General Info

URL

http://www.mediafire.com/file/gd13bw2vnc6a3k6/FreeFileSync_10.13_Windows_Setup.exe

Full analysis
https://app.any.run/tasks/06e8c901-19e1-4153-b75b-108d7f789153
Verdict
Malicious activity
Analysis date
7/11/2019, 16:00:58
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

adware

Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • FreeFileSync.exe (PID: 2704)
  • FreeFileSync_Win32.exe (PID: 3476)
  • FreeFileSync_Win32.exe (PID: 2860)
  • FreeFileSync.exe (PID: 2692)
  • FreeFileSync_10.13_Windows_Setup.exe (PID: 3568)
  • FreeFileSync_10.13_Windows_Setup.exe (PID: 2820)
Changes settings of System certificates
  • FreeFileSync_Win32.exe (PID: 2860)
Downloads executable files from the Internet
  • chrome.exe (PID: 2664)
Executes PowerShell scripts
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Creates files in the user directory
  • FreeFileSync_Win32.exe (PID: 3476)
  • powershell.exe (PID: 2756)
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Adds / modifies Windows certificates
  • FreeFileSync_Win32.exe (PID: 2860)
Modifies the open verb of a shell class
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Starts CMD.EXE for commands execution
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Executable content was dropped or overwritten
  • FreeFileSync_10.13_Windows_Setup.exe (PID: 2820)
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
  • FreeFileSync_10.13_Windows_Setup.exe (PID: 3568)
  • chrome.exe (PID: 3080)
Uses TASKLIST.EXE to query information about running processes
  • cmd.exe (PID: 2652)
Reads Windows owner or organization settings
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Reads the Windows organization settings
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Manual execution by user
  • FreeFileSync.exe (PID: 2692)
  • explorer.exe (PID: 2552)
Creates a software uninstall entry
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Dropped object may contain Bitcoin addresses
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Creates files in the program directory
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
Application was dropped or rewritten from another process
  • FreeFileSync.exe (PID: 3652)
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 4024)
  • FreeFileSync_10.13_Windows_Setup.tmp (PID: 3124)
Reads Internet Cache Settings
  • chrome.exe (PID: 3080)
Reads settings of System Certificates
  • chrome.exe (PID: 2664)
Application launched itself
  • chrome.exe (PID: 3080)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
65
Monitored processes
23
Malicious processes
5
Suspicious processes
2

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs freefilesync_10.13_windows_setup.exe freefilesync_10.13_windows_setup.tmp no specs freefilesync_10.13_windows_setup.exe freefilesync_10.13_windows_setup.tmp freefilesync.exe no specs cmd.exe no specs tasklist.exe no specs powershell.exe no specs freefilesync.exe no specs freefilesync_win32.exe no specs chrome.exe no specs explorer.exe no specs freefilesync.exe no specs freefilesync_win32.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3080
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" http://www.mediafire.com/file/gd13bw2vnc6a3k6/FreeFileSync_10.13_Windows_Setup.exe
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\freefilesync_10.13_windows_setup.exe
c:\windows\system32\credssp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\mpr.dll

PID
3756
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6c88a9d0,0x6c88a9e0,0x6c88a9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3028
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3084 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
2364
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=11959801087912451943 --mojo-platform-channel-handle=1016 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
2664
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=12152439995664432638 --mojo-platform-channel-handle=1644 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
2736
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10930369960067843202 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2236 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3424
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2466267208460986850 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2248 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
924
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2091918124574831319 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2432 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3976
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=8882773613255519556 --mojo-platform-channel-handle=4284 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
3568
CMD
"C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe"
Path
C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync Setup
Version
10.13
Modules
Image
c:\users\admin\downloads\freefilesync_10.13_windows_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-74r5n.tmp\freefilesync_10.13_windows_setup.tmp

PID
3124
CMD
"C:\Users\admin\AppData\Local\Temp\is-74R5N.tmp\FreeFileSync_10.13_Windows_Setup.tmp" /SL5="$30132,13428938,240128,C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-74R5N.tmp\FreeFileSync_10.13_Windows_Setup.tmp
Indicators
No indicators
Parent process
FreeFileSync_10.13_Windows_Setup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-74r5n.tmp\freefilesync_10.13_windows_setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2820
CMD
"C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe" /SPAWNWND=$30166 /NOTIFYWND=$30132
Path
C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe
Indicators
Parent process
FreeFileSync_10.13_Windows_Setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync Setup
Version
10.13
Modules
Image
c:\users\admin\downloads\freefilesync_10.13_windows_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-6gs16.tmp\freefilesync_10.13_windows_setup.tmp

PID
4024
CMD
"C:\Users\admin\AppData\Local\Temp\is-6GS16.tmp\FreeFileSync_10.13_Windows_Setup.tmp" /SL5="$40182,13428938,240128,C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe" /SPAWNWND=$30166 /NOTIFYWND=$30132
Path
C:\Users\admin\AppData\Local\Temp\is-6GS16.tmp\FreeFileSync_10.13_Windows_Setup.tmp
Indicators
Parent process
FreeFileSync_10.13_Windows_Setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-6gs16.tmp\freefilesync_10.13_windows_setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\users\admin\appdata\local\temp\is-r7j6k.tmp\freefilesync.exe
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\freefilesync\freefilesync.exe
c:\program files\freefilesync\realtimesync.exe
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netutils.dll

PID
3652
CMD
"C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\FreeFileSync.exe" ffs_installer_convert_jpg_to_bmp "C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\img_31.jpg"
Path
C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\FreeFileSync.exe
Indicators
No indicators
Parent process
FreeFileSync_10.13_Windows_Setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync - Folder Comparison and Synchronization
Version
10.13
Modules
Image
c:\users\admin\appdata\local\temp\is-r7j6k.tmp\freefilesync.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll

PID
2652
CMD
"C:\Windows\system32\cmd.exe" /c tasklist /FO CSV > "C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\tasklist.txt"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
FreeFileSync_10.13_Windows_Setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\tasklist.exe

PID
3344
CMD
tasklist /FO CSV
Path
C:\Windows\system32\tasklist.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Lists the current running tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\tasklist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
2756
CMD
"powershell.exe" -inputformat none -outputformat none -NonInteractive -Command "Add-MpPreference -ExclusionProcess 'C:\Program Files\FreeFileSync\Bin\*'"
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
No indicators
Parent process
FreeFileSync_10.13_Windows_Setup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\system32\netutils.dll

PID
2704
CMD
"C:\Program Files\FreeFileSync\FreeFileSync.exe" ffs_finalize_installation
Path
C:\Program Files\FreeFileSync\FreeFileSync.exe
Indicators
No indicators
Parent process
FreeFileSync_10.13_Windows_Setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync - Folder Comparison and Synchronization
Version
10.13
Modules
Image
c:\program files\freefilesync\freefilesync.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\freefilesync\bin\freefilesync_win32.exe

PID
2860
CMD
"C:\Program Files\FreeFileSync\Bin\FreeFileSync_Win32.exe" ffs_finalize_installation
Path
C:\Program Files\FreeFileSync\Bin\FreeFileSync_Win32.exe
Indicators
No indicators
Parent process
FreeFileSync.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync - Folder Comparison and Synchronization
Version
10.13
Modules
Image
c:\program files\freefilesync\bin\freefilesync_win32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\propsys.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\imageres.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\is-6gs16.tmp\freefilesync_10.13_windows_setup.tmp
c:\users\admin\downloads\freefilesync_10.13_windows_setup.exe

PID
2840
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,9485076162974521865,14530295773762355968,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=7786298312105617287 --mojo-platform-channel-handle=1256 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\zipfldr.dll
c:\windows\system32\fxsresm.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
2552
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
2692
CMD
"C:\Program Files\FreeFileSync\FreeFileSync.exe"
Path
C:\Program Files\FreeFileSync\FreeFileSync.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync - Folder Comparison and Synchronization
Version
10.13
Modules
Image
c:\program files\freefilesync\freefilesync.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3476
CMD
"C:\Program Files\FreeFileSync\Bin\FreeFileSync_Win32.exe"
Path
C:\Program Files\FreeFileSync\Bin\FreeFileSync_Win32.exe
Indicators
Parent process
FreeFileSync.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
FreeFileSync.org
Description
FreeFileSync - Folder Comparison and Synchronization
Version
10.13
Modules
Image
c:\program files\freefilesync\bin\freefilesync_win32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\propsys.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\imageres.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\system32\windowspowershell\v1.0\pwrshsip.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\fwpuclnt.dll

Registry activity

Total events
1900
Read events
1685
Write events
214
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
3476
FreeFileSync_Win32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
EnableFileTracing
0
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
EnableConsoleTracing
0
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
FileTracingMask
4294901760
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
ConsoleTracingMask
4294901760
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
MaxFileSize
1048576
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASAPI32
FileDirectory
%windir%\tracing
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
EnableFileTracing
0
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
EnableConsoleTracing
0
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
FileTracingMask
4294901760
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
ConsoleTracingMask
4294901760
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
MaxFileSize
1048576
3476
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FreeFileSync_Win32_RASMANCS
FileDirectory
%windir%\tracing
3476
FreeFileSync_Win32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3476
FreeFileSync_Win32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3476
FreeFileSync_Win32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3476
FreeFileSync_Win32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3028
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3080-13207327272919000
259
3028
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3080-13207327272919000
0
2664
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
3080
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
3080
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13207327274012750
3080
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307070004000B000E0001001900880200000000
3080
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\FreeFileSync
InstallDir
C:\Program Files\FreeFileSync
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\FreeFileSync
CreateDesktopShortcut
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\FreeFileSync
CreateStartmenuEntry
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\FreeFileSync
CreateSendToShortcut
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_gui
FreeFileSync.ffs_gui.1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_gui
Content Type
Application/xml
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1
FreeFileSync Configuration
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1\DefaultIcon
C:\Program Files\FreeFileSync\FreeFileSync.exe,0
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1\shell\open\command
"C:\Program Files\FreeFileSync\FreeFileSync.exe" "%1"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1\shell\edit
Edit with FreeFileSync
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1\shell\edit
Icon
C:\Program Files\FreeFileSync\FreeFileSync.exe,0
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_gui.1\shell\edit\command
"C:\Program Files\FreeFileSync\FreeFileSync.exe" -edit "%1"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_batch
FreeFileSync.ffs_batch.1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_batch
Content Type
Application/xml
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1
FreeFileSync Batch File
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1\DefaultIcon
C:\Program Files\FreeFileSync\FreeFileSync.exe,1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1\shell\open\command
"C:\Program Files\FreeFileSync\FreeFileSync.exe" "%1"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1\shell\edit
Edit with FreeFileSync
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1\shell\edit
Icon
C:\Program Files\FreeFileSync\FreeFileSync.exe,0
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_batch.1\shell\edit\command
"C:\Program Files\FreeFileSync\FreeFileSync.exe" -edit "%1"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_db
FreeFileSync.ffs_db.1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_db.1
FreeFileSync Synchronization Database
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_db.1
NoOpen
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FreeFileSync.ffs_db.1\DefaultIcon
C:\Program Files\FreeFileSync\FreeFileSync.exe,2
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_real
RealTimeSync.ffs_real.1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ffs_real
Content Type
Application/xml
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RealTimeSync.ffs_real.1
RealTimeSync Configuration
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RealTimeSync.ffs_real.1\DefaultIcon
C:\Program Files\FreeFileSync\RealTimeSync.exe,0
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RealTimeSync.ffs_real.1\shell\open\command
"C:\Program Files\FreeFileSync\RealTimeSync.exe" "%1"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Setup Version
5.6.1 (u)
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: App Path
C:\Program Files\FreeFileSync
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
InstallLocation
C:\Program Files\FreeFileSync\
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Icon Group
(Default)
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: User
admin
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Setup Type
custom
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Selected Components
installtype,installtype\local,shortcuts,shortcuts\desktop,shortcuts\startmenu,shortcuts\sendto
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Deselected Components
installtype\portable
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Inno Setup: Language
English
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
DisplayName
FreeFileSync 10.13
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
DisplayIcon
C:\Program Files\FreeFileSync\FreeFileSync.exe
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
UninstallString
"C:\Program Files\FreeFileSync\Uninstall\unins000.exe"
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
QuietUninstallString
"C:\Program Files\FreeFileSync\Uninstall\unins000.exe" /SILENT
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
DisplayVersion
10.13
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
Publisher
FreeFileSync.org
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
URLInfoAbout
https://FreeFileSync.org
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
NoModify
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
NoRepair
1
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
InstallDate
20190711
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
MajorVersion
10
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
MinorVersion
13
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
VersionMajor
10
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
VersionMinor
13
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeFileSync_is1
EstimatedSize
38224
4024
FreeFileSync_10.13_Windows_Setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
62
2756
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2860
FreeFileSync_Win32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2860
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E
Blob
0F0000000100000014000000A8569CCD21EF9CC5737C7A12DF608C2CBC545DF153000000010000006500000030633021060B2A84680186F6770205010130123010060A2B0601040182373C0101030200C03021060B2A84680186F6770205010730123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B0000000100000034000000430065007200740075006D002000540072007500730074006500640020004E006500740077006F0072006B0020004300410000006200000001000000200000005C58468D55F58E497E743982D2B50010B6D165374ACF83A7D4A32DB768C4408E1400000001000000140000000876CDCB07FF24F6C5CDEDBB90BCE284374675F71D0000000100000010000000E3F9AF952C6DF2AAA41706A77A44C20303000000010000001400000007E032E020B72C3F192F0628A2593A19A70F069E2000000001000000BF030000308203BB308202A3A00302010202030444C0300D06092A864886F70D0101050500307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B204341301E170D3038313032323132303733375A170D3239313233313132303733375A307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100E3FB7DA372BAC2F0C91487F56B014EE16E4007BA6D275D7FF75B2DB35AC7515FABA432A66187B66E0F86D2300297F8D76957A118395D6A6479C60159AC3C314A387CD204D24B28E8205F3B07A2CC4D73DBF3AE4FC756D55AA79689FAF3AB68D423865927CF0927BCAC6E72831C3072DFE0A2E9D2E1747519BD2A9E7B1554041BD74339AD5528C5E21ABBF4C0E4AE384933CC76859F3945D2A49EF2128C51F87CE42D7FF5AC5FEB169FB12DD1BACC9142774C25C990386FDBF0CCFB8E1E97593ED5604EE60528ED4979134BBA48DB2FF972D339CAFE1FD83472F5B440CF3101C3ECDE112D175D1FB850D15E19A769DE073328CA5095F9A754CB54865045A9F9490203010001A3423040300F0603551D130101FF040530030101FF301D0603551D0E041604140876CDCB07FF24F6C5CDEDBB90BCE284374675F7300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100A6A8AD22CE013DA6A3FF62D0489D8B5E72B07844E3DC1CAF09FD2348FABD2AC4B95504B510A38D27DE0B8263D0EEDE0C3779415B22B2B09A415CA670E0D4D077CB23D300E06C562FE1690D0DD9AABF218150D906A5A8FF9537D0AAFEE2B3F5992D45848AE54209D774022FF789D899E9BC27D4478DBA0D461C77CF14A41CB9A431C49C28740334FF331926A5E90D74B73E97C676E82796A366DDE1AEF2415BCA9856837370E4861AD23141BA2FBE2D135A766F4EE84E810E3F5B0322A012BE6658114ACB03C4B42A2A2D9617E03954BC48D376279D9A2D06A6C9EC39D2ABDB9F9A0B27023529B14095E7F9E89C55881946D6B734F57ECE399AD938F151F74F2C
2860
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E
Blob
040000000100000010000000D5E98140C51869FC462C8975620FAA7803000000010000001400000007E032E020B72C3F192F0628A2593A19A70F069E1D0000000100000010000000E3F9AF952C6DF2AAA41706A77A44C2031400000001000000140000000876CDCB07FF24F6C5CDEDBB90BCE284374675F76200000001000000200000005C58468D55F58E497E743982D2B50010B6D165374ACF83A7D4A32DB768C4408E0B0000000100000034000000430065007200740075006D002000540072007500730074006500640020004E006500740077006F0072006B002000430041000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030753000000010000006500000030633021060B2A84680186F6770205010130123010060A2B0601040182373C0101030200C03021060B2A84680186F6770205010730123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00F0000000100000014000000A8569CCD21EF9CC5737C7A12DF608C2CBC545DF12000000001000000BF030000308203BB308202A3A00302010202030444C0300D06092A864886F70D0101050500307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B204341301E170D3038313032323132303733375A170D3239313233313132303733375A307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100E3FB7DA372BAC2F0C91487F56B014EE16E4007BA6D275D7FF75B2DB35AC7515FABA432A66187B66E0F86D2300297F8D76957A118395D6A6479C60159AC3C314A387CD204D24B28E8205F3B07A2CC4D73DBF3AE4FC756D55AA79689FAF3AB68D423865927CF0927BCAC6E72831C3072DFE0A2E9D2E1747519BD2A9E7B1554041BD74339AD5528C5E21ABBF4C0E4AE384933CC76859F3945D2A49EF2128C51F87CE42D7FF5AC5FEB169FB12DD1BACC9142774C25C990386FDBF0CCFB8E1E97593ED5604EE60528ED4979134BBA48DB2FF972D339CAFE1FD83472F5B440CF3101C3ECDE112D175D1FB850D15E19A769DE073328CA5095F9A754CB54865045A9F9490203010001A3423040300F0603551D130101FF040530030101FF301D0603551D0E041604140876CDCB07FF24F6C5CDEDBB90BCE284374675F7300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100A6A8AD22CE013DA6A3FF62D0489D8B5E72B07844E3DC1CAF09FD2348FABD2AC4B95504B510A38D27DE0B8263D0EEDE0C3779415B22B2B09A415CA670E0D4D077CB23D300E06C562FE1690D0DD9AABF218150D906A5A8FF9537D0AAFEE2B3F5992D45848AE54209D774022FF789D899E9BC27D4478DBA0D461C77CF14A41CB9A431C49C28740334FF331926A5E90D74B73E97C676E82796A366DDE1AEF2415BCA9856837370E4861AD23141BA2FBE2D135A766F4EE84E810E3F5B0322A012BE6658114ACB03C4B42A2A2D9617E03954BC48D376279D9A2D06A6C9EC39D2ABDB9F9A0B27023529B14095E7F9E89C55881946D6B734F57ECE399AD938F151F74F2C
2860
FreeFileSync_Win32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E
Blob
1900000001000000100000001F7E750B566B128AC0B8D6576D2A70A50F0000000100000014000000A8569CCD21EF9CC5737C7A12DF608C2CBC545DF153000000010000006500000030633021060B2A84680186F6770205010130123010060A2B0601040182373C0101030200C03021060B2A84680186F6770205010730123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B0000000100000034000000430065007200740075006D002000540072007500730074006500640020004E006500740077006F0072006B0020004300410000006200000001000000200000005C58468D55F58E497E743982D2B50010B6D165374ACF83A7D4A32DB768C4408E1400000001000000140000000876CDCB07FF24F6C5CDEDBB90BCE284374675F71D0000000100000010000000E3F9AF952C6DF2AAA41706A77A44C20303000000010000001400000007E032E020B72C3F192F0628A2593A19A70F069E040000000100000010000000D5E98140C51869FC462C8975620FAA782000000001000000BF030000308203BB308202A3A00302010202030444C0300D06092A864886F70D0101050500307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B204341301E170D3038313032323132303733375A170D3239313233313132303733375A307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100E3FB7DA372BAC2F0C91487F56B014EE16E4007BA6D275D7FF75B2DB35AC7515FABA432A66187B66E0F86D2300297F8D76957A118395D6A6479C60159AC3C314A387CD204D24B28E8205F3B07A2CC4D73DBF3AE4FC756D55AA79689FAF3AB68D423865927CF0927BCAC6E72831C3072DFE0A2E9D2E1747519BD2A9E7B1554041BD74339AD5528C5E21ABBF4C0E4AE384933CC76859F3945D2A49EF2128C51F87CE42D7FF5AC5FEB169FB12DD1BACC9142774C25C990386FDBF0CCFB8E1E97593ED5604EE60528ED4979134BBA48DB2FF972D339CAFE1FD83472F5B440CF3101C3ECDE112D175D1FB850D15E19A769DE073328CA5095F9A754CB54865045A9F9490203010001A3423040300F0603551D130101FF040530030101FF301D0603551D0E041604140876CDCB07FF24F6C5CDEDBB90BCE284374675F7300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100A6A8AD22CE013DA6A3FF62D0489D8B5E72B07844E3DC1CAF09FD2348FABD2AC4B95504B510A38D27DE0B8263D0EEDE0C3779415B22B2B09A415CA670E0D4D077CB23D300E06C562FE1690D0DD9AABF218150D906A5A8FF9537D0AAFEE2B3F5992D45848AE54209D774022FF789D899E9BC27D4478DBA0D461C77CF14A41CB9A431C49C28740334FF331926A5E90D74B73E97C676E82796A366DDE1AEF2415BCA9856837370E4861AD23141BA2FBE2D135A766F4EE84E810E3F5B0322A012BE6658114ACB03C4B42A2A2D9617E03954BC48D376279D9A2D06A6C9EC39D2ABDB9F9A0B27023529B14095E7F9E89C55881946D6B734F57ECE399AD938F151F74F2C
2840
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2840
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@sendmail.dll,-21
Desktop (create shortcut)
2840
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@zipfldr.dll,-10148
Compressed (zipped) folder
2840
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@sendmail.dll,-4
Mail recipient
2840
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
@C:\Windows\system32\FXSRESM.dll,-120
Fax recipient

Files activity

Executable files
14
Suspicious files
36
Text files
119
Unknown types
19

Dropped files

PID
Process
Filename
Type
3080
chrome.exe
C:\Users\admin\Downloads\12f465f8-b33f-453b-ba64-d0859d2c9300.tmp
executable
MD5: a4c2e955fe1ae4594a684ed4f3d0d534
SHA256: 3895b11e9cdbc9671af0eaf95970884010335d5551cd858f867a3b8e688ba86d
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\FreeFileSync_x64.exe
executable
MD5: b274b2842f1b2575c0b7079f3a2de4de
SHA256: 365dd649689f1d53c76646a11b8662bb9a30faf1f52632c67c9a78f3002a334c
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\FreeFileSync.exe
executable
MD5: 04b4e48dd6b8f1a0a5058482e7145372
SHA256: e772a8eededa39d17d6a4b5f0e845dab82bd6683c822b27577c552633bdb8072
2820
FreeFileSync_10.13_Windows_Setup.exe
C:\Users\admin\AppData\Local\Temp\is-6GS16.tmp\FreeFileSync_10.13_Windows_Setup.tmp
executable
MD5: c9abba4aa0b64f76a684f02eaf384070
SHA256: 8f524c13afc0d44e07bb07124d6bf94094980710bc8d7cc77335a608d64074cf
3568
FreeFileSync_10.13_Windows_Setup.exe
C:\Users\admin\AppData\Local\Temp\is-74R5N.tmp\FreeFileSync_10.13_Windows_Setup.tmp
executable
MD5: c9abba4aa0b64f76a684f02eaf384070
SHA256: 8f524c13afc0d44e07bb07124d6bf94094980710bc8d7cc77335a608d64074cf
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\FreeFileSync.exe
executable
MD5: 04b4e48dd6b8f1a0a5058482e7145372
SHA256: e772a8eededa39d17d6a4b5f0e845dab82bd6683c822b27577c552633bdb8072
3080
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 712930.crdownload
executable
MD5: 42438176ae1f0d4cfc7087efbf900558
SHA256: 4dad982f97d8e98a35e46364b45b83db965b5e4aceb931bce9f8649962f673d2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\RealTimeSync_Win32.exe
executable
MD5: d2991c5a7c0800e99ed235fa8965533d
SHA256: e619447e760434ca20cee6fade5ed7813e9ab39a3612944aece65c01948d8635
3080
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 712930.crdownload
executable
MD5: 0d83c8b50960af9a55f5ad4c48156975
SHA256: 69c86dde133a0fe2f3db07bd289b19adfd9ad4e399cfc6b5b185505c0ca8bd57
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\RealTimeSync_x64.exe
executable
MD5: 1037da6e6d123af96119c8a1fba6f742
SHA256: 08326a7abe14f33a8f23dd336857832ca24567d7f7f324949f4b9ee4decf3344
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Uninstall\unins000.exe
executable
MD5: c9abba4aa0b64f76a684f02eaf384070
SHA256: 8f524c13afc0d44e07bb07124d6bf94094980710bc8d7cc77335a608d64074cf
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\RealTimeSync.exe
executable
MD5: 8d0ea9dd4f87ef4d9e414e616f6b8b48
SHA256: 30a2036aa48735efac0fa25a1bd37da093124ea7cc3297d86a0ae5c3bc4dc59f
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\FreeFileSync_Win32.exe
executable
MD5: 4ffd7a766848df3c3cbb0c3c893760fa
SHA256: cd447a3d51a588227c67126643ba9b07fb1792e321d6b7cccd09485a1899cab3
3080
chrome.exe
C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe
executable
MD5: 42438176ae1f0d4cfc7087efbf900558
SHA256: 4dad982f97d8e98a35e46364b45b83db965b5e4aceb931bce9f8649962f673d2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\bulgarian.lng
text
MD5: 2fe76c93078db9cd22897357b7315e38
SHA256: 08e48e9de2b68e10cea729bc3f92440678cf98655a1f5d14590f7194bb2aaac9
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
binary
MD5: 6b7401045db4b7c613b379be188f8a59
SHA256: 268a5c1117e9f67d8d898ef4312f23943f302b59294fda50bc552e27517e7b44
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
text
MD5: 8e6917ab1e5b5731766f60e38fda0205
SHA256: eac071ed158d6973a5c653595019cb75b777a847efd8f28abbba5943e01464dc
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
binary
MD5: c2651a13ca654d2d66c0c631e6d1cbd3
SHA256: 21825029c220cbd566d0efa6ea3325a671b4c5d365ec60a1025ef6161aa8f752
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000003.log
binary
MD5: abfbf70f5139143407cc73d9df342cc6
SHA256: 74a8c46e03b20b4a41801a071fc721f4ae1c3d34732b767f409b2aade78bb6cb
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
text
MD5: 5b699c63314da9756370e0d6db1e8ec3
SHA256: eaf8a5941bf6eea6a0f72a57b035da586a0f96ea878665782ecc9df54d4ad8cb
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
text
MD5: 15004f39e2712ad0cab8d278ade513eb
SHA256: e1c875b6b81553139029628492886cfba9f6fa923b0a95b95b40c5c755591a69
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
binary
MD5: 640ef794d11a1c8d8d999a708fa0d18e
SHA256: d418a0a7adf3c6c5ec6a635e096c3375b104234d54c22889d26fcf2654623304
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
text
MD5: fc2b3e85b38feb9e36ab9883f8c49850
SHA256: 36826375ed5d5801bad218e3b74eafdeb913450ca745261bca364b316b31240e
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG
text
MD5: 6df7322f8d6211f74eab8888f48fa80a
SHA256: 3c2fd78d4db019d8626d7906b2c73093b054e7f94e20604bf5e39fb0f6e281db
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000002
binary
MD5: 22bf0e81636b1b45051b138f48b3d148
SHA256: e292f241daafc3df90f3e2d339c61c6e2787a0d0739aac764e1ea9bb8544ee97
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
sqlite
MD5: d3b10330b5481dfd2205318b46045d90
SHA256: bb1b055788e87fe3460eeb3e2f703c971c582b84f2de60606f8dd66e0ab7853d
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
text
MD5: 63293a6f17622c390d6a419753e5bed4
SHA256: 29e96c901ff4ccbac68e2602d8717c383063b9516f72ec8eccf41090b2200ff0
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
binary
MD5: 0686d6159557e1162d04c44240103333
SHA256: 3303d5eed881951b0bb52cf1c6bfa758770034d0120c197f9f7a3520b92a86fb
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
text
MD5: aa9d92eaf0b14da51a98df2127481b23
SHA256: 5df3fc8d661195977b5eb7e0901f82dbd6c942e47967e4c94dc445ec955b96ba
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
text
MD5: ba524373123fc675fc02c8fa6dd0f0ba
SHA256: d944ee2095ce08734720c661912924f107b474afc68a32c9a63ac5c85b645a43
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
text
MD5: 0a7b6ae68bc2227ae106c3233eb74948
SHA256: 583cb003000e97c9d0fff07d613ba9a8c508ee50def6757844caad4edacabf21
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Visited Links
binary
MD5: 549efd08b8208afc72d4f0ad9face1c6
SHA256: 7e023a5f33bdb9f2bbc2533acdb1c2221f6521739905da06d8870d033c40fdf5
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000020
binary
MD5: 506562585675f86ceab6a68bf036a597
SHA256: 2bb80413a9331da8e530be250c3d1e1ae21a38f34a93806200575cee6df9b00b
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
text
MD5: ad23f27d1f6ab091c88ff35eb8208d83
SHA256: 15ce4da083aa641873c289debf79c984ae2ede974cd3dd85e07d8cd066d10a02
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
text
MD5: 7c37ead03052c075a280a92f0429f682
SHA256: 953b7c426d7adaa8a0e9a4b9dcc71bb733146deb434593c24bd0c44f1a5611d2
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF10f203.TMP
text
MD5: 9bc75ad15fe7ecdb0d0adf9d87ab1fb0
SHA256: da04011cf13de75cc9503b15fe68b0343277546f4f58a19b87fb07d26f2bd153
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons
sqlite
MD5: 162ce2306747f43a0992970c5ac35fc9
SHA256: d8d3200c890dc9dc11b9fb9bc32be5e7286cbd357a2ed6e07c5c26a63378497e
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
text
MD5: c7bbce53d77942794bd8666eab36017f
SHA256: 314e9c1dab704ffbf8c39f8168ff1d2ab9de2399a49b3a62eb76bd8abf4c826d
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data
sqlite
MD5: 34aeec6b8b7aae3b0ed24ac4acdd1f8e
SHA256: a758007d8fa6a13b2d728a09ce43883150cb18b945eda4bf15224ee7f92bd5de
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log
binary
MD5: bc7da2cac6132acd0a3c13fa652189fb
SHA256: cb1868e25c09c5491c14beae657fda819cf83470b61de5e6370fef191914c5b9
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History
sqlite
MD5: 32e639e7abbc6f1ce9e19c27509ffe2c
SHA256: 531a667f8e5d7bd9e600f3804d9e28bf71345aa5c1d8edecf85f7f269880f041
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\a24564a5-4163-41de-87a8-7e7583ed70db.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Session
binary
MD5: 77d69c51c01878f5af7ed614cbc41698
SHA256: 808a108e1869b8351cd4327df52a4e907c42b86d895616dfc93814111621e598
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies
sqlite
MD5: 33f152d75815b60e951585209a039248
SHA256: be02cf2bf9df632178b335005f1c10cb819689761cc55714ee1137d0d3331752
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
binary
MD5: a9851aa4c3c8af2d1bd8834201b2ba51
SHA256: e708be5e34097c8b4b6ecb50ead7705843d0dc4b0779b95ef57073d80f36c191
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 0c07149df41a39f4864940e9ddae2f8d
SHA256: 24e47ef39dc976262b31037fe96361a47cc453be3abff639f02dd243fc2bd04a
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF10deb9.TMP
text
MD5: 0c07149df41a39f4864940e9ddae2f8d
SHA256: 24e47ef39dc976262b31037fe96361a47cc453be3abff639f02dd243fc2bd04a
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\3cc86435-29e2-4fc9-b7f6-0e000672a309.tmp
––
MD5:  ––
SHA256:  ––
2860
FreeFileSync_Win32.exe
C:\Program Files\FreeFileSync\Install.dat
binary
MD5: 21d0cfc676953d576e82117e0be03cab
SHA256: 46eeda0dd97254f2967784b163ed669baad3b827a963895ec85c4f0e71f0d471
2860
FreeFileSync_Win32.exe
C:\Program Files\FreeFileSync\Install.dat.1515.tmp
––
MD5:  ––
SHA256:  ––
2860
FreeFileSync_Win32.exe
C:\Program Files\FreeFileSync\Install.dat.1751.tmp
––
MD5:  ––
SHA256:  ––
2756
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF10b4db.TMP
binary
MD5: 9b2d1efa0be7143cb658133a528ac158
SHA256: 1e454e5c557c498adf3fa385195b98ed08625c36fb6095fd7e6dc58cea4c9c03
2756
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms
binary
MD5: 9b2d1efa0be7143cb658133a528ac158
SHA256: 1e454e5c557c498adf3fa385195b98ed08625c36fb6095fd7e6dc58cea4c9c03
2756
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6S03V8LM6CBQ208G53HJ.temp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Uninstall\unins000.dat
dat
MD5: ad4a24e1ee6dd816584784a1eb490f81
SHA256: dbfb75ba0d9783022e4ca1aaec18de1ac47f68932b1d679bc9f5db66efa294e0
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Uninstall\unins000.msg
binary
MD5: 3c4697e6f46b10815d5ec6c46fdef413
SHA256: 29f507920254e881eb4ee7fb7564099a62b6a6fc7427889936f1e82b829ccbb3
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\FreeFileSync.lnk
lnk
MD5: a6e90cd21ba285f91e1c628f1d2887ba
SHA256: 4bef594051443d17267d6bb1e22585608c778cb10871b34ee9b0f860e7a193ec
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealTimeSync.lnk
lnk
MD5: f3dca6af4154de31f34b852c2c6390eb
SHA256: 091ff66a7264237a6c6d86364b524f89222d8cb49744c72601432a3af37347fc
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk
lnk
MD5: 59f9dccaf15dcfdc8dd76d18d99d6c80
SHA256: 52886cf3e3216c1b7b708e51ee65e980b0b16eae137566c1a4024882ef8530e6
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Users\Public\Desktop\RealTimeSync.lnk
lnk
MD5: 434378842edd625ab3ce2904fdd2fa33
SHA256: c719071393a3c0e6695df9a931f062480444066dc1350d28288d648099d00647
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Users\Public\Desktop\FreeFileSync.lnk
lnk
MD5: 355e210456a55e0967ded8ac94ef7ddb
SHA256: b2dc5b674213c2afc64cdfb17539bff330e4450fbc84a5067780e4d55e55cd07
3476
FreeFileSync_Win32.exe
C:\Users\admin\AppData\Roaming\FreeFileSync\GlobalSettings.xml
xml
MD5: 37dced71f3d208d4b5cda00f2c225def
SHA256: 7d4597aade519bf4b175f462f1215c2e48ef61a968ed68adbcc46ce6007f3ac1
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\is-9KTH6.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
text
MD5: 112a64eaeb79ed8f81123c5f28590075
SHA256: 44b8666203c4facbb96a4275c26eea6ed732015f6199813d891a89da804e7bf6
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\is-KBS9O.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
binary
MD5: 57833b7bc148b0188ae582ac40e59151
SHA256: 167d87896ad7b272b37aec22fe449c5bc6552f7319c5d14100970fa839ddc00c
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\is-A3D64.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF10a829.TMP
text
MD5: 506daf275080a3b7526e70a23611bbe2
SHA256: c482409d9b0330819410c169bc44a58c9eeba9dcad7cdd6e10df73d99f6d0ade
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 506daf275080a3b7526e70a23611bbe2
SHA256: c482409d9b0330819410c169bc44a58c9eeba9dcad7cdd6e10df73d99f6d0ade
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\929f98e0-fd09-43d3-8bae-3a38b3d61f3b.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: f26d1a9b45308a9a23d254ed8592b16c
SHA256: be87d29789514dbda48c4961d3a0cf3a1e90c64f73ac328ec9bd57edc4c868d2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Bin\is-QKBVR.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\swedish.lng
text
MD5: 507e1f0ac62ee18f2b0db7e043a32a86
SHA256: d5c6d46aa05e28dc0858d29e10d0b38091e6c068980caf2ce3df3c53f1bc9b26
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\spanish.lng
text
MD5: e2e96d8eb498a062cf65ab7676b93c00
SHA256: 80e4f49996a7a34da1a3c409e198eb4be7affeea66eb5b3f23035e3bf4b34502
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-C2I6E.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\slovak.lng
text
MD5: bcee83ce3fe4a110723ca0218edf6cbb
SHA256: 05b486cb1bcb0658e5e0f95105ac442db3064d7fb99dec082534af0dababc552
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\slovenian.lng
text
MD5: ffe2f3fa7f932db844c5d6c4abd4bcc3
SHA256: 730f757fc4efef263b97048f6f0a91cb1414207a0f17b59894568cab215e7fac
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\romanian.lng
text
MD5: f7bb4e68eea53d30932d87dbbe10fd58
SHA256: 65a7cf191799b772f986e087b00e2434ccf51e5417cb813d588681bdf7163cd3
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\russian.lng
text
MD5: 05f06452cd0fee0d4323d2db28de681f
SHA256: eadf38221e136b9b00aeb3d01b0b437eced2ef479bd6ef3dff3e209087b0e277
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-RUVTQ.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-RTITU.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-T0BIQ.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-E7PFK.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-KDEC8.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\portuguese_br.lng
text
MD5: f2e778570d9131ff929fb05e8b2f75fd
SHA256: 9e4fad3eb1d1edd6d09f1abfd8c1c19e5a1179a69d014505c291523841708081
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\portuguese.lng
text
MD5: 1421af217e9ceea9f6904391db1dc18c
SHA256: e18d5bf43a884c35b360e585409b0050a4458fc74f5f3d9b3337ef450eaed59b
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\polish.lng
text
MD5: 55dd32224bd024524f26d2d834b8d649
SHA256: 5f66118ed23153e77f55b64b223ac1de5141e46aa056e964faa4e04e0719afb4
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-57GNQ.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-IBPFP.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-JFBU1.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\korean.lng
text
MD5: 46f8909235db2179c20857a01c2438eb
SHA256: 935b6b355875ca6d4af69cb44a6b471372a33bbefe54a2a24010014f9f833155
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\lithuanian.lng
text
MD5: c82131a1c00d9a8a6a963327d201849c
SHA256: 37058a5f02a2ad1afc48ce95c11e09524eaaf1757324798ba35daa75a4cd68ec
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\japanese.lng
text
MD5: fcc50d79d4468fe72ffd17114d7700d2
SHA256: 9b70a9a2f55924220bd7e4b184da6bf5f8cb18b7b97364685cd2ce3274d0bccb
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\norwegian.lng
text
MD5: b40f071c39e02f2c43c8fdf71d9bb123
SHA256: 2abe575bff8ae51c5db8935ee307278ecbf3eb378e1e407b7ade77abfe6e91a2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\italian.lng
text
MD5: 3290414162f26b478dcd26a5c13538c8
SHA256: 300b8d32cdd58625dd20354ec20a26ae6cd44edd4680d83910bd642eaa4ae5e2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-LQU5A.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-EISN1.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-LPOH1.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-OGRMS.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-RJAT9.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\greek.lng
text
MD5: 87fa9423f252965c4c220901860ef9bb
SHA256: cf8161b9d58fc7f35afc04739c4d1fb8e0c2c0740bd1e5cc60cc5a5eb64c35fd
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\hungarian.lng
text
MD5: f95ff6cd5fc35bcb34c416503b1972d1
SHA256: 0eff19ebf0a3d86cde5c0cd7cd99b6a90bcc429fb011bf8140a796797f035f02
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\hebrew.lng
text
MD5: cf0ae54c4fb2787bb44c6bb1dbc4af66
SHA256: fc91e754ae27b18d2ca816de3a763380920de8242fc31fc29f28d4b854be1cd2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\hindi.lng
text
MD5: 214d7781a2c2bddc2d58b147c14c3a2d
SHA256: 83481c984b05f565a4af9909291999823e2f590ef0ad08d0acc0a4e6384423dd
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-6FTKP.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-B27IQ.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-FPUJD.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-FVNCD.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\german.lng
text
MD5: 58ff5a48d064a1bf5d11908f678bc216
SHA256: b3bfeaf9098915d2009e7bc236a13ed0f99913b532e36a240631d10182709b7e
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\french.lng
text
MD5: d655d9c18dd206b2a47a82112a1a4983
SHA256: 92b86bc08b928f5f1e9c1ae0d5dad31d8474ad4ba45d5b184b5699ab44abc0c5
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\english_uk.lng
text
MD5: 332aed691bfa63f193e31af2c72445c5
SHA256: 24b9a4876a903112bac3ac8a170e6acd249d7615913152dfed16878df280c501
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-26MME.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-VM1TA.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-AKO0U.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\danish.lng
text
MD5: ada553d589e956e1567ad26eaa4e6af3
SHA256: 14379e7443e57004d0ec86226ed43a37a008bb8b4845c96ba6cecc95a7a03931
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\czech.lng
text
MD5: ae897973852fa59d70360d5159413433
SHA256: 96b866571c6f5ff6a7fb8ca6b5de7e1f71bbc18457f6d1b9fcff759278969dd8
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\croatian.lng
text
MD5: 65bb02b2168f8ca29a42062c60d9b392
SHA256: 51ec128fd05bc353c358c16e6b954f19ae5220f466d245b9588180bb0878c8d0
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\dutch.lng
text
MD5: 386496db3daadffb285728a134e60d64
SHA256: 267cf665141a09155bb55e3a32a0dce469c1bcc6480b00583d1b34ff3c219d0d
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-DKFET.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-B2U15.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-DMKGR.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-1R30K.tmp
––
MD5:  ––
SHA256:  ––
3756
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\chinese_traditional.lng
text
MD5: 0c02a96f81aaf309753e8b0b32a8462a
SHA256: a3f0051d9d5fbb6c35274b9ef162fd9f27509714a1c2c820de86433ae8cda3f8
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\chinese_simple.lng
text
MD5: 53c7aa5a201f6b75510b3dc5f667a36b
SHA256: 893b3f0311d85860b42231532c235a43923bc3aa7190f0df6a001b2013eabea7
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-78A51.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-F2Q65.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-4GCPL.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\arabic.lng
text
MD5: 76d1f56f51ca9700c781ba98ce30af48
SHA256: 62fcf6d1587144c92b44bedeee7a237df27a25a5ee6907a3c015ea128ec7c71a
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\harp.wav
wav
MD5: e875fad9206aa9a9f5d48fd9fc46ef69
SHA256: 31da846077e99bf11f95477b9547513d04df8048914fa7ac8ec4087b7889c4b0
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\notify.wav
wav
MD5: 06aa6e9bb4c8b813bedeb8bfaf9a0231
SHA256: 793663736aa27af730224872b5276b771a62501c038ebdadf785e003f5149caa
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Languages\is-O6S7P.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-E4BJ2.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-IOACP.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\gong.wav
wav
MD5: 7dff321c9c0dfba94c1fd67b621dd759
SHA256: 7f6c0f42af2125813d3fd67e57d2cf885d7d6567fbf076daf7c13321fbb46d80
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-48S5V.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\ding.wav
wav
MD5: c13b4139d1e32dcabdb8eee9e699053d
SHA256: d6b7b4d6e7a38e58484fed53bdbb27c0d0097a58e6289bc5c06267c6b2c8d06a
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-PFBVL.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\bell.wav
wav
MD5: 8f25094e49e0eed54613716d78fc25f4
SHA256: e925452ebe92b4276138bcd8ed7b63d5d46c98948a354f63831f4761b6a8745e
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\bell2.wav
wav
MD5: 00e641ecf71aafbedf54f6d948ca8b58
SHA256: 0d670f271dbc8ddd1f8add6c01cdad1678e8d968a38482a09b69af2a4e12c3c2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-BDAG7.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-NT718.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\cacert.pem
text
MD5: f4a13fcdd32ca18c3e62c7a728ebb378
SHA256: cb2eca3fbfa232c9e3874e3852d43b33589f27face98eef10242a853d83a437a
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-0G082.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\Icons.zip
compressed
MD5: 2dd30b648f8197cbf87986f4a488b51c
SHA256: eea1d25b7a10dfc7a878f1263820f791863920d743741f214d8d00b4cd62e207
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Resources\is-03G5F.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\License.txt
text
MD5: 56f9187e5a389b60cb500248f18c0dd1
SHA256: 66908fb3f468c1865b7812655b16cbba05baeaccf02a4b5a613b15a7f320e1cf
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF10f232.TMP
text
MD5: 9bc75ad15fe7ecdb0d0adf9d87ab1fb0
SHA256: da04011cf13de75cc9503b15fe68b0343277546f4f58a19b87fb07d26f2bd153
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\is-FQCVN.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\is-C50RQ.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 9bc75ad15fe7ecdb0d0adf9d87ab1fb0
SHA256: da04011cf13de75cc9503b15fe68b0343277546f4f58a19b87fb07d26f2bd153
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\is-64KM5.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\User Manual.pdf
pdf
MD5: 82e6eca63ddfe420439eb593e5777320
SHA256: 3e62f37bdc32b70941ac3fb88ff44337c440d70ef6ffca9e0a8883b6e8670f9e
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\is-KH6AG.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Changelog.txt
text
MD5: a9b52bb938cd4fb8ef0479fc667c7f88
SHA256: a87cf123f0bae637f5c42dac15001021bc359fb537c75adb472e5beb6bde1121
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: 58139605eac7465cc2c37cb021e2b730
SHA256: 5cfa7adb36d084545c5d7a0bb34b5a8808a9f2e3eeade9b0e87cd7d0582c04a2
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\is-A6GJ0.tmp
––
MD5:  ––
SHA256:  ––
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Program Files\FreeFileSync\Uninstall\is-QIKUI.tmp
––
MD5:  ––
SHA256:  ––
2652
cmd.exe
C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\tasklist.txt
text
MD5: 59ce0c52b5f14e087c04a58e4a1b58da
SHA256: d29eab68d3d0bf10276f8582fb321c98147e248d6c94d8ab9a12b7ea72bc79d3
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 2282676b91355016f9d112d375d3109d
SHA256: d79b1ce8e263fa358390ca36f1dfc4ef229060e002b649785d358e66fa986245
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF106f94.TMP
text
MD5: 2282676b91355016f9d112d375d3109d
SHA256: d79b1ce8e263fa358390ca36f1dfc4ef229060e002b649785d358e66fa986245
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\d35ed834-69d9-439d-aa5a-e84cab0ce08c.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: e595134e310c09cb4ded9a3f6cfc9784
SHA256: f130faf49996295c9a40f1a54706442f6a6d0175935ce8baf6e92f0e21492509
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF106860.TMP
text
MD5: e595134e310c09cb4ded9a3f6cfc9784
SHA256: f130faf49996295c9a40f1a54706442f6a6d0175935ce8baf6e92f0e21492509
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\178e8fab-7521-41ef-becd-4e87ef95ed85.tmp
––
MD5:  ––
SHA256:  ––
3652
FreeFileSync.exe
C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\img_31.bmp
image
MD5: 99c114c2799ee05ec3bd92a8112778a9
SHA256: ef741a6728b067e6b1484a687a05d6b017eba23785e6334d5a1419ccd30a289f
4024
FreeFileSync_10.13_Windows_Setup.tmp
C:\Users\admin\AppData\Local\Temp\is-R7J6K.tmp\img_31.jpg
image
MD5: 0965883bcf8d18fb5a11463a9c655837
SHA256: ad14e88cf69f170f044f73cb51ae86bde4352640d9f9088abed65dcfad9aba00
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF10f232.TMP
text
MD5: f26d1a9b45308a9a23d254ed8592b16c
SHA256: be87d29789514dbda48c4961d3a0cf3a1e90c64f73ac328ec9bd57edc4c868d2
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF10f241.TMP
text
MD5: 58139605eac7465cc2c37cb021e2b730
SHA256: 5cfa7adb36d084545c5d7a0bb34b5a8808a9f2e3eeade9b0e87cd7d0582c04a2
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6f7809f5-4ccc-4a0b-b85f-c9af937e263e.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: ea0f971278199d406a24ed9a49c21237
SHA256: 70fd11371f354fb4e42c24994aad564db97d4dc3224c191cf3acf1036103e2f2
3080
chrome.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: ec9ac716ef8f443b94c3b891073b151d
SHA256: f1fd9aac950825995123bd5ec836e43f496470a7bebf9ffca870c9584827445c
3080
chrome.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
compressed
MD5: ea8f42f93bee43a6632dbaddc84bf19a
SHA256: 7cea505e8377dfcce4155bfcc08c8bac011bd181c681c5c5545fca619b4b8f3b
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar4085.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab4084.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6525274CBC2077D43D7D17A33C868C4F
der
MD5: d5e98140c51869fc462c8975620faa78
SHA256: 5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e
3080
chrome.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6525274CBC2077D43D7D17A33C868C4F
binary
MD5: 185d4ed3878f0eedee4de99914111322
SHA256: fdf16f2e923a4dfcbddbc4d22a0d0959bf8559abff7a0031b23e8db68e954101
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab3FE5.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar3FE6.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar3F58.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab3F57.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: a140dd687da3e2aaf0fa531113dd6cac
SHA256: 2334ec1dc09851e71d6076b1e315e86e63162e34c3757f797a5b285329d43206
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata~RF103ea1.TMP
binary
MD5: a140dd687da3e2aaf0fa531113dd6cac
SHA256: 2334ec1dc09851e71d6076b1e315e86e63162e34c3757f797a5b285329d43206
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\299036af-f64d-4559-a712-1deca53223f7.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: 208d5015f7fdf612ac6e89ee07ebbb52
SHA256: 6a702d09490cc304758cb6089aea683f21e3415ff50abbc3f85a02b40bdac98c
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\7879cf5d-e2ee-4c8e-93a8-2bf74e7f1e54.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\Downloads\FreeFileSync_10.13_Windows_Setup.exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies
sqlite
MD5: 7abfa8880f36ac292e0e87c102ca4334
SHA256: 6a9534cde5f75f87554b5ab3bd95126ac37c1a10b3c5b16526f9ceb1bd9e143b
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar37E4.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab37E3.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar37D2.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab37D1.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar37D0.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab37CF.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar37BE.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab37BD.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Tar379D.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Temp\Cab379C.tmp
––
MD5:  ––
SHA256:  ––
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 07d4160d18d1a88465c126f54895ad2d
SHA256: dabb653de64f402a60b97d66c24661ab040f33c7e282738237647fae96b697a0
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF10374e.TMP
text
MD5: 07d4160d18d1a88465c126f54895ad2d
SHA256: dabb653de64f402a60b97d66c24661ab040f33c7e282738237647fae96b697a0
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0f5bafc4-03a3-467d-9a32-79731acdbc1f.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\e63aca85-31f7-48df-b326-d05103f4e6bb.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF10327c.TMP
text
MD5: 65ebd7a76cfe817ee91ac6132a3877d3
SHA256: 761e58a9f860c343846257c6f3ef2b02c14864d7aa7da7354b6090a510f06e36
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 65ebd7a76cfe817ee91ac6132a3877d3
SHA256: 761e58a9f860c343846257c6f3ef2b02c14864d7aa7da7354b6090a510f06e36
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\9b0bbac7-309c-423a-a91e-5895c3c96e00.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF1031a1.TMP
text
MD5: 653b74712185395eb6b8a60f874190de
SHA256: 1f00a1e5acae4a3227437abf6e2e73e38f0af79df7802c474efe42e93a05262f
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 653b74712185395eb6b8a60f874190de
SHA256: 1f00a1e5acae4a3227437abf6e2e73e38f0af79df7802c474efe42e93a05262f
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\75cfd475-dcde-46bc-b1df-c0720628712c.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old
text
MD5: 97aa7678fb9d338d08c371711b54a104
SHA256: 4657635b66fa68ae1550b7bff4e54016f8874b4df43a004c9a7244c8465c6ca8
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session
binary
MD5: 92eb31d830454841999ecdb4a714d301
SHA256: 63f01870e03b0329f3ae859435ef5610661a45085390af36275ae7d6808c8ffb
2664
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6154549d-9537-49a0-b5eb-396720ac936b.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT~RF101222.TMP
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000002.dbtmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000001.dbtmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF101128.TMP
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF1010cb.TMP
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: f50f89a0a91564d0b8a211f8921aa7de
SHA256: b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
binary
MD5: f50f89a0a91564d0b8a211f8921aa7de
SHA256: b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
text
MD5: 448678ce825d57fb6d2f7161dbb650a2
SHA256: 73ef7a2b58324ed1483784ef3fa9f2c60299d98c2d4ab3964ab073ab2e90528a
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
binary
MD5: 891a884b9fa2bff4519f5f56d2a25d62
SHA256: e2610960c3757d1757f206c7b84378efa22d86dcf161a98096a5f0e56e1a367e
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old
text
MD5: 722d616be0caaf9ed585c9aea7f3742c
SHA256: f86c514fa380332be463670b3b334c8feedc2f6cb9b4118ea367729b056de0fb
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
text
MD5: 911b244e4a362b56f2478647d2d61a40
SHA256: 3a5aec1ea537d8841e604d0aa4cd5f9241c805a3d4eb4e372cfb7eeb3678a361
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
text
MD5: 0acecca4cf9ade756da7cc9dcdf02d50
SHA256: 18f910775132b4fee014ea0fab836d857f367e76232fab4ae6a86a92e4c3ebee
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old
text
MD5: 454106ccf080f3e3795c229fc73350d4
SHA256: 9974dc611be9e20bdfa7b8d939cb913ad23859dea5f52ebb8d10cead9ab5b4fa
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF100c66.TMP
text
MD5: 454106ccf080f3e3795c229fc73350d4
SHA256: 9974dc611be9e20bdfa7b8d939cb913ad23859dea5f52ebb8d10cead9ab5b4fa
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF100c17.TMP
text
MD5: a874f3e3462932a0c15ed8f780124fc5
SHA256: 01bd196d6a114691ec642082ebf6591765c0168d4098a0cd834869bd11c8b87d
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
text
MD5: a874f3e3462932a0c15ed8f780124fc5
SHA256: 01bd196d6a114691ec642082ebf6591765c0168d4098a0cd834869bd11c8b87d
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old
text
MD5: 3d551b6e929cf62f7aa66091e718704b
SHA256: 1698a1b1bc3e86676392fb8bd4c712438302a5a2220503c08f290ed4b1790404
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RF100bf8.TMP
text
MD5: 3d551b6e929cf62f7aa66091e718704b
SHA256: 1698a1b1bc3e86676392fb8bd4c712438302a5a2220503c08f290ed4b1790404
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs
binary
MD5: 0686d6159557e1162d04c44240103333
SHA256: 3303d5eed881951b0bb52cf1c6bfa758770034d0120c197f9f7a3520b92a86fb
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\e381e49a-bdb3-4d64-a91c-d35339d2daed.tmp
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
text
MD5: a519780ed0a2f4336db4f5651d79c369
SHA256: da5b71bd0075b55757bf757bf5f4d4a1dcbcf0762cda5b31b28680963e068c75
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF100bc9.TMP
text
MD5: a519780ed0a2f4336db4f5651d79c369
SHA256: da5b71bd0075b55757bf757bf5f4d4a1dcbcf0762cda5b31b28680963e068c75
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
text
MD5: 213ae3da120d7862d60b5763b6c9d466
SHA256: 5736534d6ee654c1bf1a8e79e73330af58f622e8657285330d2c7189a55604f4
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF100bba.TMP
text
MD5: 213ae3da120d7862d60b5763b6c9d466
SHA256: 5736534d6ee654c1bf1a8e79e73330af58f622e8657285330d2c7189a55604f4
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
––
MD5:  ––
SHA256:  ––
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
text
MD5: dc32343f45b01764b6267ad36548102a
SHA256: a250f5ad57d4bd58aae92810d50278e3be2dbf869f126a3a3519691bcdfc2075
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
text
MD5: c4d6cbb269c626168a5d6d0d8cce6c30
SHA256: b62cdbb758278a0c2e50593357390119441d8de09428eb29027f3dfd1332e348
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF100b8b.TMP
text
MD5: c4d6cbb269c626168a5d6d0d8cce6c30
SHA256: b62cdbb758278a0c2e50593357390119441d8de09428eb29027f3dfd1332e348
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF100b9a.TMP
text
MD5: dc32343f45b01764b6267ad36548102a
SHA256: a250f5ad57d4bd58aae92810d50278e3be2dbf869f126a3a3519691bcdfc2075
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787
3080
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version
text
MD5: 1a89a1bebe6c843c4ff582e7ed33ca1f
SHA256: 65099ca087b66aa8ca420ab121daad713e1db5a61c5a574d9b1c0df24f012520
3476
FreeFileSync_Win32.exe
C:\Users\admin\AppData\Roaming\FreeFileSync\LastRun.ffs_gui
xml
MD5: 6922e7cff1bd8b462db4a01a29e255c5
SHA256: 81580c6a97a84325b1d5931cc74a359e8dfb97ca035634450686f2c1f3a1390f

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
6
TCP/UDP connections
14
DNS requests
10
Threats
3

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2664 chrome.exe GET 302 104.19.195.29:80 http://www.mediafire.com/file/gd13bw2vnc6a3k6/FreeFileSync_10.13_Windows_Setup.exe US
––
––
malicious
2664 chrome.exe GET 200 199.91.154.188:80 http://download2194.mediafire.com/bh6y6js6xxbg/gd13bw2vnc6a3k6/FreeFileSync_10.13_Windows_Setup.exe US
executable
suspicious
3080 chrome.exe GET 200 23.111.11.204:80 http://repository.certum.pl/ctnca.cer US
der
whitelisted
3080 chrome.exe GET 200 205.185.216.10:80 http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab US
compressed
whitelisted
4024 FreeFileSync_10.13_Windows_Setup.tmp POST 200 66.198.240.22:80 http://freefilesync.org/on_new_installation.php US
text
––
––
malicious
3476 FreeFileSync_Win32.exe POST 200 66.198.240.22:80 http://freefilesync.org/get_latest_version_number.php US
text
text
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2664 chrome.exe 172.217.21.195:443 Google Inc. US whitelisted
2664 chrome.exe 172.217.16.205:443 Google Inc. US whitelisted
2664 chrome.exe 104.19.195.29:80 Cloudflare Inc US shared
2664 chrome.exe 199.91.154.188:80 MediaFire, LLC US suspicious
2664 chrome.exe 216.58.205.228:443 Google Inc. US whitelisted
2664 chrome.exe 172.217.16.142:443 Google Inc. US whitelisted
3080 chrome.exe 23.111.11.204:80 netDNA US unknown
3080 chrome.exe 205.185.216.10:80 Highwinds Network Group, Inc. US whitelisted
4024 FreeFileSync_10.13_Windows_Setup.tmp 66.198.240.22:80 A2 Hosting, Inc. US suspicious
3476 FreeFileSync_Win32.exe 66.198.240.22:80 A2 Hosting, Inc. US suspicious

DNS requests

Domain IP Reputation
www.mediafire.com 104.19.195.29
104.19.194.29
malicious
clientservices.googleapis.com 172.217.21.195
whitelisted
accounts.google.com 172.217.16.205
shared
download2194.mediafire.com 199.91.154.188
suspicious
www.google.com 216.58.205.228
whitelisted
ssl.gstatic.com 172.217.21.195
whitelisted
sb-ssl.google.com 172.217.16.142
whitelisted
repository.certum.pl 23.111.11.204
whitelisted
www.download.windowsupdate.com 205.185.216.10
205.185.216.42
whitelisted
freefilesync.org 66.198.240.22
malicious

Threats

PID Process Class Message
2664 chrome.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
2664 chrome.exe Misc activity ET INFO EXE - Served Attached HTTP
4024 FreeFileSync_10.13_Windows_Setup.tmp Misc activity ADWARE [PTsecurity] PUP.FusionCore.D

Debug output strings

No debug info.