General Info

File name

d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2

Full analysis
https://app.any.run/tasks/dd0a94ba-4271-4ae0-9474-6abfe2745228
Verdict
Malicious activity
Analysis date
3/14/2019, 15:40:26
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adload
loader
pup
trojan
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

379ed04ec69bbdb50c19038e757a28e8

SHA1

22296564d28f226435b08059a1526bcab60af3a4

SHA256

d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2

SSDEEP

49152:cfKk+wEyCXcHubb0MiPn1+dPc6V62ILb5UcpXONo0ZHYd0U8b3qJ7sK1o7VKECiq:Jk+nXd2v1CkVb5RpH0ZHM0e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • MailRuUpdater.exe (PID: 4064)
  • na_runner.exe (PID: 1416)
  • schtasks.exe (PID: 2580)
  • schtasks.exe (PID: 2256)
  • schtasks.exe (PID: 2168)
Application was dropped or rewritten from another process
  • MailRuUpdater.exe (PID: 1156)
  • MailRuUpdater.exe (PID: 3092)
  • MailRuUpdater.exe (PID: 2892)
  • MailRuUpdater.exe (PID: 4064)
  • 047b-1a0a-326d-bfac (PID: 2472)
  • mrupdsrv.exe (PID: 3356)
  • MailRuUpdater.exe (PID: 3724)
  • MailRuUpdater.exe (PID: 2788)
  • smappscontroller.exe (PID: 3756)
  • na_runner.exe (PID: 1416)
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe (PID: 3032)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
  • 412076AD-CD08-4F14-99EA-8629F29A6063.exe (PID: 2124)
  • E3B87877-10F6-4536-9523-42DAE1F68021.exe (PID: 2428)
Changes the autorun value in the registry
  • MailRuUpdater.exe (PID: 4064)
  • na_runner.exe (PID: 1416)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Loads dropped or rewritten executable
  • regsvr32.exe (PID: 2716)
  • E3B87877-10F6-4536-9523-42DAE1F68021.exe (PID: 2428)
Changes Windows auto-update feature
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Registers / Runs the DLL via REGSVR32.EXE
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
MAILRU was detected
  • MailRuUpdater.exe (PID: 2788)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Connects to CnC server
  • MailRuUpdater.exe (PID: 2788)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
Uses Task Scheduler to run other applications
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Downloads executable files from the Internet
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
ADLOAD was detected
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
Removes files from Windows directory
  • MailRuUpdater.exe (PID: 2892)
  • MailRuUpdater.exe (PID: 2788)
Executable content was dropped or overwritten
  • MailRuUpdater.exe (PID: 4064)
  • MailRuUpdater.exe (PID: 3724)
  • MailRuUpdater.exe (PID: 2788)
  • regsvr32.exe (PID: 2716)
  • 047b-1a0a-326d-bfac (PID: 2472)
  • na_runner.exe (PID: 1416)
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe (PID: 3032)
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
  • E3B87877-10F6-4536-9523-42DAE1F68021.exe (PID: 2428)
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
Starts itself from another location
  • MailRuUpdater.exe (PID: 4064)
  • na_runner.exe (PID: 1416)
Creates a software uninstall entry
  • MailRuUpdater.exe (PID: 4064)
  • na_runner.exe (PID: 1416)
Creates files in the Windows directory
  • MailRuUpdater.exe (PID: 2788)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
  • mrupdsrv.exe (PID: 3356)
Creates files in the program directory
  • na_runner.exe (PID: 1416)
  • 047b-1a0a-326d-bfac (PID: 2472)
  • MailRuUpdater.exe (PID: 3724)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Changes the started page of IE
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Creates files in the user directory
  • MailRuUpdater.exe (PID: 3724)
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
  • E3B87877-10F6-4536-9523-42DAE1F68021.exe (PID: 2428)
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Starts application with an unusual extension
  • MailRuUpdater.exe (PID: 2788)
Creates COM task schedule object
  • regsvr32.exe (PID: 2716)
Uses TASKKILL.EXE to kill process
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Reads the cookies of Mozilla Firefox
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Reads the cookies of Google Chrome
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Reads Windows owner or organization settings
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Reads the Windows organization settings
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Changes tracing settings of the file or console
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
Searches for installed software
  • d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe (PID: 3780)
  • smappscontroller.exe (PID: 3756)
Dropped object may contain Bitcoin addresses
  • 854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe (PID: 3560)
Reads settings of System Certificates
  • MailRuUpdater.exe (PID: 3724)
Application was dropped or rewritten from another process
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Loads dropped or rewritten executable
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Creates files in the program directory
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)
Creates a software uninstall entry
  • DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp (PID: 2928)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:03:21 13:44:17+01:00
PEType:
PE32
LinkerVersion:
12
CodeSize:
294400
InitializedDataSize:
6119424
UninitializedDataSize:
null
EntryPoint:
0x255da
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
8.0.1.28153
ProductVersionNumber:
8.0.0.0
FileFlagsMask:
0x003f
FileFlags:
Pre-release
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
CompanyName:
Blizzard Entertainment
FileDescription:
World of Warcraft Voice Proxy
FileVersion:
8, 0, 1, 28153
InternalName:
WowVoiceProxy.exe
LegalCopyright:
Copyright © 2018 Blizzard Entertainment
OriginalFileName:
WowVoiceProxy.exe
ProductName:
World of Warcraft
ProductVersion:
Version 8.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
21-Mar-2016 12:44:17
Detected languages
English - United States
CompanyName:
Blizzard Entertainment
FileDescription:
World of Warcraft Voice Proxy
FileVersion:
8, 0, 1, 28153
InternalName:
WowVoiceProxy.exe
LegalCopyright:
Copyright © 2018 Blizzard Entertainment
OriginalFilename:
WowVoiceProxy.exe
ProductName:
World of Warcraft
ProductVersion:
Version 8.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
9
Time date stamp:
21-Mar-2016 12:44:17
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00047D11 0x00047E00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.52305
.rdata 0x00049000 0x0000AE84 0x0000B000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.7263
.data 0x00054000 0x059A9CEC 0x0009CC00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.51993
.y0e19 0x059FE000 0x000C88C0 0x000C8A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.02616
.6thocl 0x05AC7000 0x00202A38 0x00202C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.91526
.6e7r 0x05CCA000 0x000B6358 0x000B6400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.04734
.5ch39 0x05D81000 0x0013E3F0 0x0013E400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.27886
.e6n954 0x05EC0000 0x00049160 0x00049200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.90839
.rsrc 0x05F0A000 0x00025323 0x00025400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.0826
Resources
1

2

3

4

5

6

7

8

9

Imports
    KERNEL32.dll

    WININET.dll

Exports

    No exports.

Screenshots

Processes

Total processes
62
Monitored processes
22
Malicious processes
10
Suspicious processes
0

Behavior graph

+
download and start download and start download and start download and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe no specs #ADLOAD d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe 412076ad-cd08-4f14-99ea-8629f29a6063.exe e3b87877-10f6-4536-9523-42dae1f68021.exe #MAILRU 854a0f92-0841-4f1d-a5e6-8850a44a9c19.exe db85f1cd-00d2-462d-aab4-fb49190c4608.exe db85f1cd-00d2-462d-aab4-fb49190c4608.tmp taskkill.exe no specs smappscontroller.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs na_runner.exe mailruupdater.exe #MAILRU mailruupdater.exe 047b-1a0a-326d-bfac mrupdsrv.exe regsvr32.exe mailruupdater.exe mailruupdater.exe mailruupdater.exe mailruupdater.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3268
CMD
"C:\Users\admin\AppData\Local\Temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe"
Path
C:\Users\admin\AppData\Local\Temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Blizzard Entertainment
Description
World of Warcraft Voice Proxy
Version
8, 0, 1, 28153
Modules
Image
c:\users\admin\appdata\local\temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
c:\systemroot\system32\ntdll.dll

PID
3780
CMD
"C:\Users\admin\AppData\Local\Temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe"
Path
C:\Users\admin\AppData\Local\Temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Version:
Company
Blizzard Entertainment
Description
World of Warcraft Voice Proxy
Version
8, 0, 1, 28153
Modules
Image
c:\users\admin\appdata\local\temp\d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\winmm.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\security.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\idndl.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\412076ad-cd08-4f14-99ea-8629f29a6063\412076ad-cd08-4f14-99ea-8629f29a6063.exe
c:\users\admin\appdata\local\temp\e3b87877-10f6-4536-9523-42dae1f68021\e3b87877-10f6-4536-9523-42dae1f68021.exe
c:\users\admin\appdata\local\temp\854a0f92-0841-4f1d-a5e6-8850a44a9c19\854a0f92-0841-4f1d-a5e6-8850a44a9c19.exe
c:\users\admin\appdata\local\temp\db85f1cd-00d2-462d-aab4-fb49190c4608\db85f1cd-00d2-462d-aab4-fb49190c4608.exe
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll

PID
2124
CMD
"C:\Users\admin\AppData\Local\Temp\412076AD-CD08-4F14-99EA-8629F29A6063\412076AD-CD08-4F14-99EA-8629F29A6063.exe" mode=s siteid=12257 campaignid=1 sourceid=112
Path
C:\Users\admin\AppData\Local\Temp\412076AD-CD08-4F14-99EA-8629F29A6063\412076AD-CD08-4F14-99EA-8629F29A6063.exe
Indicators
Parent process
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
"My Web Shield"
Description
My Web Shield Installation File
Version
3.0.0.0
Modules
Image
c:\users\admin\appdata\local\temp\412076ad-cd08-4f14-99ea-8629f29a6063\412076ad-cd08-4f14-99ea-8629f29a6063.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
2428
CMD
"C:\Users\admin\AppData\Local\Temp\E3B87877-10F6-4536-9523-42DAE1F68021\E3B87877-10F6-4536-9523-42DAE1F68021.exe" /sid=4 /pid=550612257
Path
C:\Users\admin\AppData\Local\Temp\E3B87877-10F6-4536-9523-42DAE1F68021\E3B87877-10F6-4536-9523-42DAE1F68021.exe
Indicators
Parent process
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\e3b87877-10f6-4536-9523-42dae1f68021\e3b87877-10f6-4536-9523-42dae1f68021.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsdb9a3.tmp\blowfish.dll
c:\users\admin\appdata\local\temp\nsdb9a3.tmp\nsprocess.dll
c:\users\admin\appdata\local\temp\nsdb9a3.tmp\inetc.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
3560
CMD
"C:\Users\admin\AppData\Local\Temp\854A0F92-0841-4F1D-A5E6-8850A44A9C19\854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe" --silent --install_browser_class=0 --pay_browser_class=0 "--rfr=hp.1:834408,dse.1:811570,vbm.1:811580,pult.1:811580,hp.2:834423,dse.2:811610,vbm.2:811620,pult.2:811620,any:811550,any.2:811590" "--install_callback=http://orienteering.site/api_v2/callback/?guid={guid}&br={browser}&comp={component}&paid={paid}&pb={paidBrowser}&pa={paidAction}&ibc={installBrowserClass}&pbc={payBrowserClass}&ur={unpaidActionReason}&browserclass1={browserClass1}&browserclass2={browserClass2}&rfr={rfr}&clid=205694811&dlid=323571615"
Path
C:\Users\admin\AppData\Local\Temp\854A0F92-0841-4F1D-A5E6-8850A44A9C19\854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
Indicators
Parent process
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
sputnik
Version
5.1.0.194
Modules
Image
c:\users\admin\appdata\local\temp\854a0f92-0841-4f1d-a5e6-8850a44a9c19\854a0f92-0841-4f1d-a5e6-8850a44a9c19.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\sxs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\mssprxy.dll
c:\users\admin\appdata\local\temp\435e-a331-f726-7df0\na_runner.exe
c:\windows\system32\gpedit.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\atl.dll
c:\windows\system32\dsuiext.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\dssec.dll
c:\windows\system32\authz.dll
c:\windows\system32\dfscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\framedynos.dll
c:\users\admin\appdata\local\mail.ru\gochromiumnativehost\native_host_app.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mydocs.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\regsvr32.exe
c:\windows\system32\thumbcache.dll

PID
3032
CMD
"C:\Users\admin\AppData\Local\Temp\DB85F1CD-00D2-462D-AAB4-FB49190C4608\DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe" /VERYSILENT /SUPPRESSMESSAGES
Path
C:\Users\admin\AppData\Local\Temp\DB85F1CD-00D2-462D-AAB4-FB49190C4608\DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe
Indicators
Parent process
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Smart Application Controller
Description
Smart Application Controller
Version
1.00
Modules
Image
c:\users\admin\appdata\local\temp\db85f1cd-00d2-462d-aab4-fb49190c4608\db85f1cd-00d2-462d-aab4-fb49190c4608.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-cvpsh.tmp\db85f1cd-00d2-462d-aab4-fb49190c4608.tmp

PID
2928
CMD
"C:\Users\admin\AppData\Local\Temp\is-CVPSH.tmp\DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp" /SL5="$10174,2554955,467456,C:\Users\admin\AppData\Local\Temp\DB85F1CD-00D2-462D-AAB4-FB49190C4608\DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe" /VERYSILENT /SUPPRESSMESSAGES
Path
C:\Users\admin\AppData\Local\Temp\is-CVPSH.tmp\DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
Indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-cvpsh.tmp\db85f1cd-00d2-462d-aab4-fb49190c4608.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-mvqnm.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\windows\system32\clbcatq.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\smart application controller\smappscontroller.exe
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netutils.dll

PID
3900
CMD
"C:\Windows\System32\taskkill.exe" /F /IM smappscontroller.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3756
CMD
"C:\Program Files\Smart Application Controller\smappscontroller.exe" -frominstaller -silent
Path
C:\Program Files\Smart Application Controller\smappscontroller.exe
Indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Smart Application Controller
Description
Smart Application Controller
Version
1.0.0.0
Modules
Image
c:\program files\smart application controller\smappscontroller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\winspool.drv
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\security.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\idndl.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\d3d10_1.dll
c:\windows\system32\d3d10_1core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_plugin.exe
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_pepper.exe
c:\program files\ccleaner\ccleaner.exe
c:\program files\filezilla ftp client\filezilla.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\notepad++\notepad++.exe
c:\program files\microsoft\skype for desktop\skype.exe
c:\program files\videolan\vlc\vlc.exe
c:\program files\winrar\winrar.exe
c:\programdata\package cache\{7e9fae12-5bbf-47fb-b944-09c49e75c061}\vc_redist.x86.exe
c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
c:\windows\system32\profapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2168
CMD
"C:\Windows\System32\schtasks.exe" /delete /f /tn "CheckControllerUpdatesCore"
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
2256
CMD
"C:\Windows\System32\schtasks.exe" /delete /f /tn "CheckControllerUpdatesUA"
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
2580
CMD
"C:\Windows\System32\schtasks.exe" /Create /TN "CheckControllerUpdatesUA" /XML "C:\Users\admin\AppData\Local\Temp\is-MVQNM.tmp\CheckControllerUpdatesUA.xml"
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
1416
CMD
"C:\Users\admin\AppData\Local\Temp\435e-a331-f726-7df0\na_runner.exe" --install
Path
C:\Users\admin\AppData\Local\Temp\435e-a331-f726-7df0\na_runner.exe
Indicators
Parent process
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.0.0.176
Modules
Image
c:\users\admin\appdata\local\temp\435e-a331-f726-7df0\na_runner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\mail.ru\mailruupdater.exe

PID
3724
CMD
"C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe"
Path
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
Indicators
Parent process
na_runner.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.0.0.176
Modules
Image
c:\users\admin\appdata\local\mail.ru\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\program files\google\chrome\application\chrome.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\mozilla firefox\firefox.exe
c:\users\admin\appdata\local\temp\dad9-1e1b-e0dd-3fbc
c:\windows\system32\apphelp.dll

PID
2788
CMD
"C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe" --s
Path
C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.0.0.176
Modules
Image
c:\program files\mail.ru\mailruupdater\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\apphelp.dll
c:\windows\temp\047b-1a0a-326d-bfac
c:\windows\temp\2fb2-8092-43e3-c6ab

PID
2472
CMD
"C:\Windows\TEMP\047b-1a0a-326d-bfac" --install
Path
C:\Windows\TEMP\047b-1a0a-326d-bfac
Indicators
Parent process
MailRuUpdater.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Mail.Ru
Description
Mail.Ru Update Service
Version
3.12.0.10
Modules
Image
c:\windows\temp\047b-1a0a-326d-bfac
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\winsta.dll

PID
3356
CMD
"C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe" --s
Path
C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Mail.Ru
Description
Mail.Ru Update Service
Version
3.12.0.10
Modules
Image
c:\program files\mail.ru\update service\mrupdsrv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll

PID
2716
CMD
"C:\Windows\System32\regsvr32.exe" /s "C:\Users\admin\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll"
Path
C:\Windows\System32\regsvr32.exe
Indicators
Parent process
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\mail.ru\sputnik\ie_addon_dll.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\atl.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
4064
CMD
"C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004_d\MailRuUpdater.exe" --update-installation
Path
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004_d\MailRuUpdater.exe
Indicators
Parent process
MailRuUpdater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.1.0.195
Modules
Image
c:\users\admin\appdata\local\mail.ru\mailruupdater\us\2d0cd78004_d\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\mail.ru\mailruupdater.exe

PID
2892
CMD
"C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\MailRuUpdater\us\336327ca85_d\MailRuUpdater.exe" --us
Path
C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\MailRuUpdater\us\336327ca85_d\MailRuUpdater.exe
Indicators
Parent process
MailRuUpdater.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
1
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.1.0.195
Modules
Image
c:\windows\system32\config\systemprofile\appdata\local\mail.ru\mailruupdater\us\336327ca85_d\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll

PID
3092
CMD
"C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe" --s
Path
C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.1.0.195
Modules
Image
c:\program files\mail.ru\mailruupdater\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll

PID
1156
CMD
"C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe"
Path
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
Indicators
No indicators
Parent process
MailRuUpdater.exe
User
admin
Integrity Level
HIGH
Version:
Company
Mail.Ru
Description
Mail.Ru updater
Version
5.1.0.195
Modules
Image
c:\users\admin\appdata\local\mail.ru\mailruupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

Registry activity

Total events
3878
Read events
2946
Write events
816
Delete events
116

Modification events

PID
Process
Operation
Key
Name
Value
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
quarantine
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
EnableFileTracing
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
EnableConsoleTracing
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
FileTracingMask
4294901760
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
ConsoleTracingMask
4294901760
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
MaxFileSize
1048576
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
FileDirectory
%windir%\tracing
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
EnableFileTracing
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
EnableConsoleTracing
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
FileTracingMask
4294901760
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
ConsoleTracingMask
4294901760
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
MaxFileSize
1048576
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASMANCS
FileDirectory
%windir%\tracing
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
quarantine
6-1552574463,8-1552574463,9-1552574463
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
installedcampaigns
910
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
quarantine
6-1552574463,8-1552574463,9-1552574463,10-1552574463
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
installedcampaigns
910,1116
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
installedcampaigns
910,1116,812
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
write
HKEY_CURRENT_USER\Software\Downloader
installedcampaigns
910,1116,812,1088
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
EnableFileTracing
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
EnableConsoleTracing
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
FileTracingMask
4294901760
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
ConsoleTracingMask
4294901760
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
MaxFileSize
1048576
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASAPI32
FileDirectory
%windir%\tracing
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
EnableFileTracing
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
EnableConsoleTracing
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
FileTracingMask
4294901760
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
ConsoleTracingMask
4294901760
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
MaxFileSize
1048576
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\412076AD-CD08-4F14-99EA-8629F29A6063_RASMANCS
FileDirectory
%windir%\tracing
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2124
412076AD-CD08-4F14-99EA-8629F29A6063.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\view
pid
550612257
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\view
sid
4
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
DontShowUI
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
EnableFileTracing
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
EnableConsoleTracing
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
FileTracingMask
4294901760
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
ConsoleTracingMask
4294901760
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
MaxFileSize
1048576
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASAPI32
FileDirectory
%windir%\tracing
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
EnableFileTracing
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
EnableConsoleTracing
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
FileTracingMask
4294901760
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
ConsoleTracingMask
4294901760
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
MaxFileSize
1048576
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\E3B87877-10F6-4536-9523-42DAE1F68021_RASMANCS
FileDirectory
%windir%\tracing
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech
UserID
{0A663502-9002-4CC1-BA54-6565D86EAD06}
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Favorites
007C01000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000007601000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C000000007801000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C00000000EE00000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4D7D5911005461736B426172003C0008000400EFBE454B864A1C4D7D592A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032007A0800001C4D59592000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C000000005201000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4DD15D11005461736B426172003C0008000400EFBE454B864A1C4DD15D2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200FB0600001C4DD05D20004F50455241317E312E4C4E4B0000540008000400EFBE1C4DD15D1C4DD15D2A000000E6C600000000010000000000000000000000000000004F007000650072006100310032002E0031003500200031003700340038002E006C006E006B0000001C007A0000001D00EFBE02007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004F0070006500720061005C006F0070006500720061002E0065007800650000001C000000005201000014001F80C827341F105C1042AA032EE45287D66852003100000000006E4E257511005461736B426172003C0008000400EFBE454B864A6E4E25752A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200950700006E4E237520004D41494C52557E312E4C4E4B0000440008000400EFBE6E4E25756E4E25752A0000009CDF00000000030000000000000000000000000000004D00610069006C002E00520075002E006C006E006B0000001C008A0000001D00EFBE02004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00440032003100380044004100330039002D0035004600340045002D0045003300390032002D0039003400310035002D004300320036004500380032003900330037003800350039007D0000001C000000FF
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesChanges
10
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesVersion
2
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
53
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
54
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
55
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
56
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
mailruhomesearch
"C:\Users\admin\AppData\Local\Mail.Ru\Sputnik\ptls\mailruhomesearch.exe" --pr_deferred
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7CB3A6B1-A811-443A-9486-500EB80CAFA8}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\iepoegkaoeljnbhagabakjodgpfniimo
update_url
https://clients2.google.com/service/update2/crx
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\beliehdniadoecbonbhlcgbdldccfigp
update_url
https://clients2.google.com/service/update2/crx
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B1B7A3F7-3E56-49F2-BB0C-E4B5FDB61194}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{B15BED25-AAB6-4224-8539-5C8F17B07F48}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ch\iepoegkaoeljnbhagabakjodgpfniimo
CB5E3106FC7418337191EFA58C2033C50BB0736198061855D5ED90D9CBADA630A9645DB463DB5E57CA3B7E75D9F9BDBF01E37BDDF3C4FACCA3EBF65A1DECF1D8F70F80C9623B9A128B9FB474E5E925A123B7C1DF527C822C84B85BDFDB534CF41A5643CE10251123673CEE56CAAE92F12121C849D4AC7463C6D73DE1756B280EA94B53E67E72C390E2C87CF4139DB04BBE96E8041281BF40B07313028683C51F4363FB22D446D45E33382B901205A14582E8D3F137604516C1883CA72AC787528F4A2D1B63A94B9A78E0E46F7EF0A61990F95F471309EE03695B200EF6080C889C4D94225029A6E6E05A41E9D884D8D3884F2E735C568282BDF476A8E675E277153AEFB9D68336EF1E4DECE8C2336D8F83627C1E157FCBE74F9B819121433BF817F0B13365520C5DADE2CBA63576B99C46C58A9F827A959C8C79EE89150E3F0DDB4C1C3B0FE0E2AC83DA05A46BBEE8DCE6AD2B15740F12006121E1E0DE48E0750EAB1A1638A4C970A0645D6B750730E600C1CD9E99F50E68F995B598661201193862F2956D0AE3C7E1D7FD5170BD29341F1E0C951A5812251D1A113A72C02C017F9C7530ECA1B3EA92981D4BF5F7340F9E6EA2B80FD9EEF3E5D34F9DEFA457CAB3981A7D1718777794D627176A8F3B628BF6943B8AF32533855FEDAA48AC95DA3064DB5CE0F5B3D2256C775E17AFD6658244E3C70CA5A4B0DE0791692E4719035EB62E9DB169F133
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ch\beliehdniadoecbonbhlcgbdldccfigp
CB5E3106FC7418337191EFA58C2033C50BB0736198061855D5ED90D9CBADA630A9645DB463DB5E57021C9B357709F46DFA2B09F33640195B90E1FB306DA4FF70C734119892E1E59B27126637FA33855869686A263BA5A97584B85BDFDB534CF41A5643CE10251123673CEE56CAAE92F12121C849D4AC7463C6D73DE1756B280EA94B53E67E72C390E2C87CF4139DB04BBE96E8041281BF40B07313028683C51F4363FB22D446D45E33382B901205A145C4BE501E7A4348F2C1883CA72AC787528F4A2D1B63A94B9A78E0E46F7EF0A61990F95F471309EE03695B200EF6080C889C4D94225029A6E6E05A41E9D884D8D3884F2E735C568282BDF476A8E675E277153AEFB9D68336EF1E4DECE8C2336D8F83627C1E157FCBE74F9B819121433BF817F0B13365520C5DADE2CBA63576B99C46C58A9F827A959C8C79EE89150E3F0DDB4C1C3B0FE0E2AC83DA05A46BBEE8DCE6AD2B15740F12006121E1E0DE48E0750EAB1A1638A4C970A0645D6B750730E600C1CD9E99F50E68F995B598661201193862F2956D0AE3C7E1D7FD5170BD29341F1E0C951A5812251D1A113A72C02C017F9C7530ECA1B3EA92981D4BF5F7340F9E6EA2B80FD9EEF3E5D34F9DEFA457CAB3981A7D17187777BA9F18AAA30D9A60DD058FA6F1E1F8C05F55D916287126594A301CD3D816CB0685E6D2E5C93E0ABE4A5F49B1CA9C0B33DE0791692E471903535E634B8D269B41
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\NativeMessagingHosts\ru.mail.go.ext_info_host
C:\Users\admin\AppData\Local\Mail.Ru\GoChromiumNativeHost\manifest.json
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech
avedte
5A36D0FE6048590997E3F11C1AB7B9E39C49A22308F19254A51B95A977597E83C3AFF6DB3BE504DD319E17DC4E71F1E2674C8CFF6BCC6C2D
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ff\[email protected]
7B22676F5F706172616D6574657273223A5B7B224964223A2270726F647563745F6964222C2256616C7565223A227B41424246424437382D313136462D343545412D423345392D4532434130374435314133357D227D2C7B224964223A22696E7374616C6C5F6964222C2256616C7565223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D227D2C7B224964223A226770222C2256616C7565223A22383131363130227D5D2C22696E7374616C6C5F6964223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D222C226D7264735F706172616D6574657273223A5B7B224964223A22696E7374616C6C6572222C2256616C7565223A22737075746E696B227D2C7B224964223A2262726F777365725F636C61737331222C2256616C7565223A66616C73657D2C7B224964223A2262726F777365725F636C61737332222C2256616C7565223A747275657D2C7B224964223A227061222C2256616C7565223A747275657D2C7B224964223A227064222C2256616C7565223A747275657D2C7B224964223A227062222C2256616C7565223A747275657D5D2C2270726F647563745F6964223A227B41424246424437382D313136462D343545412D423345392D4532434130374435314133357D222C22726672223A22383131363130227D0A
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ff\[email protected]
7B22676F5F706172616D6574657273223A5B7B224964223A2270726F647563745F6964222C2256616C7565223A227B32383532384644312D373944302D343635322D394441412D3730333339443246423341327D227D2C7B224964223A22696E7374616C6C5F6964222C2256616C7565223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D227D2C7B224964223A226770222C2256616C7565223A22383334343233227D5D2C22696E7374616C6C5F6964223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D222C226D7264735F706172616D6574657273223A5B7B224964223A22696E7374616C6C6572222C2256616C7565223A22737075746E696B227D2C7B224964223A2262726F777365725F636C61737331222C2256616C7565223A66616C73657D2C7B224964223A2262726F777365725F636C61737332222C2256616C7565223A747275657D2C7B224964223A227061222C2256616C7565223A747275657D2C7B224964223A227064222C2256616C7565223A747275657D2C7B224964223A227062222C2256616C7565223A747275657D5D2C2270726F647563745F6964223A227B32383532384644312D373944302D343635322D394441412D3730333339443246423341327D222C22726672223A22383334343233227D0A
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ff\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
7B22676F5F706172616D6574657273223A5B7B224964223A2270726F647563745F6964222C2256616C7565223A227B30453834463735332D324435302D343044422D393039432D3645444432414136413035447D227D2C7B224964223A22696E7374616C6C5F6964222C2256616C7565223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D227D2C7B224964223A226770222C2256616C7565223A22383131363230227D5D2C22696E7374616C6C5F6964223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D222C226D7264735F706172616D6574657273223A5B7B224964223A22696E7374616C6C6572222C2256616C7565223A22737075746E696B227D2C7B224964223A2262726F777365725F636C61737331222C2256616C7565223A66616C73657D2C7B224964223A2262726F777365725F636C61737332222C2256616C7565223A747275657D2C7B224964223A227061222C2256616C7565223A747275657D2C7B224964223A227064222C2256616C7565223A747275657D2C7B224964223A227062222C2256616C7565223A747275657D5D2C2270726F647563745F6964223A227B30453834463735332D324435302D343044422D393039432D3645444432414136413035447D222C22726672223A22383131363230227D0A
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mozilla\NativeMessagingHosts\ru.mail.go.ext_info_host
C:\Users\admin\AppData\Local\Mail.Ru\GoChromiumNativeHost\manifest_ff.json
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech
avedte
5A36D0FE6048590997E3F11C1AB7B9E39C49A22308F19254A51B95A977597E83C3AFF6DB3BE504DD319E17DC4E71F1E2484E7CDB6072C690
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C2D3933A-2937-4A85-946B-96FA38EB3992}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Approved Extensions
{8E8F97CD-60B5-456F-A201-73065652D099}
51667A6C4C1D3B1BDD889E9780330101B90A394657149585
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
DisplayName
Поиск@Mail.Ru
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
URL
https://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B9664489D-DC85-498D-A541-3191D713EF70%7D&gp=811610
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
FaviconURLFallback
https://go.mail.ru/favicon.ico
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
ShowSearchSuggestions
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
SuggestionsURL
https://suggests.go.mail.ru/ie8?q={searchTerms}
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
DefaultScope
{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Start Page
https://mail.ru/cnt/10445?gp=834423
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{C59D4E12-1990-4073-85D5-E4D058DB07AE}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
IncludeRecommendedUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AutoInstallMinorUpdates
0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows Defender
DisableAntiSpyware
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
DisableRealtimeMonitoring
1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}User
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows Defender
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{F15E1C54-E73A-4F31-94A0-86DC0992C206}Machine\Software\Policies\Microsoft\Windows Defender\Real-time Protection
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ExternalES\ie\{8E8F97CD-60B5-456F-A201-73065652D099}
7B22676F5F706172616D6574657273223A5B7B224964223A2270726F647563745F6964222C2256616C7565223A227B34443631313234322D324543362D344644302D424337452D3533384144464643383438427D227D2C7B224964223A22696E7374616C6C5F6964222C2256616C7565223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D227D2C7B224964223A226770222C2256616C7565223A22383131363130227D5D2C22696E7374616C6C5F6964223A227B38453830314445452D343836302D343737322D413031432D4335353143423346354245397D222C226D7264735F706172616D6574657273223A5B7B224964223A22696E7374616C6C6572222C2256616C7565223A22737075746E696B227D2C7B224964223A2262726F777365725F636C61737331222C2256616C7565223A66616C73657D2C7B224964223A2262726F777365725F636C61737332222C2256616C7565223A747275657D2C7B224964223A227061222C2256616C7565223A747275657D2C7B224964223A227064222C2256616C7565223A747275657D2C7B224964223A227062222C2256616C7565223A747275657D5D2C2270726F647563745F6964223A227B34443631313234322D324543362D344644302D424337452D3533384144464643383438427D222C22726672223A22383131363130227D0A
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech
avedte
5A36D0FE6048590997E3F11C1AB7B9E39C49A22308F19254A51B95A977597E83C3AFF6DB3BE504DD319E17DC4E71F1E29F59CBB38DB17E46
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
700B0000D81729F473DAD401
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
8AE14AB7C95DB7082FD58600B4799C3783A9D06E5D2B4A4ED13E80377D3E47E7
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\Smart Application Controller\smappscontroller.exe
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
DE156D5F0163B751170E79A6A4D836D0A91C2D784A36AC6F634BE718DB87A808
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Inno Setup: Setup Version
5.5.5 (u)
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Inno Setup: App Path
C:\Program Files\Smart Application Controller
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
InstallLocation
C:\Program Files\Smart Application Controller\
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Inno Setup: Icon Group
Smart Application Controller
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Inno Setup: User
admin
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Inno Setup: Language
russian
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
DisplayName
Smart Application Controller
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
DisplayIcon
C:\Program Files\Smart Application Controller\software_update.ico
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
UninstallString
"C:\Program Files\Smart Application Controller\unins000.exe"
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
QuietUninstallString
"C:\Program Files\Smart Application Controller\unins000.exe" /SILENT
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
DisplayVersion
1.00
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
Publisher
Smart Application Controller
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
NoModify
1
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
NoRepair
1
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
InstallDate
20190314
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
MajorVersion
1
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
MinorVersion
0
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6AE177E-D46B-4463-AA69-B9F818E0DC4A}_is1
EstimatedSize
11292
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3756
smappscontroller.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
smappscontroller.exe
3756
smappscontroller.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
EnableFileTracing
0
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
EnableConsoleTracing
0
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
FileTracingMask
4294901760
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
ConsoleTracingMask
4294901760
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
MaxFileSize
1048576
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASAPI32
FileDirectory
%windir%\tracing
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
EnableFileTracing
0
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
EnableConsoleTracing
0
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
FileTracingMask
4294901760
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
ConsoleTracingMask
4294901760
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
MaxFileSize
1048576
3756
smappscontroller.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\smappscontroller_RASMANCS
FileDirectory
%windir%\tracing
3756
smappscontroller.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3756
smappscontroller.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006C000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3756
smappscontroller.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3756
smappscontroller.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
na_runner.exe
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\AppDataLow\Software\Mail.Ru\IE_Bar\Settings
GUID
{D81E8409-F3CA-4DBA-8CE0-4D84A7C32066}
1416
na_runner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mail.Ru\Updater
GUID
{D81E8409-F3CA-4DBA-8CE0-4D84A7C32066}
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
UninstallString
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe uninstall
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
DisplayName
Служба автоматического обновления программ
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
Publisher
Mail.Ru
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
DisplayIcon
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
InstallLocation
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
VersionMajor
5
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
VersionMinor
0
1416
na_runner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MailRuUpdater
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
3724
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe
3724
MailRuUpdater.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3724
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{2AB1F4AB-E3FA-4047-9033-EC223C8354F5}
finished_time
1D688A5C00000000
3724
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{B202C093-6D9F-43F2-8B6C-44FC1583EFAF}
runid
10
3724
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Mail.Ru\Tech\ptls\{FC604959-8A01-4E8B-A3E5-87CEEBD6FEDB}
finished_time
1D688A5C00000000
2788
MailRuUpdater.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe
2788
MailRuUpdater.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2788
MailRuUpdater.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Mail.Ru\Tech\ptls\{84DC8324-C256-4EF5-B0DC-383B43EE77E9}\ready_items
waiter
1
2788
MailRuUpdater.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Mail.Ru\Tech\ptls\{84DC8324-C256-4EF5-B0DC-383B43EE77E9}
finished_time
22688A5C00000000
3356
mrupdsrv.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
MRSearchPlugin
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
NoExplorer
1
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
AppName
mrkeeper.exe
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
AppPath
C:\Users\admin\AppData\Local\Mail.Ru
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
Policy
3
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\InprocServer32
C:\Users\admin\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\InprocServer32
ThreadingModel
Apartment
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\Version
1.0
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\ProgID
IESearchPlugin.MailRuBHO.1
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\Name
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IESearchPlugin.MailRuBHO
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IESearchPlugin.MailRuBHO\CLSID
{8E8F97CD-60B5-456F-A201-73065652D099}
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IESearchPlugin.MailRuBHO\CurVer
IESearchPlugin.MailRuBHO.1
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IESearchPlugin.MailRuBHO.1
2716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IESearchPlugin.MailRuBHO.1\CLSID
{8E8F97CD-60B5-456F-A201-73065652D099}
2716
regsvr32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Approved Extensions
{8E8F97CD-60B5-456F-A201-73065652D099}
51667A6C4C1D3B1BDD88949382330308BA03384654109082
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
UninstallString
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe uninstall
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
DisplayName
Служба автоматического обновления программ
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
Publisher
Mail.Ru
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
DisplayIcon
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
InstallLocation
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
VersionMajor
5
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
VersionMinor
1
4064
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MailRuUpdater
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
2892
MailRuUpdater.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe
3092
MailRuUpdater.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe
1156
MailRuUpdater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
MailRuUpdater.exe

Files activity

Executable files
25
Suspicious files
24
Text files
253
Unknown types
19

Dropped files

PID
Process
Filename
Type
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
C:\Users\admin\AppData\Local\Temp\412076AD-CD08-4F14-99EA-8629F29A6063\412076AD-CD08-4F14-99EA-8629F29A6063.exe
executable
MD5: 489357ef15d52c5f62f31a798471f1ca
SHA256: 4dfaf07aabd8ec5831b2e9cccf2e6f40999a16d0e7c66ff84d13d9f87fd604a7
3032
DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe
C:\Users\admin\AppData\Local\Temp\is-CVPSH.tmp\DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
executable
MD5: 31d0b20289f542a33d197cfa7cdf4e4b
SHA256: 80a958710ef3ecd3c416f2a66af356070fcab5e63d3ebaf33fb574aa1b7f92c3
2472
047b-1a0a-326d-bfac
C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe
executable
MD5: 602cd1f0dd54e83de1413705aa378803
SHA256: 8eeef659d4d3e827474b4c769436807eafedf58dc923054338cb5385dc8d3998
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
C:\Users\admin\AppData\Local\Temp\DB85F1CD-00D2-462D-AAB4-FB49190C4608\DB85F1CD-00D2-462D-AAB4-FB49190C4608.exe
executable
MD5: d2fed2ae467dadadb7909fc6c1996d9c
SHA256: 7b470950a776abaf0fd0d04ed8a2bc98f3e983350c9ec112808d02da8cd1e70e
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
C:\Users\admin\AppData\Local\Temp\is-MVQNM.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
C:\Users\admin\AppData\Local\Temp\854A0F92-0841-4F1D-A5E6-8850A44A9C19\854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
executable
MD5: a29c9f523b47027fb97190b908c18979
SHA256: 25ceeaed228c2d7c08bad41362ad6619c243324ad8a0e05c75d3672e96373bed
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll
executable
MD5: 8c1c71d39137c7a7b2b9bdfe6eefe73c
SHA256: 1d297d91948c568edf3214eff94460c7dcf5c32a96bbee1f5adf47c3754ced63
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
C:\Users\admin\AppData\Local\Temp\nsdB9A3.tmp\INetC.dll
executable
MD5: 92ec4dd8c0ddd8c4305ae1684ab65fb0
SHA256: 5520208a33e6409c129b4ea1270771f741d95afe5b048c2a1e6a2cc2ad829934
2716
regsvr32.exe
C:\Users\admin\AppData\Local\Mail.Ru\mrkeeper.exe
executable
MD5: 2dfcf04fc94b9f268991b6344149bf7b
SHA256: b75db4bc584670986c305e1ff8df339bae96c1148c63defd2202ebe487604651
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
C:\Users\admin\AppData\Local\Temp\nsdB9A3.tmp\nsProcess.dll
executable
MD5: faa7f034b38e729a983965c04cc70fc1
SHA256: 579a034ff5ab9b732a318b1636c2902840f604e8e664f5b93c07a99253b3c9cf
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
C:\Program Files\Smart Application Controller\unins000.exe
executable
MD5: 047894f66dc6460b2ce90ad7d6b98db3
SHA256: b5306ebd2005160ca1787fc73d692c8efec058af2811e41a2fd9e7feae03e41c
3724
MailRuUpdater.exe
C:\Users\admin\AppData\Local\Temp\dad9-1e1b-e0dd-3fbc
executable
MD5: 4ac5a9796e153b190e70e2f51e49a131
SHA256: 5530be4592507773e6ca5ef13160973824c8dcff7f4cb4f97b5b508a336c8727
2928
DB85F1CD-00D2-462D-AAB4-FB49190C4608.tmp
C:\Program Files\Smart Application Controller\smappscontroller.exe
executable
MD5: 0737725ccaf3e39321a07f699b092c16
SHA256: 480b7b87faed6bd213bfa76d3d1ea357fedaadf8d0f66485cc1a62ccb9bbf2be
2428
E3B87877-10F6-4536-9523-42DAE1F68021.exe
C:\Users\admin\AppData\Local\Temp\nsdB9A3.tmp\blowfish.dll
executable
MD5: 5afd4a9b7e69e7c6e312b2ce4040394a
SHA256: 053b4487d22aacf8274bab448ae1d665fe7926102197b47bfba6c7ed5493b3ae
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Sputnik\ptls\mailruhomesearch.exe
executable
MD5: a29c9f523b47027fb97190b908c18979
SHA256: 25ceeaed228c2d7c08bad41362ad6619c243324ad8a0e05c75d3672e96373bed
3724
MailRuUpdater.exe
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004_d\MailRuUpdater.exe
executable
MD5: 4ac5a9796e153b190e70e2f51e49a131
SHA256: 5530be4592507773e6ca5ef13160973824c8dcff7f4cb4f97b5b508a336c8727
2788
MailRuUpdater.exe
C:\Windows\Temp\047b-1a0a-326d-bfac
executable
MD5: 602cd1f0dd54e83de1413705aa378803
SHA256: 8eeef659d4d3e827474b4c769436807eafedf58dc923054338cb5385dc8d3998
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
C:\Users\admin\AppData\Local\Temp\E3B87877-10F6-4536-9523-42DAE1F68021\E3B87877-10F6-4536-9523-42DAE1F68021.exe
executable
MD5: 550b1ba51db6914eca0f915a6e7fdc0c
SHA256: 6d2c4634ec3f443b7f74763c187873d9fa5daa44b2258a42947ce8ae0414ea54
1416
na_runner.exe
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
executable
MD5: feb798265c24beb577cb5bcd43cbd158
SHA256: d9be17d76dfb9d90246512ce89dd7aab7cf1cf94d6145429a84094614aba65e4
2788
MailRuUpdater.exe
C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\MailRuUpdater\us\336327ca85_d\MailRuUpdater.exe
executable
MD5: 4ac5a9796e153b190e70e2f51e49a131
SHA256: 5530be4592507773e6ca5ef13160973824c8dcff7f4cb4f97b5b508a336c8727
1416
na_runner.exe
C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
executable
MD5: feb798265c24beb577cb5bcd43cbd158
SHA256: d9be17d76dfb9d90246512ce89dd7aab7cf1cf94d6145429a84094614aba65e4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\435e-a331-f726-7df0\na_runner.exe
executable
MD5: feb798265c24beb577cb5bcd43cbd158
SHA256: d9be17d76dfb9d90246512ce89dd7aab7cf1cf94d6145429a84094614aba65e4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\GoChromiumNativeHost\native_host_app.exe
executable
MD5: 2fd24b550e262ef2b91162f4728729d2
SHA256: 3891ff2d5620b4ee5326dcfdd50e1a34def8397579c7dbec45b296dd5727d25f
4064
MailRuUpdater.exe
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater.exe_
executable
MD5: 4ac5a9796e153b190e70e2f51e49a131
SHA256: 5530be4592507773e6ca5ef13160973824c8dcff7f4cb4f97b5b508a336c8727
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\69a5-42b7-e12f-83bb\ie_addon_dll.dll
executable
MD5: 8c1c71d39137c7a7b2b9bdfe6eefe73c
SHA256: 1d297d91948c568edf3214eff94460c7dcf5c32a96bbee1f5adf47c3754ced63
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\currency-arrow.png
image
MD5: e2a3657ea4e7cb014c002c97059c4dd9
SHA256: 0b9a3219fbacc641d96be7b141ddb1dbb15df9fd6ffcd8791df11ead52fd3da0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
text
MD5: 74ec188993f9145e4470a0352b94ad25
SHA256: f1ae7fbefb2873c285170255ff85f48bf9306256f403a8fbd450e14de33beb22
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 39f2a0442f1483d3ea936bc09c2e8a72
SHA256: fcd503b3041c0036268ace2d4b5abb10fd76fe108e4aa9a985b6fb96cbca2f4c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json_0cbf-c3cc-6728-800c
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\visual-bookmarks.html
html
MD5: e1e02c0f0c27c2c44b8919d52e7e8c64
SHA256: 7542815ef5e378ceaf83f7e8dc9937c8cc0c9bf80c1b920c9e8cb37373d50eaf
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\manifest.json
text
MD5: d37b6b040f4cdf279f61fb810f0f51ea
SHA256: 4bd418e830cd1571e19536980eec9cd65475d5298e04e134e40664eb4519565b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\legacy_install.rdf
xml
MD5: 7fc693e1b131768d086374500db0623e
SHA256: 414092ff36095ff9b4c88e0b7cb00086eddea86ca8904c8d8b8a6a89ed0be609
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\js\preload.js
text
MD5: 75a9fc54b51ef54235874b7b8699e109
SHA256: 93eaf163f82fcbd4c4900f1a684c3d4181b9c8536a067393ba4cf888a409ab9b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\js\background.js
text
MD5: e5015e22bb2b31a002b71c26458134fa
SHA256: 6a221eeda7002f68923cec3a6429a6277a037c54188d16061973155c6772e876
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\7.png
image
MD5: 4444966a15d556bb0b9375feda7d51ed
SHA256: 156f3370e51b5ba87448c344bc8e5366a5cf422a0f3378922e806d7c1a613062
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\9.png
image
MD5: eeb0820e8e4e55a95f7732182b40bb21
SHA256: 308d8afedc57abcbbad3c58fb26164a02fa4789b1ad36073951c2d981280f134
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\js\cs-add-site.js
text
MD5: a8f2098dcdbddcad63e8910346eb5309
SHA256: 587be1b47f4e6e544b8fd5bca5f828dc3c45e46b7387826438be304f4fefe999
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\js\vendors.js
text
MD5: cbcd93e85467923de132d807634278cb
SHA256: e2ccb87eb21f34c2c8c1ec5b1f8691aca95e4ca229a797f8282b81d86255a2c4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\white-cross.png
image
MD5: 11b3a6ed2d3139ffaa551d14e4f0f615
SHA256: e3be0a74402b8de0b9c4e454b44290b5daec0a34a2247eebfd780e6b9feab2f8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\weather.zip
compressed
MD5: 2596e21b066c4986dda30c5db04123a2
SHA256: d30f74c89d322e61f1f602c0b484a7a4388a41a756e58438315fb2b9c28738c5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\8.png
image
MD5: 30fcef1fba37287f82f15b62c385ef7c
SHA256: 8cb31c86f70fc657400bb85e116017a0148f08ef3f38bdb6bac3da75a1619fc6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\js\app.js
text
MD5: 3e8e335173b87fa5c04f5fb78e7dc039
SHA256: 058a61ecaf9c204589d5bbd22014239beb2e8d8589ca60d528e5d13a5c0dd616
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\6.png
image
MD5: d5515c696a2ed73fe691606b0fe6f99a
SHA256: 5083e8c41eecc908da8ec7ac0198a3dcc4716f2406e4877b9024ba42ab7028b4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\5.png
image
MD5: f256db079d37e7ba8555791527a7f130
SHA256: b22148905595efe2dab3c44a73f41b6cd7cba7d6f7383a5e84b675135a371997
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\11.png
image
MD5: 779292bb1389f82975d97af996597102
SHA256: 14cb9f4b40fcd17e39cd445edb7cf20a6dcc6eebc29c7bd4a2a6c42dd4523340
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\2.png
image
MD5: b5409fd9e13a5782b6de84dd69ec7be5
SHA256: 0388869ef3030b78371dcda0f560edec7b81d2bea93e005304f39ee0df51dbb4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\1.png
image
MD5: 8c6cb92575c2602bb51c71b2929ae75a
SHA256: 21e84808b333847f207f2915c1f032cbb35819205450eb53d68fd6c127786ee7
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\tiles-settings\mode-switch.gif
image
MD5: 3f57cab18264674b4ed4b662accd6a67
SHA256: 1e29a4b65f4c365514e5469faed4a2006c42393650907340ac700405ee45100f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\10.png
image
MD5: a3450808b936db294ed521cbe37a0e19
SHA256: f80bc9bd97077fd31d9426f1c23c793d4fc5c5f8a2daab45f933a7b5c46d9d65
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\trash.png
image
MD5: 19b080cbfbc4265174b0f8d7a40918bf
SHA256: 6d336751b44237d5c89a177f8b4420e0fa1444be31e8be8f0084ebf26bc6e138
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\tiles-settings\mode-small.svg
image
MD5: 2246088f69a7add1f91bc483d77ae5e8
SHA256: 3cc53c71e627d70db5f310c515a1fc5b4e10bdd94e39f43fc78fa8429d8404f3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\tiles-settings\mode-mix.svg
image
MD5: 2fad2c00cdafad8532d4645c2a95860d
SHA256: 2d7515f0d3e87c63113b8f03be7fd601018c96bd6a682ca991fdf1161ff41175
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\4.png
image
MD5: 2be8313c4298221760a20ea19cd17f97
SHA256: bd70dc4e28e3a1fe268806a548013914038693d04407b10dc593f484a94c3267
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\weather\3.png
image
MD5: ea59205df5f541a30ebc39cea34de073
SHA256: b7b8f76c84fdc67c3714748c9e71ffd2f79642c9722cf9892065ae9b196c6aff
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\themes__arrow-right.png
image
MD5: 1ae5a38fbf521d3136740fefc98bc509
SHA256: eb868b469b5aa68a3ff9732c7e4363c55c8e48c634c85ee43718d84b7ce371f4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\upload.png
image
MD5: d833c0b3e6975b72fb200c5bd57a95c3
SHA256: d5565aaf76c142ced6679f6fb232b9c315d3b59977b690f7d7462d2ba5358b53
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\tiles-settings\mode-large.svg
image
MD5: 6f21e7fff23cd7981c91a55270b90197
SHA256: 962b7dc9595216b1fc3ad57a262de6ec01483274901af2cfe0523e1b33bb579e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\tiles-settings\mode-medium.svg
image
MD5: dac2fbfc2c4022904213c19773954315
SHA256: 015bef343f6dd4da9d2748b54d630026d9630456e0ecee83539546a8386356e3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\upload.svg
image
MD5: 19da88c7a6dbe7fd52b5a0bb811daec0
SHA256: 31b2d0b0b4d5acb030fa8c178f3854cf01e0098ba171f7a1adf22b16f0a8d34d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\error.svg
image
MD5: e16c8a0b348f2ac5f05b8f8897fcee34
SHA256: 8cc826f45b74aca9cc9491bd44f8f78257567f56cc51202c4ff552e95db43c34
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\spinner.png
image
MD5: d1f8593465b2132bcc5d78ff6c258871
SHA256: 5c80f2023b9a895adac965fa933cee674aa9578f7c46be3c3696a68b673186fd
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\loaded-empty.png
image
MD5: 6fb9e990312bb20b03b5332bf384867d
SHA256: 2dcaa0b3f2ed4a40ab270d3d79661d82ac7dcb5a64a464ac54693fdc1bcb0c52
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\authors-info.png
image
MD5: 81bf0470f5d52c9c8b0afd1e8a721dca
SHA256: fe1fdbba59c9238ce000d580b55fd0f9ad9f1a7200337a35b70b844014706713
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\shuffle.svg
image
MD5: 20a9285664a9171e95248ef8bfd9ef68
SHA256: a720cc995841904e319bc086d2188ff63d6af0030babff0b3f572266a024a995
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\authors-info.svg
image
MD5: af8a334f6072971e84fe1b74c2d9def5
SHA256: 8f9b1bc2f030f2282cf440bc29c7353394d592ddc315bb6ca65a33740b73225d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\themes__arrow-left.png
image
MD5: 5b2a0b5ffcc43e4d698ab2b8d72ab794
SHA256: ede767581d7b07b09a765fcb2cb72d416e27bc8aa5fa05c9d8b0b674051098b4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\themes\random.png
image
MD5: 378660b85578ba79aa4935126c6c32e9
SHA256: a7f105ff595fae51b101c0ea3f55a6c6715e30eed20a3ac7439ec06f7218d80a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\social\twitter.png
image
MD5: 1e604ca6a2bd9657819fb8b22273f5d5
SHA256: 7358a4468aad3304c4264a712e085dd072efe78f9bad422eb77dac2d763606ce
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\social\vk.com.png
image
MD5: fd6c5df9d82064176b9baa1ee5ad96d3
SHA256: 07d69bf271f556fd641ad3c656503d892277e8ca5fb37f76afbb45894f469442
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\special\new-year\new_year_big.png
image
MD5: 2d57b7fa62760eab323f35477ee3de76
SHA256: c9deccbf2e111b5056b86b4fd242e46fb928ca35bea7df9d53f4476f556c2e15
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\special\new-year\new_year_small.png
image
MD5: 727d45cc744dfe2c4c5ce823f34dc4ca
SHA256: 0d0c1bbe1e69624cc66d6e141c56ff5663fd15475a67d0e6d34d1e26f782ff2a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\special\new-year\new_year_middle.png
image
MD5: 015703597dc3964a3cf708c9137f85a6
SHA256: 98f9ae8a95ab1df36c2eed7f5f596128ad01ff7522463601e119173c6873a9d8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\social\ok.ru.png
image
MD5: a6cfd5a821079f5f75c6043ac7a477f5
SHA256: 2a04b14937d308db9564a44de2cf3e1af29fa29d44e4d1e205d467685bb391c7
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\side-menu.png
image
MD5: a15e27cc622306248c0c82e04a3dd258
SHA256: f35442d8729076cf47905d3e8b6cef0d2cb926d616ea0c3f80c2d731c628f62a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\social\my.mail.png
image
MD5: 5103f88170002bc262f7326433b0a5d3
SHA256: 9638061b834763bffb8e31fa8e405bb7fe5d91115fdeca39a952657334080592
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\social\facebook.png
image
MD5: 2b72e3b7a90f5d04e54eb2e49e39374e
SHA256: f76ca05035f420f57cc6c457a4ae645fa777101522ef1af84e56df0669fecea6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\4.jpg
image
MD5: b66d4131d75045603d2666376a540a6f
SHA256: 2a525859bf521e9e74b927b7f6f378361940d38b2d7d6544998ded4726e85931
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\3.jpg
image
MD5: 16a467e0d70a6de0a7eada32c2927ab1
SHA256: ea8a08df510d9f3d4717329316cf7bc15351ac4f69a1c07ff026063ddb0d947d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\2.jpg
image
MD5: cd40d8d24657cd37cfc33575afa007b3
SHA256: d082b8bb369921c3fbc8b603c1abcff9e8f6d7e21df1e4a00e484c7b026c7f1e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\6.jpg
image
MD5: 07faba34c1851af8202007035e7861e7
SHA256: 80f6cf9abbb06e1ae1077c6b4e72f9b7f90d7800da17e488403c124433d28c07
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\5.jpg
image
MD5: 13c053e0ae2cdc77be271abc9fc718ba
SHA256: 1fe464be4147f09e3b2b06f79db11af8db378df072dfa5bddd048635230b9397
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\showcase-placeholders\games\1.jpg
image
MD5: 8dd81c0f073688d3d00c426646f4903d
SHA256: df05475074e586f6c005b3095deba4e6cf2939c74fd511956c33a695dce7b676
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\settings\collections-icon.svg
image
MD5: b4cc4ddfb3bb76b29c436cab68bc310a
SHA256: f793b2101f3c48360259c0881cc00ea7ef6e0291fab6d7daf4bed92e1b3c6cf5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\search.png
image
MD5: 1963c1c1cd0c5c24c9a5646de735bf11
SHA256: 8414ff800cb06d3afd55b805578c43894fb0c5ff8b4ea81686bce73c67211e02
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\settings\themes-icon.svg
image
MD5: 2078825182229a1cbca83dafc50998bb
SHA256: 5547d1ce204c361e90a3367cab87cd830e975b9d0cc094637e8fcb75b0b886ca
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\search-crosses.png
image
MD5: e2771d54a0618586b7a7ede47a474e8b
SHA256: 258c1945ce2a671b16f7bb7e11700074a9b85702aaa77de7a7bf9b8155f8cb26
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\settings\presets-description-icon.svg
image
MD5: f64442db064e41ad0851eedc927018e0
SHA256: 86324c16dfef58b841534ac41aadd68fc3eec6f1c12a7501ffbe4341cc0c628b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\settings\modes-icon.svg
image
MD5: 2fef2dd4e8050596501d58cf465b0a1c
SHA256: 64fab862258019baf15447f4c069075ca840f35944b54083a10ccaf5626a4347
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\remove-tile-cross.png
image
MD5: 2fcd20117d7d8c283f70baf4f74dc3b8
SHA256: 97e36a6bd260ed0d1e21175f7fa83290f36e24ecfecdca9e5ea575f7423fa297
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\youtube.com.png
image
MD5: 249bce5dca17881e92efabc1f5ea8f3d
SHA256: 189a0da8b9286828b6d50b48af10a4b1b652f7bd9fb37e661b3db47aba3567e0
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\search-cancel-button.png
image
MD5: 739b3334b2d99b4ed903f12d0aca5dfe
SHA256: a208a63d40d3bfb7a5a8ff2952fe17409936d3e9cd20b538222c2e46217e092a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\tanks.mail.ru_game_unity.png
image
MD5: 72d5823af887bf5e24bf6298f14ec8ed
SHA256: f8989b636be47c267426d3ce0fc5b5f22f1ed1a81e6d16e6d91e0490fc57c0fb
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\sys.mail.ru.png
image
MD5: bd513be4b924e95ac1ccefd9c237c036
SHA256: 73c1eecd6c2d757744e523c314e41aab8a015b3b519e24f3be18d3e1bfabf80b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\wikipedia.org.png
image
MD5: 07beec1428c6b619c1275e126b707ffe
SHA256: ad333a640b324b39e660f053c72d216b4eb26c5ee8fbc788244fefe2128125cf
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\twitter.png
image
MD5: eb1fce9a5d95a9d2e7c9610e61ebde1f
SHA256: 2ebf946c17fed983616bedb8b3a78169d5e612a47a40b11719732e1454a6767c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\vkontakte.ru.png
image
MD5: f7d1c855ffc3451dc5b9eb55f54d3516
SHA256: 1e98fccfcd3d6172f91de59af69179dc98aa6241c9c2209a8ce94f5bf8b1b8f6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\otvet.mail.ru.png
image
MD5: 765d5f496184920832b31f16d1788c41
SHA256: fcd8bb04c7f4a1b498b37ce088f0a37fa5bf0cc6e6347aa13e48410ae3a81457
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\sf.mail.ru.png
image
MD5: 947002059f5f3c6d8686ef5163e3420d
SHA256: 70e0f748d9df042d4d83611d45f64d080343b8e84e57abca22f8a1b2fd1ac982
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\vk.com.png
image
MD5: d97f3434184fa690b77bc536bed3e3f3
SHA256: 7f83e9af0193ff3a2bc4035aaac9bf32676252e261395f5834bf6e1e57ca70ef
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\sys.mail.ru.ideas.png
image
MD5: 82a7b8470e9c434fc499b92807e255b8
SHA256: 9dcd88afb086f6934af28ff5f9c965e6f828d489536a1f8fd74b9135180bc526
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\sys.mail.ru.blog.png
image
MD5: 73ee5000bbc00a7f0a8c91f9162db641
SHA256: 4c50aa24f8849ca2e35ee6450a6916a4dd43fcb368eecde1236c33ce99b67a8c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\wf.mail.ru.png
image
MD5: 426e0597709b70f0c333820e036afeb3
SHA256: ecf6b8493bd40a99f225d48e27bf025b86daa05244fee2ab0680859c7287f7bb
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\mail.ru.png
image
MD5: 0c2bd61f54446aec23616c72c212beb0
SHA256: 5fa245db4336dd4ed4c609e2acabbe3b7827163e1a4568ccdae5e2420b793748
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\my.mail.ru.png
image
MD5: 9e9c746e0051c456eef0ad22cbb514e3
SHA256: 66e2b6482c9ddab597b917914c503a02672ac64edf6273451184d31e071287ab
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\news.mail.ru.png
image
MD5: af22e912c9cdd239dcbf2a895e23044b
SHA256: 70d2cd131b8be97e590dfb468d0fecd7afc56ec9fac7db610ec75e1346b9a4dd
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\jira.mail.ru.png
image
MD5: c8fcd054c53327b2b2574408f3fab343
SHA256: 05faed432d1fd02fb4257b65a153587935567f0995dbcfcda67f2f3043221d67
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\ok.ru.png
image
MD5: d02ae21c74aabde1f855e9c62e6fa726
SHA256: 78125fc2f60c6ed0e08e336a66a046102b4967d00639cb0adbb6660e72c1bfc3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\hr.corp.mail.ru_irj_portal.png
image
MD5: f691839f4b764064b09adbb774e5d639
SHA256: e35d8c560e8777e43f0cdd9dbca23b23dda452c61b0718c944f9a6310f82d0e5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\instagram.com.png
image
MD5: 269f532476a28a2fe195a84792fb5f89
SHA256: 7b2ac576e7fadaabefcccbbfd305046e9053de2afcb7f3cbae704488a48d7a23
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\fotostrana.ru.png
image
MD5: f13717e8b6097c698bb3e9c230dc5597
SHA256: e14fc21d4acd8e57e105ac1b8bd78157a58bab92382333fb261edcb7d98588c3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\ask.fm.png
image
MD5: 667d4a9e994abe0e6132b68a43c0719d
SHA256: 5eb374341fdb9a3bece0936ca5a95879f7525dab5c0cc1fdb1c66a3a124039b9
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\plus.png
image
MD5: 1c10548080d1741dc0016c737f2051f1
SHA256: 1c8f597566326e68bbdc8be20a383f28388c6418bdedc100cf12836d8911bf0f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\confluence.mail.ru.png
image
MD5: 075d452bc49b613e0c1e31fdc504a783
SHA256: 0e0c805637dd7c926b3cc6ae8ddef703fa2137a993118eb3518d9d42e18ff7e3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\cloud.mail.ru.png
image
MD5: 05b815504804abed127ff262cc072be1
SHA256: be0da4ac4cf68615b16a2880e8581f37469d280dfd29e9b494cb7c133fdefa7a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\dobro.mail.ru.png
image
MD5: d2b238b182fe3b15c3de12ae008e1f2b
SHA256: 035da9dd6cd23781ad08deaac697cbd28b31cf6d545d3450e42b538f76435ae2
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\games.mail.ru.png
image
MD5: 3b32329cb18d4e7c5629ab4f21bbcfbe
SHA256: d5757719dacfd1602730b902adac77713ddff239518f2aed4d7ac99e5e36ae2c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\predefined\facebook.com.png
image
MD5: 3a8251cf4f1cba300ab578e6e97a380b
SHA256: 651f77389c925157b11727d180e8428938e7cb3f639c4af97c4b2c3fdef13bda
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\pencil.png
image
MD5: 1f0d3d2d8b1ee1e4740c7de76dc4651d
SHA256: e7238bf7cd3398601c4c995497ffe2575710fb676bb4dadf80bbd164aab38724
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\page-action\disabled.png
image
MD5: d312dbbec224e0d6b75fbcb11f5549cd
SHA256: 8df2a42601ea8767316014087a45141d3ea0d5b646d2e54cad2a5bacb8749863
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\page-action\added.png
image
MD5: a79f72f19eb6533c9a0fdc88b7a08385
SHA256: c634a0bc5b0c79b686fdd3eac68ef9399da8a554ebde244d2d22fb255aaa2680
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\page-action\add.png
image
MD5: 5dfe3fcc2397d78639ff147c04138b67
SHA256: 033ccc8bc97a181bddd782438bbdb3b22758ffb7ebce079d4bd9a90f6e6f0784
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\sites-arrow.png
image
MD5: 9f179d977332ad3c14bf2f1fb9084d10
SHA256: 08c8bac2db696d99747ea929f3ef8b89785832af69e9b035f153d34b5f851298
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\options-spritesheet.png
image
MD5: f23b798278e19d591d9480b2f31a663e
SHA256: 46b50ea8fa4c82eb70563bd1f97bbc75d893121ea66cc838cec383c01fdfa2a6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\sites.png
image
MD5: 142262918e3859ee85baa7a78019b8ce
SHA256: cd716839c49397f1a08dd328ce6e071caebc83207995cb596b95e6fbef380619
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\search.png
image
MD5: e2cdab77f3fdd185f3069c7bdc2b45bb
SHA256: f7f6246810f98c4c6c0757ef92138c48c775d341232c68310306030459a701f4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\start.png
image
MD5: 1d49536d6051731f2e69663623ef64fa
SHA256: 9ef681d33703b9e8f21dccbd86f5a41e3cba66fbe986d288300e1e39c8f96855
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\menu.png
image
MD5: 5daa9ce8d7459e1328c530089ee75b84
SHA256: 6afe38ce14c25f22b1f28804b1d3b9f7c8d4310f2da1d0ea6b577f36315d67c6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\search-arrow.png
image
MD5: 5becc864227e2f3691d43ea2da2eecc2
SHA256: b79619ef651c2715dbf7221c4e3c3a05d4c55988ce679483a615471c05a86b24
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\onboarding-arrow.png
image
MD5: b769f85c0e0cafc56e7f5c219da6e041
SHA256: 767891741460b29c8b087083e2f7907ea00a2d6a7a37587688309a3ec1167aab
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\onboarding-done.png
image
MD5: feb51c261b327d6480945c3f8bc4ca03
SHA256: 8cc79c29206088b78671a0032eb782fe2d26f7bbe6eb0cf07f07e35fdfaa6b09
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\menu-arrow.png
image
MD5: 8333632af1ed50910d6ecdfcbbb52b2d
SHA256: d6decd0fc3d8a3091ee5ae5e6ce26567351f314845fdb896fa00d4eeb82a289d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\ok\live+text.png
image
MD5: b9d07504242f124d976993d00b365cf2
SHA256: 9e575eb6ec8d6d21c5539f27b5b871e28a7685f35696dac70871b4e7c053133d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\adding-arrow.png
image
MD5: fa8e87ba84f29105ce34f37cddbcf057
SHA256: 98ca69161be286f263354442a4155d2cdf9dda5bd1a6647c7c1a01e3ac78c4ca
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\onboarding\adding.png
image
MD5: b01c4024891f68cfd94caba096e020e7
SHA256: b321f97c6a254800c7c73eb3b7b7c011f7a228a3a12e9b02318b593f6e990f6d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\ok\media-arrow-left.svg
image
MD5: 49a8fd33b6f7a653ba2548641dd54592
SHA256: 6f3469927ccb14edd341db80b35b24e3b1fc16aa46bcb03bfc42ca385bdf8d13
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\ok\media-arrow-right.svg
image
MD5: c1fcff05ab6f02167ee9818737f2cab3
SHA256: 5e8f1dbb98065295091772de2d526e37084f912d25b148b8a9d3cd4a30c40bc2
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\ok\button.png
image
MD5: 97d5cf83c57cb581fb903f1bbb0daa52
SHA256: 0cc71ddc73dbaf8d7cd1c2319945f572ef9d79ce73b1b2de1fb3785da5fba846
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\odnoklassniki\ok.png
image
MD5: 5a71a139dfc0a73eccc97aedce51dc57
SHA256: edaa13f9a6001b7df978be77b55345cbde7939097a7cc5589d0efc140fcb8957
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\no-int-big-black.png
image
MD5: ea2aa4f28b1fbf93780899bb8ce5c278
SHA256: 33feb465091a22de8a7853da0b9a5d7b31910d78558bec5be8f68eda4d49d6df
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\odnoklassniki\default-avatar.png
image
MD5: 112d7c2e6d9c7f741e1ab9d865e9bb09
SHA256: c3ae5b0ec33e9dc9ccc9fa80d81fc37fd38b869ce2b6f1438405a6ae11ddc23f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\recipes-right.svg
image
MD5: 8ed6eb5ee0cb798afa21e5b40af56b46
SHA256: 16e0ec26dc438be4541bc5afba5f7d1f8e399bee4e0bc4c94721788e0064226b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\no-int-big-white.png
image
MD5: 245db7dc94bbdf18c37701e743874abb
SHA256: 642cfbf9d11e59d32360fa319b50ad864b520d81ab5d230055cb46c99c43cd08
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\odnoklassniki\gift.png
image
MD5: fe1d29d0ef77c103c0e5129a7158e5de
SHA256: 0f4d5ad1f0df9e281a2d07d3aee5cf70526fbf6a471e7c07fffb5971fa327698
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\media-arrow-right.svg
image
MD5: 3150e8635547b1fb85530eca81cddf2a
SHA256: 10b5349d8ee624f8f6276d9fa16aaa4980aa92e972373c678104751fbf8a1fea
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\recipes-left.svg
image
MD5: 02e10b779cef5460b18f11995316a573
SHA256: bfc89b99205fedda0aba8f839c75ec70a6463b0ca488917b50dea384a194f95f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\media-arrow-old.svg
image
MD5: 10410f77c7c89731e419c60468ac5767
SHA256: a335c63795ee0423b7e25bcde859c9c6b27971acd9665bca41a5e8cd930abc6d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\hitech.svg
image
MD5: 27db13bf2ff847d24cbd2c09ca9ffffa
SHA256: f9b8d64dc0603ee4e4fb38a3ce358c48feb2200b6d65e46446c15f329c8fafdc
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\media-tile\media-arrow-left.svg
image
MD5: cffab0aa187aac70177523dd0190de02
SHA256: 9588541a04d29a277839bdf88d5fb9d24bf693db3d3a2f19c928bde5bf604099
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\chrome\icon48.png
image
MD5: a13ad0614e2c287d8acb0ad0759e7045
SHA256: 232ca0ca83aa1860b2d49a69d3d602297c8526c649498ea69457bb403b089756
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\chrome\icon128.png
image
MD5: 76a13cd117000cc8713457817cbd9a7e
SHA256: 5358d181f97e8ac5af6cf869f11c2fc9a8d9af80f1ea723064567d3ed7ed100a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\chrome\icon19.png
image
MD5: d312dbbec224e0d6b75fbcb11f5549cd
SHA256: 8df2a42601ea8767316014087a45141d3ea0d5b646d2e54cad2a5bacb8749863
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\amigo\icon16.png
image
MD5: 23a347219bc797c41988fd8d4a410b65
SHA256: 414490997a057228d1a88fb5cefdcc2f34e23cd548ef8bb55461ba303ea46e67
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\amigo\icon48.png
image
MD5: a13ad0614e2c287d8acb0ad0759e7045
SHA256: 232ca0ca83aa1860b2d49a69d3d602297c8526c649498ea69457bb403b089756
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\taurus-dark.png
image
MD5: f5b915976cbad299096ceabad2f0daf7
SHA256: e850e4c1f5ef7dd93884f6489a1a0f211f4c37daeaa3f5d5c807be25c88b6215
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\virgo-dark.png
image
MD5: 6e33217a75b9465c68533b76b581de9e
SHA256: f6b3f8ce320439321290d9d101bdc6085c1b2d96f9a72792cdc50dc46f0f9ca8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\scorpio-dark.png
image
MD5: f23350127666dd1741ed92dd426d7fb3
SHA256: 01e27f93dc7d63c13c602a00e98d4aedffcab6df8ec1e3acf0507daa49dc2622
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\icons\amigo\icon128.png
image
MD5: 76a13cd117000cc8713457817cbd9a7e
SHA256: 5358d181f97e8ac5af6cf869f11c2fc9a8d9af80f1ea723064567d3ed7ed100a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\sagittarius-dark.png
image
MD5: 65ba410f9d2599bf176e0d496d6a5ec8
SHA256: 85fecfc1ec31db062a3f5368bcc4e7a15c8a02616d464ece394fd9914df81a02
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\gemini-dark.png
image
MD5: 09d54e81d4377ede445fae7c1356636d
SHA256: 3c5df79fde2153bb80306d25b8174cb7ae4570f16b46e5eeefa40898c1de9f68
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\leo-dark.png
image
MD5: 39b96f6ddddccefd9f8e23e89ed0ad9b
SHA256: dbc858f8063e471ea180d05691ae730db98c922e77898f57086eb5bb0df87a5d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\libra-dark.png
image
MD5: 1773d07d239dbd777ac0ae77a6361aeb
SHA256: 4d7e9e988591953ea10300090d6166768de9c825914b737e7c5c930f8fe2a83e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\pisces-dark.png
image
MD5: 8d0d3a7e30519d73d2ca755fa753c21c
SHA256: 7147962ccc5c3cbdf04c299460be044f6522a1d19ab30a041ff1642706962f60
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\pisces.png
image
MD5: 2effb402bb8ae757464ec581ec58c5a4
SHA256: 63602a1fda7e1fc734d6e29a55404b7cad61bee0f77c9f719e3752f035de436f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\capricorn-dark.png
image
MD5: 9d13f193328922215d827cb747270a58
SHA256: 33670f696faaa42c66a448805f0135a00671423217d6522923da21dae70a2f9d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\cancer-dark.png
image
MD5: 46352375db9cfca84c602299bf1d474c
SHA256: 4e92a8044bb7c102e5bd281fc058f91f64b2b0430ea42767fe2539fa9ee8c217
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Virgo.png
image
MD5: b13f54614e81f295a669d3e04a613343
SHA256: d72565beba18572a8e81acaed6bfa5fe55101331df95ee96c6ee9ec5cc74865a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\aries-dark.png
image
MD5: 4e39fea63ff5c0f7da97d6211a82b5ac
SHA256: fe8ca78e95cc67301b3daddc9f23b983a00c742cb3731dfab5e50eff54be291f
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Scorpio.png
image
MD5: 4c93e1b1baa519c769666291f03b0cd0
SHA256: e2ce0549f1bf4301ae31be68c66d7aa195f20508e7489c8d1c7e29dc6c36f294
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Libra.png
image
MD5: 6d22b14c1262be705a825bbe1ddb834b
SHA256: 4436c7f96b4ceec6f157268a71300e3222a20367544c27a43c37f2afa3106578
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Taurus.png
image
MD5: 505cb591e62cc3a583c774b869c119f5
SHA256: a2fcb4d8cc27a9d069f43da5d71fc5cd40f1d77554b2df150ea9e81a19979fad
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\aquarius-dark.png
image
MD5: 42394cf5a7367a122302b7cfc16bd012
SHA256: f76dca0aac9579e263635d903d735aa8ca2e4cc5972e0a13e941b1786745e9f3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Sagittarius.png
image
MD5: 42db427dcd9c15ec2bd4cc80c787d161
SHA256: 3a94f91d464f8c2caf6f79785bc89e6b19dcb5de7a7d44a855dbc10f6f3519ed
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\aries.png
image
MD5: 227cdc451490b7b062b470c4fef840bf
SHA256: 7333bf24269d47b9f6de3c40a1e1bc7ad25547f67193b364b88f4c1cc0349b1d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Leo.png
image
MD5: 4485b3ce38d50f31857bdba3582d7557
SHA256: 85ee3e98d5ad75caf9a0cb0d17ea1943963f452d3dbbef67398b7594077e04ed
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Cancer.png
image
MD5: 78924830976b1e196dea9cd7be0f87c5
SHA256: 52d1458f4b90fa98ac36df535ae3e378c1e5334587cc661a6166e427c9537415
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Capricorn.png
image
MD5: 6d520e8ec9c822e64c0ff66f30de85a2
SHA256: 6bb97f8d181c72c09be3a7730c74a4e73656162984940c267dafd2b0a7042e29
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Gemini.png
image
MD5: 7679d30dec2d745db9e587144d218d8d
SHA256: 6fa17ced1cfe3bce6443b9c2b72338732dd47a94dbde0e06ee9ed5f921ed1f47
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\restore-tile.png
image
MD5: 159085e0834ca415ca65d6a7d478d68c
SHA256: 9df4b6a70fa1776254756e077d1d89ef7104651cd31204a632f50a552ae81669
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\hint-more-themes.png
image
MD5: b737b7e910bafb31f7b728a1b01dadf3
SHA256: f744b1bd9cfb83e284a1ec28c8909a70991aa36655dc6de07047676ffdda056a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\horo\Aquarius.png
image
MD5: c058e5d80e5628b3c1cbed3dc2f60e1a
SHA256: cf06f93c1ed4de66fa44f9bccd63246bcc7feda43d6cf23e2b8f683213b8d480
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\hint-cross.png
image
MD5: b942ef4086efce8252ba60a36a1438b0
SHA256: ea6750d2b46ee176f7896c91ff235cff4e1ae75927ed1ce1d885c6676f346634
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\restore-tile-arrow-light.png
image
MD5: 6f223225b3cc3d1b911569bc1844ddf5
SHA256: adba53c47ee90f6ca7a650182fbf361063ba386a1f8d3e45681b4915e723dbe2
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\can-drag-tile.png
image
MD5: 43b1fafd36a309178f7750aeee6046cb
SHA256: 72df2fb1bbdaa68572e3573941d280fbfdaf691107096eebba4e14382d16c120
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\drag-tile-arrow.png
image
MD5: c888d1807b6eb2cf0e2e089012b15afb
SHA256: 2aae1282392900699dcc644607af1f9ad50b664c56c9df58e23089898ae4b9ed
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\restore-tile-arrow-dark.png
image
MD5: 8718b6663ffe848b88a139adf844647a
SHA256: df0dbda61135b42983508e3a7f11a1ae3ec71aaa8f069a86601eed093c53c7e6
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\popup-arrow-light.png
image
MD5: 76785ae4424680115c619c9783ea785e
SHA256: e335e037742bc9a242f568902b3f5d920e3342c9ae50434fc293b8720e2c5377
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\popup-arrow-dark.png
image
MD5: b133331462976add5443fb833a35ca83
SHA256: 660088dcb8bcc450d3f25f385dee5baa2430f380afe432d2c651b18b42e73959
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\new-tile-arrow-dark.png
image
MD5: eb6a8eef95ceb27d16ac3143e4af186a
SHA256: 886be410b581b2501062aa5bcc8e88cc7b8b5bc492473aedb0f713a0a83390dc
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\more-themes-arrow-dark.png
image
MD5: a1420dfee6d04f6826c904b22f2556c8
SHA256: 2948dbff8a28104da56ee341f00673999da2edaba4ec3ad18a70af7d039e095e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\more-themes-arrow-light.png
image
MD5: f3a6267d1a01053518500dbaccb30204
SHA256: f5241fb943a6900e61c94b4709a4bc61f9c80d6ff9c46f1fe5d0e981b89cae85
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\new-tile-arrow-light.png
image
MD5: 1c007ba24f3e2226863f7329187ba08e
SHA256: eb6d1b6bd11c3bb1883797010bf9d09234f97a3b5b87a94a3e9337992f1752b4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\add-tile-arrow-light.png
image
MD5: 61b1ae50763a2fd1bc9004139ebeed35
SHA256: 9b70f1529cf7445e1152127d05f20c108c0b0db3422cf71018d6e66d81fef1a3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\arrows\add-tile-arrow-dark.png
image
MD5: e07619d893fe2cd2a626bc69e4aacead
SHA256: acee61b1a77fbae011e3fe9881fc08874cd62f868373c40ce7d1f92a943ac833
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\add-tile.png
image
MD5: 935e295ae1e2f361c6346823c07d3e6b
SHA256: 0e979c0890a017812712dd73e98236c145d70cf29b8e0000ad9d1a1eeef51856
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\hints\add-site.png
image
MD5: 2d7c815915c0f9c4e3bdea858db7deda
SHA256: 1fc277db4d46e03d9afd84e7d5a2e5ec11f872f27adac6d548856896d2b60199
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\music-medium.png
image
MD5: f450cb82b154a83c7c7341c0210d73f0
SHA256: 5835d99890022767e89a5c20d47c09de9e0f99fabf0daab7a0a10d9db1dbd333
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\horo-small.png
image
MD5: 9a02e69feb665d28acad9a46948280bf
SHA256: 4dcda0cb5ba1e4bfd1f8445c9445ba76d07d6ba8344b74b58cfcacd01395909e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\music-small.png
image
MD5: c85e59da532c8a858f60f5600b666e75
SHA256: 94951c659aa76f5d138f438126c678f99d42ae47d1f613a657a9e5777cb65107
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\music-large.png
image
MD5: a1225660981ff46133221a7fed50cc4a
SHA256: 8d0169f975e21ccbd79f91f2b569ee367c69a52192581f2e9cf0f78a21a06a9c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\mail-medium.png
image
MD5: ad7070c03b9e0194694c1e057a69f6a6
SHA256: 2c5891b79994c435637be824ae4bb5dec80a01d115ba2b3c4e54e35e97589ff9
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\green-circle.png
image
MD5: 532c43f6ad40dd450154aecf5080788a
SHA256: e8407baec50eda7810a64d7a0e667c85731cbb26cebdfb18890f53436f07e4fe
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\mail-small.png
image
MD5: afdcc6d269137356cc71adfcf3ae8ac6
SHA256: 4496b831e382a7da950377f66da61e779c9b777e234e0d6760f846d3deebda15
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\mail-large.png
image
MD5: 6880f8c3eba101c8a75f1d738eb3e563
SHA256: f8ef805f5efa939e60a1cb49cc87d8196ca1d741379dbb81e7736bdacde3c28e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\music-special.png
image
MD5: 827b9d8862cb1940b15f9552494d1907
SHA256: 0bbac50b563f38026fb4f91821a44283497e9508008bd7df774f81dfcdb893ef
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\horo-medium.png
image
MD5: 7d6f94c8750f2d8439e497c23f585bbf
SHA256: 24a9e36ac7666df27c5a6c1384d48349771a9471103040fd96252b98b6b8c2e8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\at-sign.png
image
MD5: cd8a130f3c96bdc88cc47073512693d3
SHA256: 35c5155fc0aea90ec4712be5fb7f4c5cbd5c3d13ca332b3a468697785c4ee2e4
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\horo-large.png
image
MD5: 794b2329cf104ccd9f10ce3f1a07a4dc
SHA256: fff361830f53a7d8c88f40ce227b3df0ad0e062d017459fa123c59b0fcb38e9c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\extensions\games.png
image
MD5: 4060dd185be024b70803ced497604539
SHA256: fefd9371a72f50db83629c1f86a27f6973497832de0e34d3c18e4f6c2634f891
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\drag-arrows.png
image
MD5: b9c11da70b05bb39b7f5aa4f619cbacf
SHA256: 2ce0eb7690581cfa576ffa3e9acd8e3531978babc2bff8f5f86d9087b9e0550e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\drop-arrow-up.png
image
MD5: 6dbd5760815169bdd115bb704abda8d0
SHA256: aea66d4163d8ff24a9a3389c8d9a2fae1be16180e8a10f8cef71bd4eddee204b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\dots.png
image
MD5: 2c383e058da77639620457b44518ba2b
SHA256: fe58a0d138fda35fee669359899b2d7f366cc682a637c08d8c3bae57aef8bbca
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\dialog-cross.png
image
MD5: ccf4a2d808d0dc4e40366a62bc8c5a81
SHA256: cc79c681569b56e3b41e2943f58faeef74cb1ed031f51355abccde3de5e72244
3780
d0df51bca3719e4352f382b8d9b3a6d2a654fbf7a4186c162df3ff5f10f465f2.exe
C:\Users\admin\AppData\Local\Temp\Downloader\tempicon.ico
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\currency-arrow-light.png
image
MD5: 2a5c25c4fea734fac503e09bd8fe3d0a
SHA256: 8ec0cb7a18cb7fba7dc0dbe1a32a3af2dbcb5974f938a9091af0e974adab1e17
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\drop-arrow.png
image
MD5: efc873bc3501da0f2d7b8e06775a30d7
SHA256: 45333bb6c2a5ddb33b89f140fd6f69aae395074e3f29cd9f3a88fb26c1bdd912
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\currency-arrow-light-rotated.png
image
MD5: 98e95bfd3ca2f62018872de9c997c92d
SHA256: 2ab761fbff45c9f7f680572fecea1650997c2b6f24fd0ad4498c49c8ddb2a931
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\black-cross.png
image
MD5: 6e8f63a0c0ec7a96d543468c81fb17d7
SHA256: 8596e18836e11b1dd4764089f169b7d2f07bc3a7bf677bbd14e0f72cba549cd5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\boards-panel-preview.png
image
MD5: a4c661fc1f66e2aefd2bd5c16deab1ff
SHA256: 684cd662c683ec8def36a843f11497c4808d510ffe2b88bcdba8c17b73cd80a1
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\arrows.png
image
MD5: 5de5e7c169629fd52f65b3e7cb8e36cb
SHA256: 489b579f7c2b73521852607e47cf846c2c5f8dd3893994629d5ae28f48127d8d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\auth\auth-ok.svg
image
MD5: eb5cf0c5f87d93c4eb46c2553abf21d8
SHA256: a8b733fdd74fef3d37576eeae8ab7f1c6d3dbdbfd5e4c45b3c1dccc551a0b389
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\auth\auth-login.png
image
MD5: 4f0bc2effc5956b3a2ea19905f00bb96
SHA256: f2afecb625cf2cdce64e053ecb477cc5506f0aa3fcfa8c16153e3e7b9c78fc7a
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\img\boards-icon.png
image
MD5: 42d87b77a73de20bcedf9a071996a59f
SHA256: 0766fa78b85e94fcc35de47bb6e7ab23b960b7fd20d41383b4046bf27738d2dd
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\OpenSans-Light.woff
woff
MD5: d80d74570da6a34e3f6375e7f080cef3
SHA256: 3f807901ead0dd4071499e1ea4433caa4ea2dc634d6a51d6cd9a45fbaece9bee
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\Lato-Regular.woff
woff
MD5: fbe9eb0f891d30d7f332291ecb8877d3
SHA256: 24d2cc56e7af8268c3e777daa99792e249b8745b16a8cbf09011269f4d11eef2
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\OpenSans-Regular.woff
woff
MD5: d2f212b3306c1c2be3aad8ddf94bc439
SHA256: bd17871b2e3f8cba33258588f71aec35ecf019ed7cc25453d353525a898d64d8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\PTM75F_W.woff
woff
MD5: 71f577922f915321613db777009896d0
SHA256: a076393bc722054bb394ade872e240ecac87d35e1be4f292d560c50dcfdc4059
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\OpenSans-Bold.woff
woff
MD5: 6e0f48c0eaec9b4ab52d2c4043b44315
SHA256: df7819891c255bda57d59fb342572ee799c2dc648f66fba7812a39589530fa57
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\Lato-Bold.woff
woff
MD5: 05ffca7ddff7697735dad4a7de5c611b
SHA256: 4e9769bf083ebc8551c8436078a08fdc367aed3a2841270649d80133d125cead
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\OpenSans-Semibold.woff
woff
MD5: 500a6522f5d2450d7d7c4f5676076db1
SHA256: 95991fc6f467f909190ba9d9470cc14478bd802564744806515ecfab0db7bdf5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\Lato-Black.woff
woff
MD5: ab61bc722f2f931948144fac563cd6ea
SHA256: f947467687d450a6e2513ec8284bf088fc239c7089b413d26c725055dc59194b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\fonts\Lato-Light.woff
woff
MD5: dcc19a9c675ac1f12b2758c57147eedd
SHA256: 4093e2b51405b0c503d25c268365951234d67416a8622b36dff8333989542596
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\css\main.css
text
MD5: 8089481e26ad5ded41966c5190f58618
SHA256: 0626e605366ecb0fbb1554351c062f013b7662aa36ad9fb76759d418eff94684
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\external\build.js
text
MD5: 2107a73fefc9ff5c1a51d8e638f02706
SHA256: ebf664abdcc705f23574af76a5a4271a00fb4593140d894437c21babd42fba9b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\uz\messages.json
text
MD5: 5f8dd9f6178c95fa2e30f5deab8f7d79
SHA256: 4533c96ae903d3a22a4b4993e793c70526196385fa943e929a881d3982fd4275
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\external\metric.js
text
MD5: ae20d83bb7ea4b8ea0f83b10d8431443
SHA256: a42b875bf9a4f25fd25d17e30fcd2f17889dda83a3115a9dc03676b1bdfca656
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\uk\messages.json
text
MD5: 924931a79484c4b161aa52676c3ee52f
SHA256: cfb152cc67c9f34789c7c41a4c0592bde52893550e0e453ca9400ea6ffbf675b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\background.html
html
MD5: cfce080e950410c674caf290b6cec7d0
SHA256: e009840e8de1ad6ad8ef4a4abc5e4d1f92944956985d71585848b18b3c2dc755
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\css\cs-add-site.css
text
MD5: 4ec28e9742e1f0fba06f6f0380170d83
SHA256: 23d00a66d73f15ad3420acb8a5ad1fa20f2be72da91ebb31771b72c5954a174d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\tr\messages.json
text
MD5: 77e7d45321795ef3c8fcd07f89fac1bf
SHA256: 413232a92935c0f426385f0937d951fda2346b0918d8a95d11e8cd2a13a7a8ff
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\ru\messages.json
text
MD5: 35f142037757b18c832a1a2367a39ca9
SHA256: 7f378d02480c87acb78691f92c478e7417d45cc58df78a2658f9a0d4800bc562
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\ro\messages.json
text
MD5: 6a7989c2527416d27546c7e5704dad6a
SHA256: 5a7005018d4c0bfe5544f67acd11e2e39d01e3117d8ec1a827b54f8d7cc09ef8
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\ro_MO\messages.json
text
MD5: 180885a6126fe1e302d69fdce36239c0
SHA256: 40921d2f9faa0568594d55bc37e2fe203ac56e3cd911c298f929f9391bd2cb98
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\kk\messages.json
text
MD5: 177a4334f993456f691d65761221b252
SHA256: 09b494b9f2b8e892353ecb49bddbb13d44b5292f024efe182e357bf9f540df34
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\ka\messages.json
text
MD5: e7ec027a1bbb9d048ef27aca3b998282
SHA256: 4d5dde45d511c7d5d16ef90f7f15702d4b3dfa3e61bcfd5ec60e92b1fa5fae46
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\hy\messages.json
text
MD5: 68d32bffe185e8a1eb6771f0d7b93702
SHA256: ac59566d98e06afe20e70c3cdb34102710fce2f8119814d62526f238aa9fe227
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\en\messages.json
text
MD5: b5230ad966a4a6b8563a91485ab278a5
SHA256: fc9c5dd2b5eab519c919d65bc90a749366d699f52de88fd485ad4dd8827d230e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\_locales\az\messages.json
text
MD5: 2e7244a3103c35eeed134ba1caed0f4d
SHA256: c349789e65c58ad904e8dabaaeec828081b51c5b8a9dcc35fede353161252ae3
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\META-INF\mozilla.sf
text
MD5: b4d07bbea039fb456e3b2247b266cd7b
SHA256: 8a14f4bfe1963580ab3b116e3368918c5a27e590448faba8ee3f4519c60115af
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\META-INF\mozilla.rsa
cat
MD5: 509f46ecdcb0ec16fd943523acae5e7d
SHA256: 250cecae7c8587ea7a32eaa2aaa61e5b3a5cdd6ff39fc95415a97fbeed8fce4d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\e27f-45b8-4640-4a67\META-INF\manifest.mf
text
MD5: f9361bd4ad34804abad536ffa9649b8f
SHA256: d5b30e3912ab79ead431cd51e458a487135907655156f66c4196abf11909aa08
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
text
MD5: 9846f6c0974586b48d8737ba46dd6762
SHA256: 4960d5ede071119bc0499d637ed91a5a67bfd26f39a5d9734a2fc2f46fac2cea
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 3a9ab1ea59709a988d71cda269a7dcf3
SHA256: 236dfe7ea404e91fd172bc5be651999807b8ccd1506d3b70ead41614c880107d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\[email protected]
compressed
MD5: f37802d5111e422b2907a02f4cc79826
SHA256: 479a726be719d936d5c663f7ce6b89c4b5a23262e90918414e8d560a8ebdf8f9
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json_151c-08f9-94c9-3f83
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\background.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\icons\128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\icons\48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\icons\32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\icons\16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\install.rdf
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\META-INF\mozilla.rsa
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\META-INF\manifest.mf
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\fc76-1708-8a66-deeb\META-INF\mozilla.sf
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
ini
MD5: 2f4a9822679c1a3f6dbfea9c68d182ad
SHA256: ee238ceebe2287138c7529b7502dbe189bb0533c4357f3b6a12cf9964528513e
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\[email protected]
compressed
MD5: 13fd02c4b8b00d9ce9cd27b0d08ba147
SHA256: a27280497a12f159fbf577fa23fbf59ca0e3265c6e0dc3a0302485afdc424491
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json_f95d-8b52-59cf-e53b
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\install.rdf
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\icons\32.png
image
MD5: 64a4ee2110879d3e33b9738dc08acfca
SHA256: e9fbc898bcd298e966f664620585ab88122294bcfcb132da375acbc63bce9a65
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\background.js
text
MD5: 07af4785e57fb7d925515e3f5abd2d76
SHA256: 39f6a9537dc3c41ba8a84ea6a9bc1e4acc7be599f166d474b04152384f2b9467
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\META-INF\mozilla.rsa
cat
MD5: 02c8d30c01b3311fe73e0501c9e4048f
SHA256: 1f912c8b5597917d1f4ea4e2de67e1bc329cc76df8995b25ba710075e8527455
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\META-INF\mozilla.sf
text
MD5: bbee9e6df442e5d34ceec93a026801d5
SHA256: b1e15fabd43aa683d7d26ec104c1ce05a5b98f7b2990e25796e5726bc6134592
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\icons\128.png
image
MD5: da43e4343e3ed2293033d0d54f29e88e
SHA256: b03156c806faf63b1c82721be6cb5c761586639703001ddc5c4072f1f4b16397
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\icons\48.png
image
MD5: 1dea6af41e2fe95d57c3f02f9463a58a
SHA256: aea9a524e1d46e37394719674c85a9ebbebe7d40608b725cae723990651afc54
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\icons\16.png
image
MD5: cd23fe7a25703afbfabeb1fd20aae4ca
SHA256: fd3ab233f023c3ddfb441c7fa2c77a6d5200e4c64720065813030700b252f375
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\9b0f-10bf-69d5-4e93\META-INF\manifest.mf
text
MD5: 15b13529c10fb0b1ed68440b4d835898
SHA256: 3b3312ad33eb95da93e5d04dab3a5820357e59d7bdccc1d621be78e42ce14265
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\metadata
binary
MD5: 846017676acff535d8028e4754bb9a35
SHA256: a5b113a889d95b8babbd21e0c0e4c1c138e79df8c904acc3ed43232fe4d59dbf
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\GoChromiumNativeHost\manifest.json
text
MD5: 74941f1caa82d914baf9915eeb534481
SHA256: 11b19f9ae2b08f212a20c267602888a7d87a5377669dc6cb0ad812b949bd89ee
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons
sqlite
MD5: 4bb917b98137ee38c868cf270594d7ca
SHA256: fc7580a0168daec5354fb33a235d04de8e239730bf41cfa81d5f6e2148a999f7
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Bookmarks
text
MD5: 48292af00c9372ae4cbea3635ac14dcb
SHA256: ae8dedb11b8cbb1c1169d47fc05aa22d57da37eabf9441ccdda5d491ad79cb03
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Windows\System32\GroupPolicy\gpt.ini
text
MD5: 0d210c5b46142912ac25b527969bb446
SHA256: 6dd1a2813c317c320c22e5980b99ed8545ee764c7b0e1ce3b632f54f2dcd8038
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Bookmarks_250a-3922-f7ac-75f9
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\04da-f9dc-6725-ccb6\search_16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
text
MD5: fb963fb24aaf52df9a7ff794a76fe166
SHA256: 6618ff0c897ae31fc77d1d083957203d27511d5767ffa9dd70aaf2a6737f5ee5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\be8c-d44b-ae73-7793\mail_16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences_4ab5-246d-a3bd-87bd
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: c6dea9d9a1394d66472d8db3f8492475
SHA256: 56b75ffcc8d2cc34aba2b1ac9220fc51bfb833919bd31a4bf62af1538a73e638
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences_1201-2c84-eb45-1df6
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Windows\System32\GroupPolicy\GPT.INI
text
MD5: 0d210c5b46142912ac25b527969bb446
SHA256: 6dd1a2813c317c320c22e5980b99ed8545ee764c7b0e1ce3b632f54f2dcd8038
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Windows\System32\GroupPolicy\Machine\Registry.pol
binary
MD5: db4a7ed73d5af65fc281002cd6f2d1d9
SHA256: 32f4408d218a4644b98ddcee2919dc8b185a7551c6e59d9a66adfdc871b32e3d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Windows\System32\GroupPolicy\User\Registry.pol
binary
MD5: 8e1b08222f20e45a3e8db04c569f9cb7
SHA256: 5bb1f21f806938a043563024b13b33d74a2b95b767c5f81bde8456e9d0413a89
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\beliehdniadoecbonbhlcgbdldccfigp
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\visual-bookmarks.html
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\vendors~background.bundle.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\prerender.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\vendors~app.bundle.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\page-script.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\vendors~app.bundle~background.bundle.css
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\page-script.css
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\white-cross.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\vendors~app.bundle~background.bundle.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\vendors~app.bundle.css
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\spinner.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\icons\icon-48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\icons\icon-32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\icons\icon-16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\trash.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\disabled-48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\disabled-16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\disabled-32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\icons\icon-128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\disabled-128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\add-48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\added-128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\added-16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\add-128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\add-16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\added-32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\added-48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\browser-action\add-32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\background.bundle.css
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\background.bundle.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\resources\currency-arrow-light-up.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\resources\currency-arrow-dark-up.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\background.html
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\img\black-cross.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\context_mailru-plugin.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\resources\currency-arrow-light-down.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\resources\drag-arrows.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\resources\search-cancel-button.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\assets\img\loaded-empty.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\app.bundle.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\app.bundle.css
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\_metadata\verified_contents.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\_metadata\computed_hashes.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\_locales\en\messages.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\60c4-08dd-eeb3-0a74\beliehdniadoecbonbhlcgbdldccfigp\4.2.6_0\_locales\ru\messages.json
––
MD5:  ––
SHA256:  ––
2788
MailRuUpdater.exe
C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\MailRuUpdater\us\336327ca85
binary
MD5: 2448a20db5540290d4d95b0bf7ae2e84
SHA256: a14aaf5b88577f36f0dabf65e7d177ff30ac7ee8649a29b9080491e7e928851c
3724
MailRuUpdater.exe
C:\Users\admin\AppData\Local\Mail.Ru\MailRuUpdater\us\2d0cd78004
binary
MD5: 2448a20db5540290d4d95b0bf7ae2e84
SHA256: a14aaf5b88577f36f0dabf65e7d177ff30ac7ee8649a29b9080491e7e928851c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\iepoegkaoeljnbhagabakjodgpfniimo
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\manifest.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\icons\48.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\icons\32.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\icons\128.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\background.js
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\icons\16.png
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\_metadata\verified_contents.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\2c0e-3976-e22c-ef72\iepoegkaoeljnbhagabakjodgpfniimo\15.1.4.3_0\_metadata\computed_hashes.json
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Windows\System32\GroupPolicy\gpt.ini
text
MD5: 6427e1627fb697e73df506a2b5f77d72
SHA256: 3d7852515a0bf5fb21e7bd617587b28631bf49dfe21ba731d567c4c55a6f2f16
3356
mrupdsrv.exe
C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\Update Service\us\d9bf774acb
binary
MD5: 6b975618d48449ed86694f77ab951343
SHA256: 77ff2a0518b5258e4d54dcd4758b2b9cbb1518d2abfd5f1140ba76ac9ee17d3d
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\a96a-1c4c-7279-a07e
––
MD5:  ––
SHA256:  ––
3724
MailRuUpdater.exe
C:\ProgramData\Mail.ru\ifrm
binary
MD5: f84337e2ace35b14c49ea2dd079f0c93
SHA256: 6130d06bf2fa0b43fb87c373f0eb0ba638098ef452a8e9f5fc4d502fab17792e
2788
MailRuUpdater.exe
C:\Windows\Temp\2fb2-8092-43e3-c6ab
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Temp\f285-c154-7037-a22a\ie\p0b4c3115a4446533ea643007f860c4f6
compressed
MD5: 88d0066d2934121ca8d3f05794d932e2
SHA256: 85f72afbb60794b9c9cfb5c622d29a88c94ab4574ff2a0f2b8d129f873149d29
3092
MailRuUpdater.exe
C:\Windows\system32\config\systemprofile\AppData\Local\Mail.Ru\MailRuUpdater\us\336327ca85
binary
MD5: 3340434dd281a18033939b7f85e7d833
SHA256: 8cb4e5a51f6943abeab6a21d9e6987034481d6ceff82fa7b44013f4ae494506b
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\{29A974A2-2CBA-4DBB-A109-B2D73ACE5605}\p87b6ef4d2807d48bd2cd8d0ee8037ba6
compressed
MD5: 4597f0153816442f61c9f38d58365c29
SHA256: 146234f19deec3020041759d0f55c7e49c40e8b479436e55d059dc520f109b8c
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\metadata
––
MD5:  ––
SHA256:  ––
3756
smappscontroller.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\updateslist[1]
text
MD5: d751713988987e9331980363e24189ce
SHA256: 4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945
3756
smappscontroller.exe
C:\Users\admin\AppData\Local\Temp\705052.ico
––
MD5:  ––
SHA256:  ––
3756
smappscontroller.exe
C:\Users\admin\AppData\Local\Temp\319783.ico
––
MD5:  ––
SHA256:  ––
3756
smappscontroller.exe
C:\Users\admin\AppData\Local\Temp\422372.ico
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\{29A974A2-2CBA-4DBB-A109-B2D73ACE5605}\pfe58101a796f702a65f3b942494e7d1b
compressed
MD5: 8dbaa9bc3542ef07ac82c43673adfb23
SHA256: e9c8a8af9f221e05ba03c5e6db1327e6247ee6e7d845203f84d9cdfb5575ac69
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\{29A974A2-2CBA-4DBB-A109-B2D73ACE5605}\p6d2c7cda72cc50d7cd4d37c62f194afa
compressed
MD5: 4d32125ac02927870a70547b1156f791
SHA256: dc3fed4743633eb702af9a5472b62fa880c85ee0bdcd910fc560111e710849a7
3756
smappscontroller.exe
C:\Users\admin\AppData\Local\Temp\515567.ico
––
MD5:  ––
SHA256:  ––
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\metadata
binary
MD5: 44cfbf3793513c1519f496275a7f9e6f
SHA256: 0fd6fe7ea8440a739256c21b08030e8f5e35edf33b2a1343458a7237dc047fd5
3560
854A0F92-0841-4F1D-A5E6-8850A44A9C19.exe
C:\Users\admin\AppData\Local\Mail.Ru\Tmp\DeferredTasks\{29A974A2-2CBA-4DBB-A109-B2D73ACE5605}_c
binary