4f260e74c2e8c94e950062bc1de831
SHA256: 7dfa21b1bc6a727ab33f36ec21f0790ccaeffe72bd1804f49b5155edf432ca45
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\search.json.mozlz4
jsonlz4
MD5: 0681b16acf886b1434bae784d49f3dbb
SHA256: 9e403c2499c2bc980756750fea6c181013aa46c33ec8234f7f63851c57c5c5ed
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\5C3B1B4A3AF3BDDFB5E032BA9BA685FAE38E7418
compressed
MD5: 20173dcb64589ae44225ab9eff56c02c
SHA256: 83f6a09b1e964c5087c91df8eb2a78998e4682a9c911bb7ea80386ad239cc52d
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\search.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cert9.db
sqlite
MD5: d17459142590906da9e21665ac78e611
SHA256: f53050fb8cfe314fc59c8f9cbdcc2577c1e61ca73eea548da059e71599571db2
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cert9.db-journal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\28A83B17D62C1D2037B9E89A5055EB8319CAAE7E
binary
MD5: 5e40f25924518547e9af5c6b81feb284
SHA256: 249213d862f1faec87e5abbf24d302dfe50e417f94ea8d331028ec7db9081dbe
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\89DBE1DF558BB8439E2062ECC3272086F2E3FF1F
image
MD5: fa4fd2f68e28bcd6351da1ed0238e94d
SHA256: 829b20c148db42e417db98161b133cf4b370d08bbde402b944ee80ad9da6b394
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\82EDD4881E57B2293267E1CA19B8F0DE7DA6FCFE
der
MD5: 26c79e30f759082acb61aa92d35be484
SHA256: ccd4cb0e7668a8e7bea5c274839bc97f603d6e8ece8c53d411d323b6d50dee05
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\C664ABAE6A070392F60C7BFF721450AA0CF7DBA0
binary
MD5: b08c7c3b7f3c80d758c9d0ca4efd290a
SHA256: f75c9fc5f4f4032ac591ebaa6a6e108ea5c1145bd4641b2b599ed6a4cc58cd68
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
sqlite
MD5: c419e2c2c50203ef62f3bf478ecdba31
SHA256: 4fcde643d76c0d1db69ab39a33cab0fd37769ca7a5d8c2cf39b03df54c966335
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\F77EAB531E0C9F67F147F85D1271B7747A887ABA
der
MD5: db627b72f127e454ddf247faa8e3c2af
SHA256: 196624360a274998bdc914a656200962a5ce5335a0aca772a654ef1e45ad47e9
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\AAE9DC28F9764C851A0A35587A9D1D272133E14C
der
MD5: 249d6b65899fd0e72c68558c3283946f
SHA256: 9db64595e70957adba19a323c2d01ebd23aa7b08d26a4fd7392148319ac98a0f
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\update.status
text
MD5: 21b14fa7f5deed372d093de77db5c795
SHA256: ec6c7c37be67a0e4443c2a14b2bb45414fa992d0aee701d18e8b30dd6f99731a
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-journal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: c0398f2c0f060dc752390357d5ca7adc
SHA256: 721f7fead94f992b5c5e67edfe57dcc8d9ae63ae2e2d3cc60a98fd2e5d19973f
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
binary
MD5: 39f7cc8613197f4cc7c926fe69d9dc66
SHA256: 2f1ca8bee7b1855c60600a93d25296faacaaf869167f2286ccea651a0e0500b9
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\DFC42896C791034AA152214A96020985CC5E9195
image
MD5: b61376d5cbf20d1be650adb6836572c0
SHA256: 45b5fa6a86cffe2724030563027afe67bb626bd7101a3f64ba2b21bc8b5260f0
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\6509930F4539DB79DA356F2C5D01976D46756302
compressed
MD5: 17de84a2bebe8a4fe8504f8cba49012e
SHA256: cdc87c3f7d7e74b0d67d04b4be1fa9f7d7d3011753795bee68b2c45e3023e21d
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\78DBE55782B7B81AF853B4884323B48C34429A53
image
MD5: 63f5a145ee4dfb8904c4fcfae2b851af
SHA256: 405ff54d24990e42eefc9f2f788624ccd7d2757c41ba0860f3f1ac945a9f352a
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\863C89121F6B8F9B86DAD458CF263CE94F9E75B2
image
MD5: 5cfc037436177d2ac9ee5f0e79fd8cf7
SHA256: e2575de4f197dbf8e4a2dce0955250e0e3e85257895746f1b5a058150bcf3e9c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\E044228CC91563D0417E4365BC256BF9734ED0B7
compressed
MD5: e9c86a0c3d97d16fde22757c40830d46
SHA256: a1ef49e06add1cd43585ef599c6d18932cbaa9e4fe3d826fd85d7019e88a0e3c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\69F575696ECA60963259D8FAB5D15B577F719019
der
MD5: fca8a8919f07ba90e1a482a03130682c
SHA256: cc5ead9e1bc29638bb79655ebc34f76afb324886419b528e91189f11145fb0ca
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\8419A2637E780F24D2A2B6A86D7C862193C89CBA
image
MD5: 17b7449e275e1f739f7036aecfe7cde9
SHA256: 7ebedfdc805725631daec7051e1ba602d6f3c502654f3ba4faca963f0e7430cc
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\25B7BCEA5F8F9BAB63D9D39210838F8E28B9D225
compressed
MD5: 34b4340e50347443b6b0932ce5d541c2
SHA256: cb4a9140dc5707c5fcea2336614a86b4cdc015300f157fe9e08be8c7aab2df1c
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\9671DB4E21A40D05E565A5211964DD6D443A716F
image
MD5: 001dbacd324843f262d937fc6cd9c02c
SHA256: 41a5e409aeacf23998dadc03b4e66d9916901dcf834a0cf7d45656caa5c97b1e
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-journal
––
MD5:  ––
SHA256:  ––
1008
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: c322e141a537b8574fa6af0e505c4d64
SHA256: 62149dd20a3fe1902ae6723c289ea5e569322fef4e93f324c89daa8264358032
1008
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\a2bndy39.default-1547138373630\cache2\entries\AC5E012C1887C7B691A8EA00C4E754025E25C235
compressed
MD5: 6e46a2556c541e96fa595e4e2e62cbbe
SHA256: cb9e262653e73972e744e668cf32e353a4bc1ce17154ec01ecf09373bee818c7
1008
firefox.exe