\n\n\n\n\n \n \nstart \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n\noutlook.exe \n\n \n\n\n\n\n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \n\n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n","processesValues":[{"rowId":"7d1b9751-06bb-412e-9483-a3b69043af71","rowData":{"threatLevel":0,"values":[1068,"\"C:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE\" /f \"C:\\Users\\admin\\AppData\\Local\\Temp\\Potential Phish_ _External Email_ New Encrypted Fax Notification.msg\"","C:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE",["network"],"Explorer.EXE"],"information":{"values":["admin","Microsoft Corporation","MEDIUM","Microsoft Outlook","","14.0.6025.1000"],"modules":[["c:\\windows\\system32\\ntdll.dll"],["c:\\program files\\microsoft office\\office14\\outlook.exe"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\winsxs\\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\\msvcr90.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\msi.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\winsxs\\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\\msvcp90.dll"],["c:\\windows\\system32\\apphelp.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\mso.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\cultures\\office.odf"],["c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\\comctl32.dll"],["c:\\program files\\microsoft office\\office14\\addins\\umoutlookaddin.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\msimtf.dll"],["c:\\program files\\microsoft office\\office14\\1033\\outllibr.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\msores.dll"],["c:\\windows\\system32\\davclnt.dll"],["c:\\windows\\system32\\davhlpr.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\1033\\msointl.dll"],["c:\\windows\\system32\\mscoree.dll"],["c:\\windows\\microsoft.net\\framework\\v4.0.30319\\mscoreei.dll"],["c:\\program files\\common files\\microsoft shared\\officesoftwareprotectionplatform\\osppc.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\riched20.dll"],["c:\\program files\\microsoft office\\office14\\olmapi32.dll"],["c:\\program files\\microsoft office\\office14\\1033\\mapir.dll"],["c:\\windows\\system32\\powrprof.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-ole32-l1-1-0.dll"],["c:\\windows\\system32\\urlmon.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shlwapi-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-advapi32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-user32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-version-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-normaliz-l1-1-0.dll"],["c:\\windows\\system32\\normaliz.dll"],["c:\\windows\\system32\\iertutil.dll"],["c:\\windows\\system32\\wininet.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\program files\\microsoft office\\office14\\contab32.dll"],["c:\\program files\\microsoft office\\office14\\omsxp32.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\\comctl32.dll"],["c:\\program files\\microsoft office\\office14\\mspst32.dll"],["c:\\windows\\system32\\sfc.dll"],["c:\\windows\\system32\\sfc_os.dll"],["c:\\program files\\microsoft office\\office14\\exsec32.dll"],["c:\\windows\\system32\\tzres.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\program files\\common files\\microsoft shared\\ink\\tiptsf.dll"],["c:\\program files\\microsoft office\\office14\\rtfhtml.dll"],["c:\\windows\\system32\\mlang.dll"],["c:\\program files\\microsoft office\\office14\\1033\\omsintl.dll"],["c:\\program files\\microsoft office\\office14\\wwlib.dll"],["c:\\program files\\microsoft office\\office14\\gfx.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\msimg32.dll"],["c:\\program files\\microsoft office\\office14\\oart.dll"],["c:\\program files\\microsoft office\\office14\\1033\\wwintl.dll"],["c:\\program files\\common files\\microsoft shared\\office14\\msptls.dll"],["c:\\windows\\system32\\propsys.dll"],["c:\\windows\\system32\\msxml6.dll"],["c:\\windows\\system32\\bcrypt.dll"],["c:\\windows\\system32\\winspool.drv"],["c:\\program files\\common files\\microsoft shared\\office14\\usp10.dll"],["c:\\windows\\system32\\mssprxy.dll"],["c:\\program files\\internet explorer\\iexplore.exe"],["c:\\windows\\system32\\windowscodecs.dll"],["c:\\windows\\system32\\imageres.dll"],["c:\\windows\\system32\\ehstorshell.dll"],["c:\\windows\\system32\\cscui.dll"],["c:\\windows\\system32\\cscdll.dll"],["c:\\windows\\system32\\cscapi.dll"],["c:\\windows\\system32\\ntshrui.dll"],["c:\\windows\\system32\\srvcli.dll"],["c:\\windows\\system32\\slc.dll"],["c:\\windows\\system32\\explorerframe.dll"],["c:\\windows\\system32\\duser.dll"],["c:\\windows\\system32\\dui70.dll"],["c:\\program files\\microsoft office\\office14\\omsmain.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\program files\\microsoft office\\office14\\addins\\colleagueimport.dll"],["c:\\windows\\system32\\netapi32.dll"],["c:\\windows\\system32\\wkscli.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\program files\\microsoft office\\office14\\onbttnol.dll"],["c:\\windows\\system32\\secur32.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\program files\\microsoft office\\office14\\socialconnector.dll"],["c:\\windows\\winsxs\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\\gdiplus.dll"],["c:\\windows\\winsxs\\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\\mfc90u.dll"],["c:\\windows\\winsxs\\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\\mfc90enu.dll"],["c:\\windows\\system32\\mapi32.dll"],["c:\\windows\\system32\\oleacc.dll"],["c:\\program files\\microsoft office\\office14\\1033\\umoutlookstrings.dll"],["c:\\program files\\microsoft office\\office14\\sharepointprovider.dll"],["c:\\windows\\system32\\sxs.dll"],["c:\\windows\\system32\\ieframe.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shell32-l1-1-0.dll"],["c:\\windows\\system32\\winhttp.dll"],["c:\\windows\\system32\\webio.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shlwapi-l2-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-advapi32-l2-1-0.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\dhcpcsvc6.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\netprofm.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\npmproxy.dll"],["c:\\windows\\system32\\rasadhlp.dll"],["c:\\windows\\system32\\fwpuclnt.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\program files\\microsoft office\\office14\\outlacct.dll"],["c:\\windows\\system32\\msident.dll"],["c:\\windows\\system32\\atl.dll"],["c:\\windows\\system32\\pstorec.dll"],["c:\\program files\\common files\\system\\ole db\\oledb32.dll"],["c:\\windows\\system32\\msdart.dll"],["c:\\program files\\common files\\system\\ole db\\oledb32r.dll"],["c:\\windows\\system32\\comsvcs.dll"],["c:\\windows\\system32\\bcryptprimitives.dll"],["c:\\windows\\system32\\tquery.dll"],["c:\\windows\\system32\\structuredquery.dll"],["c:\\program files\\microsoft office\\office14\\msproof7.dll"],["c:\\program files\\common files\\microsoft shared\\proof\\mslid.dll"],["c:\\windows\\system32\\msoeacct.dll"],["c:\\windows\\system32\\msoert2.dll"],["c:\\windows\\system32\\inetcomm.dll"],["c:\\windows\\system32\\inetres.dll"],["c:\\windows\\system32\\acctres.dll"],["c:\\windows\\system32\\msxml3.dll"]]}}},{"rowId":"9b162726-0b2c-40e1-9ed7-4d18dc19cff2","rowData":{"threatLevel":0,"values":[2752,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -osint -url \"C:\\Users\\admin\\Desktop\\FX-Mary.kirk-54266316-54266316.htm\"","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"Explorer.EXE"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","0","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\apphelp.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"]]}}},{"rowId":"31aff2d7-ae6f-421e-9e5e-a7bbd0017e6c","rowData":{"threatLevel":0,"values":[2572,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -url C:\\Users\\admin\\Desktop\\FX-Mary.kirk-54266316-54266316.htm","C:\\Program Files\\Mozilla Firefox\\firefox.exe",["network"],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\kbdus.dll"],["c:\\windows\\system32\\dwrite.dll"],["c:\\windows\\system32\\psapi.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\netprofm.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\npmproxy.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wbem\\wbemprox.dll"],["c:\\windows\\system32\\wbemcomn2.dll"],["c:\\windows\\system32\\bcrypt.dll"],["c:\\windows\\system32\\dhcpcsvc6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\wbem\\wbemsvc.dll"],["c:\\windows\\system32\\wbem\\fastprox.dll"],["c:\\windows\\system32\\ntdsapi.dll"],["c:\\windows\\system32\\winsta.dll"],["c:\\windows\\system32\\apphelp.dll"],["c:\\windows\\system32\\mscms.dll"],["c:\\windows\\system32\\wpc.dll"],["c:\\windows\\system32\\wevtapi.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\samlib.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\windows\\system32\\mmdevapi.dll"],["c:\\windows\\system32\\propsys.dll"],["c:\\windows\\system32\\audioses.dll"],["c:\\windows\\system32\\d2d1.dll"],["c:\\windows\\system32\\xmllite.dll"],["c:\\windows\\system32\\msimg32.dll"],["c:\\program files\\mozilla firefox\\softokn3.dll"],["c:\\program files\\mozilla firefox\\freebl3.dll"],["c:\\program files\\mozilla firefox\\nssckbi.dll"],["c:\\windows\\system32\\wininet.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shlwapi-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-user32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-version-l1-1-0.dll"],["c:\\windows\\system32\\normaliz.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-normaliz-l1-1-0.dll"],["c:\\windows\\system32\\iertutil.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-advapi32-l1-1-0.dll"],["c:\\windows\\system32\\secur32.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-advapi32-l2-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-ole32-l1-1-0.dll"],["c:\\windows\\system32\\winhttp.dll"],["c:\\windows\\system32\\webio.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shlwapi-l2-1-0.dll"],["c:\\windows\\system32\\rasadhlp.dll"],["c:\\windows\\system32\\fwpuclnt.dll"],["c:\\windows\\system32\\imagehlp.dll"],["c:\\windows\\system32\\bcryptprimitives.dll"],["c:\\windows\\system32\\ncrypt.dll"],["c:\\windows\\system32\\explorerframe.dll"],["c:\\windows\\system32\\duser.dll"],["c:\\windows\\system32\\dui70.dll"],["c:\\windows\\system32\\actxprxy.dll"]]}}},{"rowId":"d6df774c-a6ed-4193-923c-10c6049d537b","rowData":{"threatLevel":0,"values":[2688,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.0.1292601068\\501720356\" -parentBuildID 20201112153044 -prefsHandle 868 -prefMapHandle 888 -prefsLen 1 -prefMapSize 238726 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 1196 gpu","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","","83.0"],"modules":[["c:\\windows\\system32\\ntdll.dll"],["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\mfplat.dll"],["c:\\windows\\system32\\mf.dll"],["c:\\windows\\system32\\atl.dll"],["c:\\windows\\system32\\ksuser.dll"],["c:\\windows\\system32\\dxva2.dll"],["c:\\windows\\system32\\evr.dll"],["c:\\windows\\system32\\powrprof.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"]]}}},{"rowId":"3419b1c7-9f15-4d13-9123-129520a24ad8","rowData":{"threatLevel":0,"values":[3424,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.6.720723943\\443174694\" -childID 1 -isForBrowser -prefsHandle 2356 -prefMapHandle 2352 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 2368 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\dwrite.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\wpc.dll"],["c:\\windows\\system32\\wevtapi.dll"],["c:\\windows\\system32\\samlib.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\program files\\mozilla firefox\\softokn3.dll"],["c:\\program files\\mozilla firefox\\freebl3.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"]]}}},{"rowId":"2476a427-b091-485d-9335-65ec2460b13a","rowData":{"threatLevel":0,"values":[3372,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.13.1901890404\\569382014\" -childID 2 -isForBrowser -prefsHandle 3472 -prefMapHandle 3468 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 3484 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\dwrite.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\wevtapi.dll"],["c:\\windows\\system32\\wpc.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\samlib.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\program files\\mozilla firefox\\softokn3.dll"],["c:\\program files\\mozilla firefox\\freebl3.dll"]]}}},{"rowId":"05cf23e2-d530-44f8-80ed-b42fa81961c5","rowData":{"threatLevel":0,"values":[2268,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.20.468459296\\933825004\" -childID 3 -isForBrowser -prefsHandle 3588 -prefMapHandle 7800 -prefsLen 7399 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 7788 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\dwrite.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\wevtapi.dll"],["c:\\windows\\system32\\wpc.dll"],["c:\\windows\\system32\\samlib.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\program files\\mozilla firefox\\softokn3.dll"],["c:\\program files\\mozilla firefox\\freebl3.dll"]]}}},{"rowId":"1fb773f5-009a-4983-b1c3-605a50c2011b","rowData":{"threatLevel":0,"values":[4088,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.27.1974456774\\1577446857\" -childID 4 -isForBrowser -prefsHandle 7520 -prefMapHandle 7532 -prefsLen 7844 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 7496 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\dwrite.dll"]]}}},{"rowId":"e2dc5228-d0f0-44fb-83b5-f1a671aafc23","rowData":{"threatLevel":0,"values":[4028,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"2572.28.685725478\\288459427\" -childID 5 -isForBrowser -prefsHandle 7508 -prefMapHandle 7512 -prefsLen 7844 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 2572 \"\\\\.\\pipe\\gecko-crash-server-pipe.2572\" 7544 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","0","83.0"],"modules":[["c:\\program files\\mozilla firefox\\firefox.exe"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\program files\\mozilla firefox\\mozglue.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\wintrust.dll"],["c:\\windows\\system32\\dbghelp.dll"],["c:\\program files\\mozilla firefox\\msvcp140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-runtime-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\ucrtbase.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-localization-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-processthreads-l1-1-1.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-timezone-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-file-l2-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-core-synch-l1-2-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-string-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-heap-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-stdio-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-convert-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-locale-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\vcruntime140.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-math-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-time-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-filesystem-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-environment-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-utility-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\api-ms-win-crt-multibyte-l1-1-0.dll"],["c:\\program files\\mozilla firefox\\nss3.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\wsock32.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\program files\\mozilla firefox\\lgpllibs.dll"],["c:\\program files\\mozilla firefox\\xul.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\dwmapi.dll"],["c:\\windows\\system32\\dxgi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\avrt.dll"],["c:\\windows\\system32\\d3d11.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\uxtheme.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\wtsapi32.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\dhcpcsvc.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\program files\\mozilla firefox\\d3dcompiler_47.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\napinsp.dll"],["c:\\windows\\system32\\nlaapi.dll"],["c:\\windows\\system32\\pnrpnsp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\winrnr.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\dwrite.dll"]]}}}]},"registryActivity":{"stats":[{"name":"Total events","value":"12 581"},{"name":"Read events","value":"11 965"},{"name":"Write events","value":"597"},{"name":"Delete events","value":"19"}],"modificationEvents":[{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1033","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1041","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1046","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1036","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1031","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1040","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1049","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"3082","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1042","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1055","value":"Off"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1033","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1046","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1036","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1031","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1040","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1041","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1049","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"3082","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1042","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\LanguageResources\\EnabledLanguages","name":"1055","value":"On"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"0o6","value":"306F36002C040000010000000000000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook","name":"MTTT","value":"2C0400000441C7978709D80100000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\SQM","name":"SQMSessionNumber","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\SQM","name":"SQMSessionDate","value":"221443200"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\AutoDiscover\\RedirectServers","name":"autodiscover-s.outlook.com","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\0a0d020000000000c000000000000046","name":"00030429","value":"03000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\9375CFF0413111d3B88A00104B2A6676","name":"{ED475418-B0D6-11D2-8C3B-00104B2A6676}","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\9375CFF0413111d3B88A00104B2A6676","name":"LastChangeVer","value":"1200000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109A10090400000000000F01FEC\\Usage","name":"OutlookMAPI2Intl_1033","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"LanguageList","value":"en-US"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"C:\\Windows\\system32,@tzres.dll,-2670","value":"(UTC+00:00) Dublin, Edinburgh, Lisbon, London"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"C:\\Windows\\system32,@tzres.dll,-262","value":"GMT Standard Time"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"C:\\Windows\\system32,@tzres.dll,-261","value":"GMT Daylight Time"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109D30000000000000000F01FEC\\Usage","name":"OUTLOOKFiles","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109D30000000000000000F01FEC\\Usage","name":"ProductFiles","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109D30000000000000000F01FEC\\Usage","name":"WORDFiles","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\9207f3e0a3b11019908b08002b2a56c2","name":"01023d11","value":"25D50E0DF9991942B4230F340501590B23F38B6EE8974A40BA16AF7A0CC96702"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"@%SystemRoot%\\system32\\mlang.dll,-4608","value":"Unicode"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10021400000000000F01FEC\\Usage","name":"StemmerFiles_1042","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"bq6","value":"627136002C040000040000000000000096000000010000008E000000430043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C0045006D00610069006C002E0064006F0074006D00000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"bq6","value":"627136002C040000040000000000000096000000010000008E000000430043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C0045006D00610069006C002E0064006F0074006D00000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"0o6","value":"306F36002C040000010000000000000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete key","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"(default)","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\0a0d020000000000c000000000000046","name":"000b046b","value":"0000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\9375CFF0413111d3B88A00104B2A6676","name":"LastChangeVer","value":"1300000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\9375CFF0413111d3B88A00104B2A6676","name":"LastChangeVer","value":"1400000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"9s6","value":"397336002C040000020000000000000000010000010000008C0000006800000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0063006F006C006C006500610067007500650069006D0070006F00720074002E0064006C006C0000006D006900630072006F0073006F006600740020007300680061007200650070006F0069006E0074002000730065007200760065007200200063006F006C006C0065006100670075006500200069006D0070006F007200740020006100640064002D0069006E000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"9s6","value":"397336002C040000020000000000000000010000010000008C0000006800000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0063006F006C006C006500610067007500650069006D0070006F00720074002E0064006C006C0000006D006900630072006F0073006F006600740020007300680061007200650070006F0069006E0074002000730065007200760065007200200063006F006C006C0065006100670075006500200069006D0070006F007200740020006100640064002D0069006E000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"is6","value":"697336002C0400000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"is6","value":"697336002C0400000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"ys6","value":"797336002C0400000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"ys6","value":"797336002C0400000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109A10090400000000000F01FEC\\Usage","name":"OUTLOOKFilesIntl_1033","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Resiliency\\StartupItems","name":"'s6","value":"277336002C0400000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\SocialConnector","name":"CleanupFolder","value":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\{4E3A6965-17F1-4243-B49B-74EE32AFF6A3}"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\SocialConnector","name":"AlertTypes","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\SocialConnector","name":"RestartsSinceAlerts","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\SocialConnector","name":"AlertInsertStrings","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\SocialConnector","name":"PeoplePaneModeInspector","value":"3"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings","name":"ProxyEnable","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections","name":"SavedLegacySettings","value":"460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Content","name":"CachePrefix","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Cookies","name":"CachePrefix","value":"Cookie:"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\History","name":"CachePrefix","value":"Visited:"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"ProxyBypass","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"IntranetName","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"UNCAsIntranet","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"AutoDetect","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{362E934C-743B-4588-8259-D2482DB771A8}","name":"WpadDecisionReason","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{362E934C-743B-4588-8259-D2482DB771A8}","name":"WpadDecisionTime","value":"4E729B988709D801"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{362E934C-743B-4588-8259-D2482DB771A8}","name":"WpadDecision","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{362E934C-743B-4588-8259-D2482DB771A8}","name":"WpadNetworkName","value":"Network 4"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\52-54-00-36-3e-ff","name":"WpadDecisionReason","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\52-54-00-36-3e-ff","name":"WpadDecisionTime","value":"4E729B988709D801"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\52-54-00-36-3e-ff","name":"WpadDecision","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Identities","name":"Identity Ordinal","value":"2"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\24B3A62F61238241880F5E6F5085144E","name":"WriterId","value":"4744375"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\24B3A62F61238241880F5E6F5085144E","name":"LastModification","value":"D0BEC2805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\24B3A62F61238241880F5E6F5085144E","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889A88001000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\CF14372EFC763840BAC11A8C1F0B8F44","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\CF14372EFC763840BAC11A8C1F0B8F44","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\CF14372EFC763840BAC11A8C1F0B8F44","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889AA8001000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\5BFF177DE1D85041B599A808F99C8815","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\5BFF177DE1D85041B599A808F99C8815","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\5BFF177DE1D85041B599A808F99C8815","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889AC8001000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C98EFDA14604C34D9F23EFEC5C5AF89D","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C98EFDA14604C34D9F23EFEC5C5AF89D","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C98EFDA14604C34D9F23EFEC5C5AF89D","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889AE8001000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\0a0d020000000000c000000000000046","name":"00030487","value":"5CF9320D"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C2489E4FCD9F344E952D5800C66FE0C6","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C2489E4FCD9F344E952D5800C66FE0C6","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\C2489E4FCD9F344E952D5800C66FE0C6","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889A08011000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\6AC9CC0241A99E41A18862DF1C01B9C6","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\6AC9CC0241A99E41A18862DF1C01B9C6","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\6AC9CC0241A99E41A18862DF1C01B9C6","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889A28011000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\D0570303DBB6284D87B3DC07F3A99AAB","name":"WriterId","value":"4744390"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\D0570303DBB6284D87B3DC07F3A99AAB","name":"LastModification","value":"D02FC5805A48D401"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Perf\\RoamingStreamsCache\\D0570303DBB6284D87B3DC07F3A99AAB","name":"MsgEID","value":"00000000EE353A6753D116479D0919B95E8B889A48011000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Search","name":"C:\\Users\\admin\\Documents\\Outlook Files\\Outlook Data File - NoMail.pst","value":"3690740"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\Licensing","name":"CFF13DD86EF249EBB265E3BFC6501C1D","value":"01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security","name":"OutlookSecureTempFolder","value":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Outlook\\KNXSWUMK\\"},{"pid":"(1068) OUTLOOK.EXE","operation":"delete value","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Word","name":"FontInfoCacheW","value":"6000000060000000F5FFFFFF000000000000000000000000BC02000000000000004000225400610068006F006D006100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D0000000B000000020000000200000000000000060000001A000000BC0200000000000060000000600000002000FDFF1F0020000000002700000000FF2E00E15B6000C0290000000000000001000000000028200700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D0000000B0000000200000002000000000000000500000017000000900100000000000060000000600000002000FDFF1F0020000000002700000000FF2E00E15B6000C02900000000000000010000000000282006000000F7FFFFFF0000000000000000000000009001000000000000004000225400610068006F006D006100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B000000090000000200000002000000000000000400000013000000900100000000000060000000600000002000FDFF1F0020000000002700000000FF2E00E15B6000C02900000000000000010000000000282005000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\3517490d76624c419a828607e2a54604","name":"001f6000","value":"4E006F004D00610069006C000000"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Ami R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Arial Unicode MS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Batang","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@BatangChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@DFKai-SB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Dotum","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@DotumChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Expo M","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@FangSong","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Gulim","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@GulimChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Gungsuh","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@GungsuhChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Headline R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGMaruGothicMPRO","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGPSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSeikaishotaiPRO","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HGSSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYGothic-Extra","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYGothic-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYGraphic-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYGungSo-Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYHeadLine-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYMyeongJo-Extra","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYPMokGak-Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYPost-Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYPost-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYShortSamul-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@HYSinMyeongJo-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@KaiTi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Magic R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Malgun Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Meiryo","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Meiryo UI","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Microsoft JhengHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Microsoft YaHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MingLiU","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MingLiU_HKSCS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MingLiU_HKSCS-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MingLiU-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MoeumT R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MS Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MS Mincho","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MS PGothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MS PMincho","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@MS UI Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@New Gulim","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@NSimSun","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@PMingLiU","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@PMingLiU-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Pyunji R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@SimHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@SimSun","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@SimSun-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"@Yet R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Agency FB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Aharoni","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Algerian","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Ami R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Andalus","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Angsana New","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"AngsanaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Aparajita","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arabic Typesetting","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arial","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arial Black","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arial Narrow","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arial Rounded MT Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Arial Unicode MS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Baskerville Old Face","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Batang","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"BatangChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bauhaus 93","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bell MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Berlin Sans FB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Berlin Sans FB Demi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bernard MT Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Blackadder ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bodoni MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bodoni MT Black","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bodoni MT Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bodoni MT Poster Compressed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Book Antiqua","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bookman Old Style","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bookshelf Symbol 7","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Bradley Hand ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Britannic Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Broadway","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Browallia New","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"BrowalliaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Brush Script MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Calibri","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Calibri Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Californian FB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Calisto MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Cambria","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Cambria Math","value":"1"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Candara","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Castellar","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Centaur","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Century","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Century Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Century Schoolbook","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Chiller","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Colonna MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Comic Sans MS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Consolas","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Constantia","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Cooper Black","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Copperplate Gothic Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Copperplate Gothic Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Corbel","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Cordia New","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"CordiaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Courier","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Courier New","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Curlz MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"DaunPenh","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"David","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"DFKai-SB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"DilleniaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"DokChampa","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Dotum","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"DotumChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Ebrima","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Edwardian Script ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Elephant","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Engravers MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Eras Bold ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Eras Demi ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Eras Light ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Eras Medium ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Estrangelo Edessa","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"EucrosiaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Euphemia","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Expo M","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"FangSong","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Felix Titling","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Fixedsys","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Footlight MT Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Forte","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Book","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Demi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Demi Cond","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Heavy","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Franklin Gothic Medium Cond","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"FrankRuehl","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"FreesiaUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Freestyle Script","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"French Script MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gabriola","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Garamond","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gautami","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Georgia","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gigi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gill Sans MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gill Sans MT Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gill Sans MT Ext Condensed Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gill Sans Ultra Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gill Sans Ultra Bold Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gisha","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gloucester MT Extra Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Goudy Old Style","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Goudy Stout","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gulim","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"GulimChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Gungsuh","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"GungsuhChe","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Haettenschweiler","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Harlow Solid Italic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Harrington","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Headline R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGMaruGothicMPRO","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGPSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSeikaishotaiPRO","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSGothicE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSGothicM","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSGyoshotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSKyokashotai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSMinchoB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSMinchoE","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSSoeiKakugothicUB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSSoeiKakupoptai","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HGSSoeiPresenceEB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"High Tower Text","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYGothic-Extra","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYGothic-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYGraphic-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYGungSo-Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYHeadLine-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYMyeongJo-Extra","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYPMokGak-Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYPost-Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYPost-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYShortSamul-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"HYSinMyeongJo-Medium","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Impact","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Imprint MT Shadow","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Informal Roman","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"IrisUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Iskoola Pota","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"JasmineUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Jokerman","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Juice ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"KaiTi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Kalinga","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Kartika","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Khmer UI","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"KodchiangUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Kokila","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Kristen ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Kunstler Script","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lao UI","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Latha","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Leelawadee","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Levenim MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"LilyUPC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Bright","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Calligraphy","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Console","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Fax","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Handwriting","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Sans","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Sans Typewriter","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Lucida Sans Unicode","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Magic R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Magneto","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Maiandra GD","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Malgun Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Mangal","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Marlett","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Matura MT Script Capitals","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Meiryo","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Meiryo UI","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft Himalaya","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft JhengHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft New Tai Lue","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft PhagsPa","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft Sans Serif","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft Tai Le","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft Uighur","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft YaHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Microsoft Yi Baiti","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MingLiU","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MingLiU_HKSCS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MingLiU_HKSCS-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MingLiU-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Miriam","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Miriam Fixed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Mistral","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Modern No. 20","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MoeumT R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Mongolian Baiti","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Monotype Corsiva","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MoolBoran","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Mincho","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Outlook","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS PGothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS PMincho","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Reference Sans Serif","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Reference Specialty","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Sans Serif","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS Serif","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MS UI Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MT Extra","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"MV Boli","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Narkisim","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"New Gulim","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Niagara Engraved","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Niagara Solid","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"NSimSun","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Nyala","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"OCR A Extended","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"OCRB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Old English Text MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Onyx","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Palace Script MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Palatino Linotype","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Papyrus","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Parchment","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Perpetua","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Perpetua Titling MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Plantagenet Cherokee","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Playbill","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"PMingLiU","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"PMingLiU-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Poor Richard","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Pristina","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Pyunji R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Raavi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Rage Italic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Ravie","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Rockwell","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Rockwell Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Rockwell Extra Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Rod","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Sakkal Majalla","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Script MT Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe Print","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe Script","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe UI","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe UI Light","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe UI Semibold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Segoe UI Symbol","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Shonar Bangla","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Showcard Gothic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Shruti","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"SimHei","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Simplified Arabic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Simplified Arabic Fixed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"SimSun","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"SimSun-ExtB","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Small Fonts","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Snap ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Stencil","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Sylfaen","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Symbol","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"System","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tahoma","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tempus Sans ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Terminal","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Times New Roman","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Traditional Arabic","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Trebuchet MS","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tunga","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tw Cen MT","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tw Cen MT Condensed","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Tw Cen MT Condensed Extra Bold","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Utsaah","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Vani","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Verdana","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Vijaya","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Viner Hand ITC","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Vivaldi","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Vladimir Script","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Vrinda","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Webdings","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Wide Latin","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Wingdings","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Wingdings 2","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Wingdings 3","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Common\\MathFonts","name":"Yet R","value":"0"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F100A0C00000000000F01FEC\\Usage","name":"SpellingAndGrammarFiles_3082","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F100C0400000000000F01FEC\\Usage","name":"SpellingAndGrammarFiles_1036","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10090400000000000F01FEC\\Usage","name":"SpellingAndGrammarFiles_1033","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10061400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1046","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10031400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1043","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10070400000000000F01FEC\\Usage","name":"SpellingAndGrammarFiles_1031","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10010400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1025","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10001400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1040","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10022400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp2_1058","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10091400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1049","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10065400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp2_1110","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F100D2400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp2_1069","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10030400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp2_1027","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F10021400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp6_1042","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00004109F100F1400000000000F01FEC\\Usage","name":"SpellingAndGrammarFilesExp1_1055","value":""},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\IAM","name":"Server ID","value":"2"},{"pid":"(2752) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Launcher","name":"C:\\Program Files\\Mozilla Firefox\\firefox.exe|Launcher","value":"03C7D1CC60000000"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Launcher","name":"C:\\Program Files\\Mozilla Firefox\\firefox.exe|Browser","value":"4FCFD1CC60000000"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Launcher","name":"C:\\Program Files\\Mozilla Firefox\\firefox.exe|Telemetry","value":"0"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\DllPrefetchExperiment","name":"C:\\Program Files\\Mozilla Firefox\\firefox.exe","value":"0"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Default Browser Agent","name":"C:\\Program Files\\Mozilla Firefox|DisableTelemetry","value":"1"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Default Browser Agent","name":"C:\\Program Files\\Mozilla Firefox|DisableDefaultBrowserAgent","value":"0"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Default Browser Agent","name":"C:\\Program Files\\Mozilla Firefox|ServicesSettingsServer","value":"https://firefox.settings.services.mozilla.com/v1"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Default Browser Agent","name":"C:\\Program Files\\Mozilla Firefox|SecurityContentSignatureRootHash","value":"97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings","name":"ProxyEnable","value":"0"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections","name":"SavedLegacySettings","value":"460000003C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8649A000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"},{"pid":"(2572) firefox.exe","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\16C\\52C64B7E","name":"LanguageList","value":"en-US"},{"pid":"(1068) OUTLOOK.EXE","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\NoMail\\0a0d020000000000c000000000000046","name":"000b0340","value":"0100"}]},"filesActivity":{"stats":[{"name":"Executable files","value":"0"},{"name":"Suspicious files","value":"87"},{"name":"Text files","value":"42"},{"name":"Unknown types","value":"15"}],"droppedFiles":[{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\CVR2B80.tmp.cvr","md5":"—","sha256":"—","type":{}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\Documents\\Outlook Files\\Outlook Data File - NoMail.pst","md5":"—","sha256":"—","type":{}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-current.bin","md5":"—","sha256":"—","type":{}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_RssRule_2_C98EFDA14604C34D9F23EFEC5C5AF89D.dat","md5":"D8B37ED0410FB241C283F72B76987F18","sha256":"31E68049F6B7F21511E70CD7F2D95B9CF1354CF54603E8F47C1FC40F40B7A114","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_ContactPrefs_2_C2489E4FCD9F344E952D5800C66FE0C6.dat","md5":"BBCF400BD7AE536EB03054021D6A6398","sha256":"383020065C1F31F4FB09F448599A6D5E532C390AF4E5B8AF0771FE17A23222AD","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Templates\\~$rmalEmail.dotm","md5":"72DFD89675A42581F728F0EEF67ED657","sha256":"E87DDE6DE70047086A13216F73C2BD8FB69D623AE5E9D47751AA290C5283D67A","type":{"value":"pgc","type":4}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\outlook logging\\firstrun.log","md5":"106B697DF4CB0DDE0EF28B14216EC5AD","sha256":"EE62AB399996F9A07B7AC9E1F5EE8EFDCB7A4B3A49661BC9E4EBB49E2E72B301","type":{"value":"text","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\mapisvc.inf","md5":"F3B25701FE362EC84616A93A45CE9998","sha256":"B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209","type":{"value":"text","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\{4E3A6965-17F1-4243-B49B-74EE32AFF6A3}\\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png","md5":"4C61C12EDBC453D7AE184976E95258E1","sha256":"296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F","type":{"value":"image","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_AvailabilityOptions_2_CF14372EFC763840BAC11A8C1F0B8F44.dat","md5":"EEAA832C12F20DE6AAAA9C7B77626E72","sha256":"C4C9A90F2C961D9EE79CF08FBEE647ED7DE0202288E876C7BAAD00F4CA29CA16","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_WorkHours_1_5BFF177DE1D85041B599A808F99C8815.dat","md5":"807EF0FC900FEB3DA82927990083D6E7","sha256":"4411E7DC978011222764943081500FFF0E43CBF7CCD44264BD1AB6306CA68913","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_Calendar_2_24B3A62F61238241880F5E6F5085144E.dat","md5":"B21ED3BD946332FF6EBC41A87776C6BB","sha256":"B1AAC4E817CD10670B785EF8E5523C4A883F44138E50486987DC73054A46F6F4","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_ConversationPrefs_2_6AC9CC0241A99E41A18862DF1C01B9C6.dat","md5":"57F30B1BCA811C2FCB81F4C13F6A927B","sha256":"612BAD93621991CB09C347FF01EC600B46617247D5C041311FF459E247D8C2D3","type":{"value":"xml","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_TCPrefs_2_D0570303DBB6284D87B3DC07F3A99AAB.dat","md5":"F194B1FA12F9B6F46A47391FAE8BEEC2","sha256":"FCD8D7E030BE6EA7588E5C6CB568E3F1BDFC263942074B693942A27DF9521A74","type":{"value":"xml","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite","md5":"—","sha256":"—","type":{}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Outlook\\KNXSWUMK\\FX-Mary kirk-54266316-54266316.htm","md5":"D6B7E9F745A97CD8FCBFA67A8336AF9C","sha256":"DC2A558AB6C67829DC9891DFC21E6B00ED034DBED40297F671BC725FA21C7B93","type":{"value":"html","type":0}},{"pid":1068,"process":"OUTLOOK.EXE","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Outlook\\KNXSWUMK\\FX-Mary kirk-54266316-54266316.htm:Zone.Identifier","md5":"FBCCF14D504B7B2DBCB5A5BDA75BD93B","sha256":"EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913","type":{"value":"text","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\prefs-1.js","md5":"45EF9A4166EDA02F826E4C88805DA4D7","sha256":"A92F489DB14813CC58287734FB24A245254098D1EFEB743F2BB8C8EDFB53F7C9","type":{"value":"text","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache-current.bin","md5":"994A33896BB41A278A315D0D796422B6","sha256":"54EC50A20FFF8CC016710E49437CF6A11D3FE5EE7B28C185E4A9AAFEE2908B63","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cookies.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionCheckpoints.json","md5":"EA8B62857DFDBD3D0BE7D7E4A954EC9A","sha256":"792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\places.sqlite-wal","md5":"6701786A42060F725A48F69D6D34D1F5","sha256":"F7A437C7F32AB24DD61671AD3DC3F9FC1F2FF6EE5D32106F68A132A9214F4D3B","type":{"value":"sqlite-wal","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\prefs.js","md5":"45EF9A4166EDA02F826E4C88805DA4D7","sha256":"A92F489DB14813CC58287734FB24A245254098D1EFEB743F2BB8C8EDFB53F7C9","type":{"value":"text","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionCheckpoints.json.tmp","md5":"EA8B62857DFDBD3D0BE7D7E4A954EC9A","sha256":"792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_a18ceDCl0uEhnUw","md5":"69944FDC91FFA75783ED9AA59A12FB5C","sha256":"0ECF22BF6A99E8EAB58653A88F7291583172368C1A4C679B0F6070E57360B073","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1451318868ntouromlalnodry--epcr.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite-wal","md5":"39681B8E9420B4BA3DB499F0D149F93A","sha256":"28ECE969A3339E9E2963E55F1479399DF7203F205B810B01B5DC13701403FEDC","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3561288849sdhlie.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\search.json.mozlz4.tmp","md5":"B17F8D93B0C43D6B72DC03752C20A2D9","sha256":"ADA0F70D374223FB63C2F19471FAB45D986A681E2485692E63F00F5071F19D76","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\addonStartup.json.lz4.tmp","md5":"01DAE35763819EE4C2BD72553B33C337","sha256":"674E499CCF7E955DEFFEB21B94C092DE0A8EA1DD308C426DCF04BC84DBDFA377","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\QLDYZ5~1.DEF\\cert9.db-journal","md5":"85ED9588410F78E6BF33BCB52B0BF70D","sha256":"51F8B2BDB5879CDB158984F6FE020B51D80BD11D979E256586E1C0680F9181BE","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\QLDYZ5~1.DEF\\cert9.db","md5":"9B0DC7D0F9F7CA765F2520926A1AC875","sha256":"859BC0057D819E083F50B10836F91096E434DB703CFF92B704F98A87CE29CFBF","type":{"value":"sqlite","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\search.json.mozlz4","md5":"B17F8D93B0C43D6B72DC03752C20A2D9","sha256":"ADA0F70D374223FB63C2F19471FAB45D986A681E2485692E63F00F5071F19D76","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2823318777ntouromlalnodry--naod.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\settings\\main\\ms-language-packs\\asrouter.ftl.tmp","md5":"3625F1DDA6D119478AD89D13950C9ACA","sha256":"CB40F6A8D58901D612A86690A41D4E273F24936FC926E98F82C0918CBEF4FC64","type":{"value":"text","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\addonStartup.json.lz4","md5":"01DAE35763819EE4C2BD72553B33C337","sha256":"674E499CCF7E955DEFFEB21B94C092DE0A8EA1DD308C426DCF04BC84DBDFA377","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\settings\\main\\ms-language-packs\\asrouter.ftl","md5":"3625F1DDA6D119478AD89D13950C9ACA","sha256":"CB40F6A8D58901D612A86690A41D4E273F24936FC926E98F82C0918CBEF4FC64","type":{"value":"text","type":0}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto.vlpset","md5":"—","sha256":"—","type":{}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto-1.vlpset","md5":"—","sha256":"—","type":{}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\recovery.jsonlz4","md5":"FCC9B12DC90062C80F6AF2C3310EF77B","sha256":"06637FF88BA829EB3BDA57F429D62AC37236A39D98BA9A939FEC22516BDB90C3","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_LsacsWlBdFzCi78","md5":"F5645E561334909DEE513598046BC76E","sha256":"B5FFC294C878C8A052D845FB40D10CCA1B3E0A9C041F964972F19FFA88AFDF66","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.files\\1","md5":"B4DDF33E1DC200BE3FFE7BA3A6FD9F3C","sha256":"D148685CE5590081B04DC0014A8F5B074AE16E65C5728AFCFDE5757896A37550","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_YeNEnRparWPrrqW","md5":"19DB3CCFCE2DA754F1BACC0D3CC96383","sha256":"579D8989BBB5A1D99F6B392B43B87867D50738601292481DA0FD46EFE8C12884","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-downloadwhite-proto.metadata","md5":"1EF5E829303A139CE967440E0CDCA10C","sha256":"98CE42DEEF51D40269D542F5314BEF2C7468D401AD5D85168BFAB4C0108F75F7","type":{"value":"abr","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\recovery.jsonlz4.tmp","md5":"FCC9B12DC90062C80F6AF2C3310EF77B","sha256":"06637FF88BA829EB3BDA57F429D62AC37236A39D98BA9A939FEC22516BDB90C3","type":{"value":"jsonlz4","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto.metadata","md5":"53553242D57214AAA5726A09B05FE7BC","sha256":"1BE2B3990B410CA4FB38D1F79019C4018CD8820B69618646C81D22DFCBDDC802","type":{"value":"abr","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto.vlpset","md5":"D6FE27E6FA4C59AE30F10D3ED3C4E643","sha256":"1E4376B6D787AAF51254B1D04124E5F1734FB0209D3B28096228657E6AEEAAC2","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_x7kiPzPBDVj9jaB","md5":"949CD1A9B1184DFF0CEFBC489F798495","sha256":"3EBFA421A21D650A46A0B1850BFCF44E919E63B5D67431BF3E6900AAC7FFB1CC","type":{"value":"mpg","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_B0k6rLql4trW2an","md5":"F56C8CBC4229F51334EC7F1D8B1DDFAB","sha256":"77954144217CC22929856A27379A337E5494D748422554B5D835DF262C14649D","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-downloadwhite-proto.vlpset","md5":"EA86E0097B81FDBDEE3F12AC90CA6410","sha256":"6A242B62530E38DDCFD272643F6CC44EDC0208C69DC3022D6CC273F4C7E79AF8","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto.metadata","md5":"53553242D57214AAA5726A09B05FE7BC","sha256":"1BE2B3990B410CA4FB38D1F79019C4018CD8820B69618646C81D22DFCBDDC802","type":{"value":"abr","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto-1.vlpset","md5":"1771828C3D3AB11DA28008F4D80E0D7A","sha256":"C309B54EE8E0CA735CB99E9669CE140C673065149FF8648DDE1EC5025705A508","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto.vlpset","md5":"6C7BD66A4404B7128ED3CDB1E071827D","sha256":"3C91EC10984682B15DDAC25FFE9E70359FA28B8878AA701E75EB235004445629","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto-1.vlpset","md5":"115566BDF49858C98B4A1B110CF6463E","sha256":"A49542481A579C3944B50A5AE6875405E1EE5CEC4E6C7F1B79AEB0E6CE13E079","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto.metadata","md5":"53553242D57214AAA5726A09B05FE7BC","sha256":"1BE2B3990B410CA4FB38D1F79019C4018CD8820B69618646C81D22DFCBDDC802","type":{"value":"abr","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite-wal","md5":"—","sha256":"—","type":{}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto-1.vlpset","md5":"0F60A117D4A5462F18C51B30B5F1CA1B","sha256":"C43C724AE3F9A937D8E87E8AFA288EB2EB4B280F087B599989941CCBDAC14EE7","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto.metadata","md5":"53553242D57214AAA5726A09B05FE7BC","sha256":"1BE2B3990B410CA4FB38D1F79019C4018CD8820B69618646C81D22DFCBDDC802","type":{"value":"abr","type":4}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto.vlpset","md5":"E4FE13A7FB7B2F22B44B786D234FB402","sha256":"2B22D4F40C144D94634D04421F41F9BD5E99134DD1B901A85247A1E81F22357C","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-downloadwhite-proto-1.vlpset","md5":"B0272F5CF9F56F11C856155DC5F40BE1","sha256":"74AB81A1929A8806D559A13140947F076CABA52BF882364C416EF4D8E9B155F4","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-child-new.bin","md5":"8780B0A03FCE30A4EC3FF093FF1EA50F","sha256":"87CBAA08A5DA06F81783BA8E0B99111AAFB6F0A73649BBA9EC5B51F7FA9B7970","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache-new.bin","md5":"187E7A7401DC9107FC2005F68F2F999D","sha256":"E93774B9FD577F80E134AB22AE1984FA3142DFDD596FC577822B5B846B022CA3","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\broadcast-listeners.json","md5":"521ACE7C66AAA7290BD8D493DC5AF462","sha256":"227B3889D25BF76B0E73EC12D31229FB650A7FDF5ECC12FA1E31F4A454F499A6","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\broadcast-listeners.json.tmp","md5":"521ACE7C66AAA7290BD8D493DC5AF462","sha256":"227B3889D25BF76B0E73EC12D31229FB650A7FDF5ECC12FA1E31F4A454F499A6","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache.bin","md5":"187E7A7401DC9107FC2005F68F2F999D","sha256":"E93774B9FD577F80E134AB22AE1984FA3142DFDD596FC577822B5B846B022CA3","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-child.bin","md5":"8780B0A03FCE30A4EC3FF093FF1EA50F","sha256":"87CBAA08A5DA06F81783BA8E0B99111AAFB6F0A73649BBA9EC5B51F7FA9B7970","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozplugin-block-digest256.sbstore","md5":"519BEB1B01FC355BB388F1F75BE997FD","sha256":"FFE2D3077B81AE6F51B220C1C661B276C823FA67DAD1D64FC5F17249FC54BDC0","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozplugin-block-digest256.vlpset","md5":"FCC9C2C9B611A3264B68EBE180EB4248","sha256":"6ECD378A537EEFE350B45CFA353741383F407D99D776BF23155A7825DC5DD2BC","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-track-digest256.sbstore","md5":"59D2D3A9FF42621AE974078BCAABD9BC","sha256":"7371E8534C31C4BFF73E340413D77C988593A0E559418B0F2A5B34B9C82DDDD2","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\analytics-track-digest256.vlpset","md5":"1E1C0442F3FE16B185D5DB74F0E91FCE","sha256":"43ACC2D047C7988E9073ECF32AC619DE0D080C45B061D441D1D671D305BB4F08","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\ads-track-digest256.sbstore","md5":"A03E51212AD01CFE7EB3A87C8CE51744","sha256":"2328A7569AB3D1E0C8638282E09860C82DB28EDD1C1BE75CAAD91FC7015E966C","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\content-track-digest256.vlpset","md5":"897401403F6A9BBC2727BF8ACFA8BBAF","sha256":"75157865105C44C1220C337AEFF723E7B2E4AEF506CE7DB00E2621D5CEAF45B8","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-track-digest256.vlpset","md5":"E1EDDE17E24B61C5B26D7B76BA039463","sha256":"C2C4612B7B9545751F37B302EE345ABD0F22170C7CC2497320897B385D508B7F","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\ads-track-digest256.vlpset","md5":"38F55098AB1772E8A7B90A05CB33CFAE","sha256":"FD44A8121E20CF102D8FD79D6EE45D55CCB0D92893907091BB7587ED3B274244","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\content-track-digest256.sbstore","md5":"2BE5027A476EFB5FE011AE8257E6B428","sha256":"26D0EF7103DBC0516ADD2DA8029CA43567B98BDA1EF8D8E4CDA42F09AA9A4B36","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\analytics-track-digest256.sbstore","md5":"AE706ABFAECFD90D67E5C965091E004E","sha256":"13CBF8A5389A33A562E6DD10660F68E8964313536A109AA80ACFD8838BF45E73","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozstd-trackwhite-digest256.vlpset","md5":"C8663695A49BB5FB5A301D1A7233DB6C","sha256":"498D10D381ED91BE12CFF65292813BCCCD676176BCF614534AB7BA0E5536306E","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozstd-trackwhite-digest256.sbstore","md5":"92A93E4C81027F5788873296C6E2875B","sha256":"4358B8F0AF157CF2EF36A3A8BD152A528D32CFE98A2E0AE66207DBDB1D943EFA","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google-trackwhite-digest256.vlpset","md5":"E54E5B84194EEE15E64D2A03F1136BB7","sha256":"07707B589BE3DBA3BB0BDAC67760A2B180EA3531E9D7976B73E4C1D8DF9DBB1E","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google-trackwhite-digest256.sbstore","md5":"FEC9BC354A7EE92C6FEEFE63E6B0FA26","sha256":"258EF8E6994A09FFB54BD0D5AFEC97C13C31F2EEFB7FE90A2A4C487C87817519","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashallow-digest256.sbstore","md5":"DD0458514C9A922B45DA6A8BEBE47320","sha256":"D27D5B27030F4725249377951BEB89E84A90A0E8241F0D5FD80EA59C1606E761","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashallow-digest256.vlpset","md5":"7194B6BFF691A056852A51E2E06CE8FE","sha256":"CBE2DC6ABFE25BEAD60F4DFAF419FC0F441FF8A8DD4A2FEBF5553BE1CBD90C49","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\allow-flashallow-digest256.sbstore","md5":"DD0458514C9A922B45DA6A8BEBE47320","sha256":"D27D5B27030F4725249377951BEB89E84A90A0E8241F0D5FD80EA59C1606E761","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\allow-flashallow-digest256.vlpset","md5":"DE0D88480C24350C59E1E9A3583DE0D1","sha256":"01BA9F0B913E04ED10BD7166796483DD4F72005F249D6EE68B12117BE4B5D3C7","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flash-digest256.sbstore","md5":"9F6B331AA1E070DCFEED473E76CE56C3","sha256":"7DBBEA2DD387EEB85E1F56E02FC9989ACDE570CD43BFEF2C2A827093BA87DA6D","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flash-digest256.vlpset","md5":"130B9AC2BEEC5ADA274561105D81AE36","sha256":"7D99FEC08182A5B95D18D1569EDAA2C60C2AAFBD15A56D8882F22F3B395E6460","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flash-digest256.sbstore","md5":"D5D6B4D59B4AE4E2DE4B40D0DA083571","sha256":"000E3A78C72A210CA3B5417A3CDD294FBCE2A31661601C9D594C75CF2800571C","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flashsubdoc-digest256.vlpset","md5":"40165280FF1345B5241EC2A9D1DA2AF0","sha256":"F80BDD5341D8B1EE946E344E258EF2D35C3C0BB6B13EB7B3E6A77467DFA8B97F","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flash-digest256.vlpset","md5":"C2994D388F8780C87D35C352D9582985","sha256":"7ED09F7D2BD632F70077A4AE4F2BD2F3FB654B03CD72652F51678B0C7D027F25","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-fingerprinting-track-digest256.sbstore","md5":"DAA7ABDB5ED1DBF8877F4028092E32F6","sha256":"B8F20B14AD5291B4528DF859129B301F367A9885F417F9807821D5A386352530","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-fingerprinting-track-digest256.vlpset","md5":"FA7667EEED0B53973506278ECE958E62","sha256":"0D55A21E6694FCE19F366F9E5351A02D215D378541DBC38DF68645B63B56D8BF","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-cryptomining-track-digest256.sbstore","md5":"D6C5C2E242DF3EC5FF8E17DD8EE15F73","sha256":"F0C6512E42F2732B3AA401F9AB4DF84C0A89C9755968B158796706A48B9F492A","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashsubdoc-digest256.sbstore","md5":"22698B4CF784DBBAE2D583F00491D43D","sha256":"3849563088AE0677D61702A1310FDE26DE5DDD846D53037222D3EFE012197BF5","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flashsubdoc-digest256.sbstore","md5":"B9556D03AFF392142AD5691D2F867310","sha256":"CFD3909B41C1EE3CBCB8B7D2B1378065E7D3B543FFF1F2FB7A4F25C5FF41722C","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-facebook-digest256.sbstore","md5":"58FBC7F7687CC8798AEA35B7066EB198","sha256":"3A2035AD8446C71242DAA9EAF3818B87F673D0429E4F5334621905B47A1C3DF5","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashsubdoc-digest256.vlpset","md5":"0C0D67875BD75A0227C02DD8529BA01A","sha256":"614BE0169EC36E67223EB9645A98DA66DBFDE5DFBB89BB064F428AAEABDD9D97","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-cryptomining-track-digest256.vlpset","md5":"7D532B89A987D92DEF1D7AABBAAD62AB","sha256":"7CB574BE3E783D6876740DBCA525D868677307A52DDDD67AC84665CCFAAE895E","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-facebook-digest256.vlpset","md5":"86B1ACDBF1FC7201D0EB7C85EE75F5AF","sha256":"A0F4C83316CD66525F663CD72A2DC8BD1B2AA2E40D599B8B6F334D61C5D03098","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-linkedin-digest256.vlpset","md5":"3303AA4BCB02D27F1A8B6AFF30C1DD9C","sha256":"6F33CCFCF9767B612657242C2819C325CFDF17B8D92224DB588A886F7EC2D26E","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-twitter-digest256.vlpset","md5":"35D8FD43D868D7BBA7041362EB8101B3","sha256":"104C2467E4F7BC7CAC0CE0E456D5ABD8C192C2C8C44F7C9A38412A59ABDD1772","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-linkedin-digest256.sbstore","md5":"3B11B562807FEF504FE671DED4D0E8CE","sha256":"9BF05ADC119CDD219347572787A9B7E18308C4465A8F440C34C697B2F5CD479F","type":{"value":"binary","type":1}},{"pid":2572,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-tracking-protection-twitter-digest256.sbstore","md5":"373411CEBF6E3BCB89D8BFA632409BF1","sha256":"C1D5B95B18FF02514BDA0EC7865D9468C3A89E5C3BA2EBD3D4284FD8FCD463D4","type":{"value":"binary","type":1}}]},"synchronization":{"values":[]},"rpsRequests":{"values":[]},"networkActivity":{"stats":[{"name":"HTTP(S) requests","value":"10"},{"name":"TCP/UDP connections","value":"60"},{"name":"DNS requests","value":"82"},{"name":"Threats","value":"2"}],"requests":[[1068,"OUTLOOK.EXE","GET","—","64.4.26.155:80","http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig","US",{"value":null},"—",{"value":"shared","type":0}],[2572,"firefox.exe","GET",200,"34.107.221.82:80","http://detectportal.firefox.com/success.txt","US",{"value":"text","type":0},"8 b",{"value":"whitelisted","type":3}],[2572,"firefox.exe","POST",200,"142.250.186.35:80","http://ocsp.pki.goog/gts1c3","US",{"value":"der","type":4},"471 b",{"value":"whitelisted","type":3}],[2572,"firefox.exe","POST",200,"142.250.186.35:80","http://ocsp.pki.goog/gts1c3","US",{"value":"der","type":4},"471 b",{"value":"whitelisted","type":3}],[2572,"firefox.exe","POST",200,"142.250.186.35:80","http://ocsp.pki.goog/gts1c3","US",{"value":"der","type":4},"471 b",{"value":"whitelisted","type":3}],[2572,"firefox.exe","POST",200,"142.250.186.35:80","http://ocsp.pki.goog/gts1c3","US",{"value":"der","type":4},"471 b",{"value":"whitelisted","type":3}],[2572,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[2572,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[2572,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[2572,"firefox.exe","GET",200,"34.107.221.82:80","http://detectportal.firefox.com/success.txt?ipv4","US",{"value":"text","type":0},"8 b",{"value":"whitelisted","type":3}]],"connections":[[2572,"firefox.exe","34.107.221.82:80","detectportal.firefox.com","—","US",{"value":"whitelisted","type":3}],[1068,"OUTLOOK.EXE","64.4.26.155:80","config.messenger.msn.com","Microsoft Corporation","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","13.32.121.96:443","firefox.settings.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[2572,"firefox.exe","104.16.18.94:443","cdnjs.cloudflare.com","Cloudflare Inc","US",{"value":"suspicious","type":1}],[2572,"firefox.exe","142.250.186.42:443","ajax.googleapis.com","Google Inc.","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","52.42.77.140:443","location.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[2572,"firefox.exe","142.250.184.202:443","fonts.googleapis.com","Google Inc.","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","142.250.186.35:80","ocsp.pki.goog","Google Inc.","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","104.18.10.207:443","maxcdn.bootstrapcdn.com","Cloudflare Inc","US",{"value":"suspicious","type":1}],[2572,"firefox.exe","104.21.78.7:443","use.fontawesome.com","Cloudflare Inc","US",{"value":"suspicious","type":1}],[2572,"firefox.exe","69.16.175.42:443","code.jquery.com","Highwinds Network Group, Inc.","US",{"value":"malicious","type":2}],[2572,"firefox.exe","13.32.121.5:443","firefox-settings-attachments.cdn.mozilla.net","Amazon.com, Inc.","US",{"value":"suspicious","type":1}],["—","—","13.32.121.96:443","firefox.settings.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[2572,"firefox.exe","93.184.220.29:80","ocsp.digicert.com","MCI Communications Services, Inc. d/b/a Verizon Business","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","142.250.186.106:443","safebrowsing.googleapis.com","Google Inc.","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","34.213.133.213:443","push.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[2572,"firefox.exe","18.65.116.99:443","content-signature-2.cdn.mozilla.net","Massachusetts Institute of Technology","US",{"value":"unknown","type":4}],[2572,"firefox.exe","172.67.223.7:443","todosec.org","—","US",{"value":"suspicious","type":1}],["—","—","142.250.186.35:80","ocsp.pki.goog","Google Inc.","US",{"value":"whitelisted","type":3}],[2572,"firefox.exe","13.32.121.15:443","snippets.cdn.mozilla.net","Amazon.com, Inc.","US",{"value":"suspicious","type":1}],[2572,"firefox.exe","13.107.246.44:443","aadcdn.msauth.net","Microsoft Corporation","US",{"value":"malicious","type":2}],[2572,"firefox.exe","54.190.2.244:443","shavar.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],["—","—","54.190.2.244:443","shavar.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[2572,"firefox.exe","18.66.97.122:443","tracking-protection.cdn.mozilla.net","Massachusetts Institute of Technology","US",{"value":"unknown","type":4}],["—","—","93.184.220.29:80","ocsp.digicert.com","MCI Communications Services, Inc. d/b/a Verizon Business","US",{"value":"whitelisted","type":3}]],"dns":[["config.messenger.msn.com",["64.4.26.155"],{"value":"shared","type":0}],["detectportal.firefox.com",["34.107.221.82"],{"value":"whitelisted","type":3}],["prod.detectportal.prod.cloudops.mozgcp.net",["34.107.221.82","2600:1901:0:38d7::"],{"value":"whitelisted","type":3}],["example.org",["93.184.216.34"],{"value":"shared","type":0}],["ipv4only.arpa",["192.0.0.170","192.0.0.171"],{"value":"whitelisted","type":3}],["firefox.settings.services.mozilla.com",["13.32.121.96","13.32.121.70","13.32.121.7","13.32.121.6"],{"value":"whitelisted","type":3}],["location.services.mozilla.com",["52.42.77.140","52.89.115.53","35.163.137.0","35.163.35.154","52.11.104.45","52.26.7.9"],{"value":"shared","type":0}],["locprod2-elb-us-west-2.prod.mozaws.net",["52.26.7.9","52.11.104.45","35.163.35.154","35.163.137.0","52.89.115.53","52.42.77.140"],{"value":"whitelisted","type":3}],["ajax.googleapis.com",["142.250.186.42","2a00:1450:4001:829::200a"],{"value":"whitelisted","type":3}],["code.jquery.com",["69.16.175.42","69.16.175.10"],{"value":"whitelisted","type":3}],["fonts.googleapis.com",["142.250.184.202","2a00:1450:4001:830::200a"],{"value":"whitelisted","type":3}],["use.fontawesome.com",["104.21.78.7","172.67.214.69"],{"value":"whitelisted","type":3}],["aadcdn.msauth.net",["13.107.246.44","13.107.213.44"],{"value":"whitelisted","type":3}],["cdnjs.cloudflare.com",["104.16.18.94","104.16.19.94","2606:4700::6810:135e","2606:4700::6810:125e"],{"value":"whitelisted","type":3}],["maxcdn.bootstrapcdn.com",["104.18.10.207","104.18.11.207","2606:4700::6812:bcf","2606:4700::6812:acf"],{"value":"whitelisted","type":3}],["cds.s5x3j6q5.hwcdn.net",["69.16.175.10","69.16.175.42","2001:4de0:ac18::1:a:2b","2001:4de0:ac18::1:a:1a","2001:4de0:ac18::1:a:1b","2001:4de0:ac18::1:a:3a","2001:4de0:ac18::1:a:2a","2001:4de0:ac18::1:a:3b"],{"value":"whitelisted","type":3}],["use.fontawesome.com.cdn.cloudflare.net",["172.67.214.69","104.21.78.7","2606:4700:3031::ac43:d645","2606:4700:3037::6815:4e07"],{"value":"whitelisted","type":3}],["part-0016.t-0009.t-msedge.net",["13.107.213.44","13.107.246.44","2620:1ec:bdf::44","2620:1ec:46::44"],{"value":"malicious","type":2}],["ocsp.pki.goog",["142.250.186.35"],{"value":"whitelisted","type":3}],["pki-goog.l.google.com",["142.250.186.35","2a00:1450:4001:827::2003"],{"value":"whitelisted","type":3}],["ocsp.digicert.com",["93.184.220.29"],{"value":"shared","type":0}],["cs9.wac.phicdn.net",["93.184.220.29"],{"value":"whitelisted","type":3}],["content-signature-2.cdn.mozilla.net",["18.65.116.99","18.65.116.85","18.65.116.14","18.65.116.40","13.32.99.117","13.32.99.100","13.32.99.116","13.32.99.50"],{"value":"whitelisted","type":3}],["d2nxq2uap88usk.cloudfront.net",["18.65.116.40","18.65.116.14","18.65.116.85","18.65.116.99","2600:9000:225e:bc00:a:da5e:7900:93a1","2600:9000:225e:f800:a:da5e:7900:93a1","2600:9000:225e:7600:a:da5e:7900:93a1","2600:9000:225e:2400:a:da5e:7900:93a1","2600:9000:225e:2e00:a:da5e:7900:93a1","2600:9000:225e:4800:a:da5e:7900:93a1","2600:9000:225e:b400:a:da5e:7900:93a1","2600:9000:225e:e200:a:da5e:7900:93a1","13.32.99.50","13.32.99.116","13.32.99.100","13.32.99.117"],{"value":"shared","type":0}],["safebrowsing.googleapis.com",["142.250.186.106","2a00:1450:4001:829::200a"],{"value":"whitelisted","type":3}],["push.services.mozilla.com",["34.213.133.213"],{"value":"shared","type":0}],["autopush.prod.mozaws.net",["34.213.133.213"],{"value":"whitelisted","type":3}],["todosec.org",["172.67.223.7","104.21.78.148","2606:4700:3031::ac43:df07","2606:4700:3035::6815:4e94"],{"value":"whitelisted","type":3}],["firefox-settings-attachments.cdn.mozilla.net",["13.32.121.5","13.32.121.102","13.32.121.84","13.32.121.24"],{"value":"whitelisted","type":3}],["fennec-catalog-cdn.prod.mozaws.net",["13.32.121.24","13.32.121.84","13.32.121.102","13.32.121.5"],{"value":"shared","type":0}],["snippets.cdn.mozilla.net",["13.32.121.15","13.32.121.85","13.32.121.49","13.32.121.112"],{"value":"whitelisted","type":3}],["d228z91au11ukj.cloudfront.net",["13.32.121.112","13.32.121.49","13.32.121.85","13.32.121.15"],{"value":"whitelisted","type":3}],["www.youtube.com",["142.250.186.46","142.250.186.78","142.250.186.110","142.250.186.142","142.250.186.174","142.250.184.206","142.250.184.238","216.58.212.142","142.250.185.78","142.250.185.110","142.250.185.142","142.250.185.174","142.250.185.206","142.250.185.238","172.217.18.110","142.250.181.238"],{"value":"shared","type":0}],["www.facebook.com",["185.60.216.35"],{"value":"whitelisted","type":3}],["www.ebay.de",["2.18.234.244"],{"value":"whitelisted","type":3}],["star-mini.c10r.facebook.com",["185.60.216.35","2a03:2880:f12d:83:face:b00c:0:25de"],{"value":"whitelisted","type":3}],["youtube-ui.l.google.com",["142.250.181.238","172.217.18.110","142.250.185.238","142.250.185.206","142.250.185.174","142.250.185.142","142.250.185.110","142.250.185.78","216.58.212.142","142.250.184.238","142.250.184.206","142.250.186.174","142.250.186.142","142.250.186.110","142.250.186.78","142.250.186.46","2a00:1450:4001:813::200e","2a00:1450:4001:809::200e","2a00:1450:4001:82f::200e","2a00:1450:4001:808::200e"],{"value":"whitelisted","type":3}],["e11847.a.akamaiedge.net",["2.18.234.244"],{"value":"whitelisted","type":3}],["www.wikipedia.org",["91.198.174.192"],{"value":"shared","type":0}],["www.reddit.com",["151.101.1.140","151.101.65.140","151.101.129.140","151.101.193.140"],{"value":"whitelisted","type":3}],["reddit.map.fastly.net",["151.101.193.140","151.101.129.140","151.101.65.140","151.101.1.140"],{"value":"whitelisted","type":3}],["dyna.wikimedia.org",["91.198.174.192","2620:0:862:ed1a::1"],{"value":"whitelisted","type":3}],["shavar.services.mozilla.com",["54.190.2.244","34.217.152.155","52.89.81.52","34.211.175.209","34.213.195.39","34.216.66.163"],{"value":"whitelisted","type":3}],["shavar.prod.mozaws.net",["34.216.66.163","34.213.195.39","34.211.175.209","52.89.81.52","34.217.152.155","54.190.2.244"],{"value":"whitelisted","type":3}],["tracking-protection.cdn.mozilla.net",["18.66.97.122","18.66.97.19","18.66.97.117","18.66.97.89"],{"value":"whitelisted","type":3}],["d1zkz3k4cclnv6.cloudfront.net",["18.66.97.89","18.66.97.117","18.66.97.19","18.66.97.122"],{"value":"shared","type":0}]],"threatsProCount":0,"threats":[[2572,"firefox.exe",{"value":"Potentially Bad Traffic","type":1},"ET INFO Terse Request for .txt - Likely Hostile"],[2572,"firefox.exe",{"value":"Potentially Bad Traffic","type":1},"ET INFO Terse Request for .txt - Likely Hostile"]]},"debugOutputStrings":{"values":[]},"meta":{"sha256":"90e58e654d07bb2f13b6ebe3ca124098c61da1c503500606a0fc8addf204bb76","uuid":"47ca32b6-ef4b-49b9-896b-ea3defb4f056","isUrlType":false,"taskName":"Potential Phish_ _External Email_ New Encrypted Fax Notification.msg","title":"Free Malware Sandbox Online","isPrivate":false,"tags":[],"copyrightYear":2022},"vue_isInlineMode":false,"vue_publicPath":"/report/"}
We're sorry but any.run reports doesn't work properly without JavaScript enabled. Please enable it to continue.
General Info Add for printing
File name: Potential Phish_ _External Email_ New Encrypted Fax Notification.msg Full analysis: https://app.any.run/tasks/47ca32b6-ef4b-49b9-896b-ea3defb4f056 Verdict: Malicious activity Analysis date: January 14, 2022, 20:44:53 OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) Indicators: MIME: application/vnd.ms-outlook File info: CDFV2 Microsoft Outlook Message MD5: 9E5D490DA83A5E847A03F0473C11C5B5 SHA1: 557C1FFAEB5A515429B0FB143747802757E23650 SHA256: 90E58E654D07BB2F13B6EBE3CA124098C61DA1C503500606A0FC8ADDF204BB76 SSDEEP: 3072:B1ImZAENr2G69FXvQRNnbBWHg1HFqXvQ7:xNiGWWRNMaHF7
ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is.
ANY.RUN does not guarantee maliciousness or safety of the content.
Software environment set and analysis options Launch configuration Task duration: 60 seconds Heavy Evasion option: off Network geolocation: off Additional time used: none MITM proxy: off Privacy: Public submission Fakenet option: off Route via Tor: off Autoconfirmation of UAC: on Network: on Processes Add for printing
Behavior graph Click at the process to see the details
start
outlook.exe
firefox.exe
no specs
firefox.exe
firefox.exe
no specs
firefox.exe
no specs
firefox.exe
no specs
firefox.exe
no specs
firefox.exe
no specs
firefox.exe
no specs
- +
Specs description Program did not start Low-level access to the HDD Process was added to the startup Debug information is available Probably Tor was used Behavior similar to spam Task has injected processes Executable file was dropped Known threat RAM overrun Network attacks were detected Integrity level elevation Connects to the network CPU overrun Process starts the services System was rebooted Task contains several apps running Application downloaded the executable file Actions similar to stealing personal data Task has apps ended with an error File is detected by antivirus software Inspected object has suspicious PE structure Behavior similar to exploiting the vulnerability Task contains an error or was rebooted The process has the malware config Process information
Network activity Add for printing
HTTP requests Download PCAP, analyze network streams, HTTP content and a lot more at the
full report Connections
DNS requests