General Info

URL

https://secure.sharefile.com/Authentication/Login#ForgotPassword

Full analysis
https://app.any.run/tasks/f79dd953-d6a6-45ad-a790-836fd0111ac0
Verdict
Malicious activity
Analysis date
12/6/2018, 07:09:39
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
240 seconds
Additional time used
180 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • firefox.exe (PID: 2336)
  • firefox.exe (PID: 3776)
  • maintenanceservice_installer.exe (PID: 2544)
  • firefox.exe (PID: 2132)
  • firefox.exe (PID: 3164)
  • setup.exe (PID: 1132)
  • setup-stub.exe (PID: 2708)
  • setup-stub.exe (PID: 3492)
Application was dropped or rewritten from another process
  • maintenanceservice.exe (PID: 3164)
  • firefox.exe (PID: 3164)
  • ns810B.tmp (PID: 3008)
  • firefox.exe (PID: 2336)
  • firefox.exe (PID: 3776)
  • firefox.exe (PID: 2132)
  • maintenanceservice_installer.exe (PID: 2544)
  • setup-stub.exe (PID: 2708)
  • setup-stub.exe (PID: 3492)
  • setup.exe (PID: 1132)
  • Firefox Installer.exe (PID: 2200)
Creates files in the program directory
  • maintenanceservice_installer.exe (PID: 2544)
  • maintenanceservice.exe (PID: 3164)
  • setup-stub.exe (PID: 2708)
  • setup.exe (PID: 1132)
Creates a software uninstall entry
  • maintenanceservice_installer.exe (PID: 2544)
  • setup.exe (PID: 1132)
Executable content was dropped or overwritten
  • maintenanceservice_installer.exe (PID: 2544)
  • firefox.exe (PID: 3776)
  • setup-stub.exe (PID: 2708)
  • iexplore.exe (PID: 2920)
  • setup.exe (PID: 1132)
  • download.exe (PID: 284)
  • Firefox Installer.exe (PID: 2200)
  • iexplore.exe (PID: 2604)
  • setup-stub.exe (PID: 3492)
Creates files in the user directory
  • setup.exe (PID: 1132)
Starts application with an unusual extension
  • setup.exe (PID: 1132)
Creates COM task schedule object
  • setup.exe (PID: 1132)
Modifies the open verb of a shell class
  • setup.exe (PID: 1132)
Loads DLL from Mozilla Firefox
  • setup.exe (PID: 1132)
Application launched itself
  • setup-stub.exe (PID: 3492)
Dropped object may contain Bitcoin addresses
  • firefox.exe (PID: 3776)
  • iexplore.exe (PID: 1488)
Reads CPU info
  • firefox.exe (PID: 3776)
Reads settings of System Certificates
  • firefox.exe (PID: 3776)
  • iexplore.exe (PID: 2920)
Application launched itself
  • firefox.exe (PID: 3776)
  • iexplore.exe (PID: 2920)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2604)
  • iexplore.exe (PID: 1488)
  • iexplore.exe (PID: 3192)
Reads internet explorer settings
  • iexplore.exe (PID: 2604)
  • iexplore.exe (PID: 1488)
  • iexplore.exe (PID: 3192)
Creates files in the user directory
  • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2632)
  • iexplore.exe (PID: 1488)
  • firefox.exe (PID: 3776)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 2920)
Changes settings of System certificates
  • iexplore.exe (PID: 2920)
Changes internet zones settings
  • iexplore.exe (PID: 2920)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
53
Monitored processes
17
Malicious processes
12
Suspicious processes
0

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs iexplore.exe firefox installer.exe setup-stub.exe setup-stub.exe download.exe setup.exe ns810b.tmp no specs maintenanceservice_installer.exe maintenanceservice.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2920
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\users\admin\downloads\firefox installer.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
3192
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2920 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\t2embed.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\msimg32.dll

PID
1488
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2920 CREDAT:203009
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\jscript.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\t2embed.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll

PID
2632
CMD
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding
Path
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Adobe Systems Incorporated
Description
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version
26,0,0,131
Modules
Image
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
2604
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2920 CREDAT:203010
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sspicli.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\version.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll

PID
2200
CMD
"C:\Users\admin\Downloads\Firefox Installer.exe"
Path
C:\Users\admin\Downloads\Firefox Installer.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla
Description
Firefox
Version
18.05
Modules
Image
c:\users\admin\downloads\firefox installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\users\admin\appdata\local\temp\7zs89828b1a\setup-stub.exe

PID
3492
CMD
.\setup-stub.exe
Path
C:\Users\admin\AppData\Local\Temp\7zS89828B1A\setup-stub.exe
Indicators
Parent process
Firefox Installer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox Installer
Version
63.0.3
Modules
Image
c:\users\admin\appdata\local\temp\7zs89828b1a\setup-stub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsu3bb3.tmp\system.dll
c:\users\admin\appdata\local\temp\nsu3bb3.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\mozilla firefox\firefox.exe

PID
2708
CMD
"C:\Users\admin\AppData\Local\Temp\7zS89828B1A\setup-stub.exe" /UAC:40290 /NCRC
Path
C:\Users\admin\AppData\Local\Temp\7zS89828B1A\setup-stub.exe
Indicators
Parent process
setup-stub.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox Installer
Version
63.0.3
Modules
Image
c:\users\admin\appdata\local\temp\7zs89828b1a\setup-stub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\system.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\userinfo.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\nsjson.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\inetbgdl.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\certcheck.dll
c:\windows\system32\imagehlp.dll
c:\users\admin\appdata\local\temp\nsc4289.tmp\download.exe
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll

PID
284
CMD
"C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\download.exe" /INI=C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\config.ini
Path
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\download.exe
Indicators
Parent process
setup-stub.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mozilla
Description
Firefox
Version
18.05
Modules
Image
c:\users\admin\appdata\local\temp\nsc4289.tmp\download.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\appdata\local\temp\7zsc118d65a\setup.exe

PID
1132
CMD
.\setup.exe /INI=C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\config.ini
Path
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\setup.exe
Indicators
Parent process
download.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox Installer
Version
63.0.3
Modules
Image
c:\users\admin\appdata\local\temp\7zsc118d65a\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\system.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\cityhash.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\program files\mozilla firefox\accessiblemarshal.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\accessiblehandler.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\nsexec.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\ns810b.tmp
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\shelllink.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\mozilla firefox\firefox.exe
c:\users\admin\appdata\local\temp\nsy76b9.tmp\applicationid.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\serviceshelper.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\invokeshellverb.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\local\temp\nsy76b9.tmp\litefirewallw.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\netutils.dll

PID
3008
CMD
"C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ns810B.tmp" "C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ns810B.tmp
Indicators
No indicators
Parent process
setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsy76b9.tmp\ns810b.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\mozilla firefox\maintenanceservice_installer.exe

PID
2544
CMD
"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"
Path
C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
Indicators
Parent process
ns810B.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mozilla Corporation
Description
Mozilla Maintenance Service Installer
Version
63.0.3
Modules
Image
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\nsd82a0.tmp\system.dll
c:\windows\system32\cryptsp.dll
c:\program files\mozilla maintenance service\maintenanceservice.exe
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll

PID
3164
CMD
"C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" install
Path
C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
Indicators
No indicators
Parent process
maintenanceservice_installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Mozilla Foundation
Description
Version
63.0.3
Modules
Image
c:\program files\mozilla maintenance service\maintenanceservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\version.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3776
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
setup-stub.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
63.0.3
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msimg32.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\actxprxy.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2adec.dll
c:\windows\system32\slc.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
2132
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3776.0.679522072\1054372570" -childID 1 -isForBrowser -prefsHandle 1840 -prefMapHandle 1208 -prefsLen 1 -prefMapSize 178740 -schedulerPrefs 0001,2 -parentBuildID 20181114214635 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3776 "\\.\pipe\gecko-crash-server-pipe.3776" 1896 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
63.0.3
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\windows\system32\shell32.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll

PID
2336
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3776.6.1811442278\1829059301" -childID 2 -isForBrowser -prefsHandle 1100 -prefMapHandle 1824 -prefsLen 41 -prefMapSize 178740 -schedulerPrefs 0001,2 -parentBuildID 20181114214635 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3776 "\\.\pipe\gecko-crash-server-pipe.3776" 1792 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
63.0.3
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
3164
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3776.12.1387042049\279113328" -childID 3 -isForBrowser -prefsHandle 2576 -prefMapHandle 2580 -prefsLen 216 -prefMapSize 178740 -schedulerPrefs 0001,2 -parentBuildID 20181114214635 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3776 "\\.\pipe\gecko-crash-server-pipe.3776" 2592 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
63.0.3
Modules
Image
c:\windows\system32\ntmarta.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dbghelp.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

Registry activity

Total events
3450
Read events
3059
Write events
374
Delete events
17

Modification events

PID
Process
Operation
Key
Name
Value
2920
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
2920
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
2920
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{931B0C15-F91D-11E8-BAD8-5254004A04AF}
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E2070C000400060006000A000600FE02
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E2070C000400060006000A0006000D03
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C000400060006000A0006009A03
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
12
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C000400060006000A000600C903
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
36
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C000400060006000A0007002F00
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
28
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018120620181207
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePrefix
:2018120620181207:
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheLimit
8192
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheOptions
11
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheRepair
0
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
B27F255C2A8DD401
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3600000036000000560300008E020000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C000400060006000A0015001302
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C000400060006000A0015003202
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C000400060006000A0015004202
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
26
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2920
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Blob
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000053000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C00F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF01D0000000100000010000000918AD43A9475F78BB5243DE886D8103C030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE47419000000010000001000000068CB42B035EA773E52EF50ECF50EC52909000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030862000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB20000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
5
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C000400060006000A001D006102
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
5
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C000400060006000A001D008102
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
37
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
5
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C000400060006000A001D00A002
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
24
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Type
1
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
2
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E2070C000400060006000A002000C903
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF4C0000004C0000006C030000A4020000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
6
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C000400060006000A0023006D00
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
15
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
6
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C000400060006000A0023009C00
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
38
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
6
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C000400060006000A002300BB00
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
25
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
3
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E2070C000400060006000A002300FE02
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
4
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E2070C000400060006000A0024002A02
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
0
43003A005C00500072006F006700720061006D002000460069006C00650073005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E00650078006500000043003A005C00550073006500720073005C00610064006D0069006E005C0044006F0077006E006C006F006100640073000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
MRUListEx
00000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0700000000000000010000000200000006000000030000000500000004000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7
MRUListEx
0000000001000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\Shell
SniffedFolderType
Generic
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
2
69006500780070006C006F00720065002E00650078006500000014001F44471A0359723FA74489C55595FE6B30EE200000001A00EEBBFE230000100090E24D373F126545916439C4925E467B00000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
MRUListEx
020000000100000000000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
0
14001F44471A0359723FA74489C55595FE6B30EE200000001A00EEBBFE230000100090E24D373F126545916439C4925E467B00007C0032000000000000000000800046697265666F7820496E7374616C6C65722E65786500580008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000460069007200650066006F007800200049006E007300740061006C006C00650072002E00650078006500000024000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
MRUListEx
00000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
1
14001F44471A0359723FA74489C55595FE6B30EE200000001A00EEBBFE230000100090E24D373F126545916439C4925E467B00007C0032000000000000000000800046697265666F7820496E7374616C6C65722E65786500580008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000460069007200650066006F007800200049006E007300740061006C006C00650072002E00650078006500000024000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
MRUListEx
0100000000000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
69006500780070006C006F00720065002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
69006500780070006C006F00720065002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B1010000BE000000310400009E020000000000000000000000000000000000000100000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
69006500780070006C006F00720065002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000AE010000B000000051030000BA01000000000000000000000000000000000000B1010000BE000000310400009E020000000000000000000000000000000000000100000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
MRUListEx
020000000100000000000000FFFFFFFF
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2920
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\53\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CIDSave\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
9C000000980000003153505305D5CDD59C2E1B10939708002B2CF9AE3B0000002A000000004E0061007600500061006E0065005F004300460044005F0046006900720073007400520075006E0000000B000000000000004100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00000000000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
Download Directory
C:\Users\admin\Downloads
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E2070C000400060006000A002F00930000000000
2920
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
3192
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
3192
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default MHTML Editor
Last
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
3192
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018120620181207
3192
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CachePrefix
:2018120620181207:
3192
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheLimit
8192
3192
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheOptions
11
3192
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheRepair
0
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
FirefoxInstallerTest
Write Test
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
EnableFileTracing
0
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
EnableConsoleTracing
0
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
FileTracingMask
4294901760
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
ConsoleTracingMask
4294901760
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
MaxFileSize
1048576
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASAPI32
FileDirectory
%windir%\tracing
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
EnableFileTracing
0
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
EnableConsoleTracing
0
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
FileTracingMask
4294901760
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
ConsoleTracingMask
4294901760
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
MaxFileSize
1048576
2708
setup-stub.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-stub_RASMANCS
FileDirectory
%windir%\tracing
2708
setup-stub.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2708
setup-stub.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2708
setup-stub.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2708
setup-stub.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2708
setup-stub.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\61.0.2 (x86 en-US)\Main
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\61.0.2 (x86 en-US)\Uninstall
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\61.0.2 (x86 en-US)
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 61.0.2\bin
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 61.0.2\extensions
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 61.0.2
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 61.0.2 (x86 en-US)
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell\open\ddeexec
1132
setup.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AppId_Catalog\1F97E3EE
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
C:\Program Files\Mozilla Firefox
308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
ThreadingModel
Both
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}
PSFactoryBuffer
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}\ProxyStubClsid32
{1814CEEB-49E2-407F-AF99-FA755A7D2607}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}
ISimpleDOMDocument
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}\NumMethods
9
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E747BE5-2052-4265-8AF0-8ECAD7AAD1C0}\ProxyStubClsid32
{1814CEEB-49E2-407F-AF99-FA755A7D2607}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E747BE5-2052-4265-8AF0-8ECAD7AAD1C0}
ISimpleDOMText
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E747BE5-2052-4265-8AF0-8ECAD7AAD1C0}\NumMethods
8
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\ProxyStubClsid32
{1814CEEB-49E2-407F-AF99-FA755A7D2607}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1814CEEB-49E2-407F-AF99-FA755A7D2607}
ISimpleDOMNode
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\NumMethods
18
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BAA303D-B4B9-45E5-9CCB-E3FCA3E274B6}\InprocHandler32
C:\Program Files\Mozilla Firefox\AccessibleHandler.dll
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BAA303D-B4B9-45E5-9CCB-E3FCA3E274B6}\InprocHandler32
ThreadingModel
Apartment
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCA8D857-1A63-4045-8F36-8809EB093D04}\InProcServer32
C:\Program Files\Mozilla Firefox\AccessibleHandler.dll
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCA8D857-1A63-4045-8F36-8809EB093D04}\InProcServer32
ThreadingModel
Both
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCA8D857-1A63-4045-8F36-8809EB093D04}
PSFactoryBuffer
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE30F77E-8847-44F0-A648-A9656BD89C0D}\ProxyStubClsid32
{DCA8D857-1A63-4045-8F36-8809EB093D04}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE30F77E-8847-44F0-A648-A9656BD89C0D}
IHandlerControl
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE30F77E-8847-44F0-A648-A9656BD89C0D}\NumMethods
5
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE30F77E-8847-44F0-A648-A9656BD89C0D}\AsynchronousInterface
{DCA8D857-1A63-4045-8F36-8809EB093D04}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCA8D857-1A63-4045-8F36-8809EB093D04}
AsyncIHandlerControl
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCA8D857-1A63-4045-8F36-8809EB093D04}\NumMethods
7
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCA8D857-1A63-4045-8F36-8809EB093D04}\SynchronousInterface
{CE30F77E-8847-44F0-A648-A9656BD89C0D}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32983FF-EF84-4945-8F86-FB7491B4F57B}\ProxyStubClsid32
{DCA8D857-1A63-4045-8F36-8809EB093D04}
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32983FF-EF84-4945-8F86-FB7491B4F57B}
IGeckoBackChannel
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32983FF-EF84-4945-8F86-FB7491B4F57B}\NumMethods
8
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
FirefoxInstallerTest
Write Test
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Firefox HTML Document
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
FriendlyTypeName
Firefox HTML Document
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\DefaultIcon
C:\Program Files\Mozilla Firefox\firefox.exe,1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell
open
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\command
"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1"
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB
Firefox URL
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB
FriendlyTypeName
Firefox URL
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB
URL Protocol
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\DefaultIcon
C:\Program Files\Mozilla Firefox\firefox.exe,1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell
open
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell\open\command
"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1"
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell\open\ddeexec
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\Mozilla
CurrentVersion
63.0.3
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\63.0.3 (x86 en-US)\Main
Install Directory
C:\Program Files\Mozilla Firefox
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\63.0.3 (x86 en-US)\Main
PathToExe
C:\Program Files\Mozilla Firefox\firefox.exe
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\63.0.3 (x86 en-US)\Uninstall
Description
Mozilla Firefox 63.0.3 (x86 en-US)
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\63.0.3 (x86 en-US)
63.0.3 (x86 en-US)
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 63.0.3\bin
PathToExe
C:\Program Files\Mozilla Firefox\firefox.exe
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 63.0.3\extensions
Components
C:\Program Files\Mozilla Firefox\components
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 63.0.3\extensions
Plugins
C:\Program Files\Mozilla Firefox\plugins
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 63.0.3
GeckoVer
63.0.3
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
63.0.3
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
CurrentVersion
63.0.3 (x86 en-US)
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
FirefoxInstallerTest
Write Test
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
Comments
Mozilla Firefox 63.0.3 (x86 en-US)
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
DisplayIcon
C:\Program Files\Mozilla Firefox\firefox.exe,0
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
DisplayName
Mozilla Firefox 63.0.3 (x86 en-US)
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
DisplayVersion
63.0.3
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
HelpLink
https://support.mozilla.org
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
InstallLocation
C:\Program Files\Mozilla Firefox
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
Publisher
Mozilla
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
UninstallString
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
URLUpdateInfo
https://www.mozilla.org/firefox/63.0.3/releasenotes
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
URLInfoAbout
https://www.mozilla.org
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
NoModify
1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
NoRepair
1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 63.0.3 (x86 en-US)
EstimatedSize
162477
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Firefox Document
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
FriendlyTypeName
Firefox Document
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB
Mozilla Firefox
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\DefaultIcon
C:\Program Files\Mozilla Firefox\firefox.exe,0
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
HideIconsCommand
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
ShowIconsCommand
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
ReinstallCommand
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
IconsVisible
1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\shell\open\command
"C:\Program Files\Mozilla Firefox\firefox.exe"
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\shell\properties
Firefox &Options
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\shell\properties\command
"C:\Program Files\Mozilla Firefox\firefox.exe" -preferences
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\shell\safemode
Firefox &Safe Mode
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\shell\safemode\command
"C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities
ApplicationDescription
Firefox delivers safe, easy web browsing. A familiar user interface, enhanced security features including protection from online identity theft, and integrated search let you get the most out of the web.
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities
ApplicationIcon
C:\Program Files\Mozilla Firefox\firefox.exe,0
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities
ApplicationName
Firefox
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\FileAssociations
.htm
FirefoxHTML-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\FileAssociations
.html
FirefoxHTML-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\FileAssociations
.shtml
FirefoxHTML-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\FileAssociations
.xht
FirefoxHTML-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\FileAssociations
.xhtml
FirefoxHTML-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\StartMenu
StartMenuInternet
Firefox-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\URLAssociations
ftp
FirefoxURL-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\URLAssociations
http
FirefoxURL-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities\URLAssociations
https
FirefoxURL-308046B0AF4A39CB
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Firefox-308046B0AF4A39CB
Software\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\Capabilities
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe
Path
C:\Program Files\Mozilla Firefox
1132
setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService
Attempted
1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService\f9b87e891978e3145f0f8f9953eadc00\0
name
Mozilla Corporation
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService\f9b87e891978e3145f0f8f9953eadc00\0
issuer
DigiCert SHA2 Assured ID Code Signing CA
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService\f9b87e891978e3145f0f8f9953eadc00\1
name
Mozilla Corporation
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService\f9b87e891978e3145f0f8f9953eadc00\1
issuer
DigiCert Assured ID Code Signing CA-1
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPage
FavoritesRemovedChanges
5
1132
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Favorites
007C01000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000007601000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C000000007801000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C00000000EE00000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4D7D5911005461736B426172003C0008000400EFBE454B864A1C4D7D592A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032007A0800001C4D59592000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C000000005201000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4DD15D11005461736B426172003C0008000400EFBE454B864A1C4DD15D2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200FB0600001C4DD05D20004F50455241317E312E4C4E4B0000540008000400EFBE1C4DD15D1C4DD15D2A000000E6C600000000010000000000000000000000000000004F007000650072006100310032002E0031003500200031003700340038002E006C006E006B0000001C007A0000001D00EFBE02007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004F0070006500720061005C006F0070006500720061002E0065007800650000001C00000000F400000014001F80C827341F105C1042AA032EE45287D6685200310000000000864D663111005461736B426172003C0008000400EFBE454B864A864D66312A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016008C0032005D040000864D6531200046697265666F782E6C6E6B00440008000400EFBE864D6631864D66312A0000006FE20000000003000000000000000000000000000000460069007200650066006F0078002E006C006E006B0000001A002E0000001D00EFBE0200330030003800300034003600420030004100460034004100330039004300420000001A000000FF
1132
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesChanges
10
1132
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
FavoritesVersion
2
1132
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
DisplayName
Mozilla Maintenance Service
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
UninstallString
"C:\Program Files\Mozilla Maintenance Service\uninstall.exe"
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
DisplayIcon
C:\Program Files\Mozilla Maintenance Service\Uninstall.exe,0
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
DisplayVersion
63.0.3
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
Publisher
Mozilla
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
Comments
Mozilla Maintenance Service
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
NoModify
1
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
EstimatedSize
286
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService
Attempted
1
2544
maintenanceservice_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MaintenanceService
Installed
1
3776
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3776
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
LanguageList
en-US
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
3776
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent

Files activity

Executable files
169
Suspicious files
133
Text files
240
Unknown types
135

Dropped files

PID
Process
Filename
Type
2604
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\Firefox%20Installer[1].exe
executable
MD5: c54895510e1ec8a46a1ef42b8dbcc040
SHA256: 583f28b1764c19c7740a1c93d64c99424f0739ea9695b4b535f2542e8f5a42e3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: dfeef8cd90daad0c80698d681e49b20d
SHA256: d027488421b5e1a7c26c746159bb7ee73f87d851a9f4f6a21bc4862d00b81af4
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: c8ec676609c65cc00e66a547ddff8115
SHA256: 2b0cd0bd73a31d71d3550ef86c185812c0bb87329fb029882188a1de7de7fca9
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 2fe406dbb418d54e9ce82c9bcba21d43
SHA256: e21e9f14cf2a8f53fdb959a08a5e0e7185dfc2f733001bba1a0c90f5f4f30f9d
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 17066086b3177bdc0a16776499fbc6e2
SHA256: 3b51ddb3b456c84f203e29846a2bba164167e1bd20c05cf2fed84521fa76b737
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: 758799f297ad9e94bd596e7e6024094b
SHA256: c158a22d32a06e4aeac07b9530523e00d1ee9a8cc75b7d4d6b22214e62eabb08
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: eea0f690520c22902ee8186e3ee61374
SHA256: cb1dcc38491a2cb563da29c4f3359e1008b3c9406a18e7c09e1f9d3a6d370156
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 66da25982c32a3f79984861ee9f0e823
SHA256: 603bf59bac00f1244d062e8eda22ac026653d9e102ce4c8b38080633b223736d
1132
setup.exe
C:\Program Files\Mozilla Firefox\breakpadinjector.dll
executable
MD5: 15d98a9ca6bf6775767a7afcddaf0a45
SHA256: dd7c3c41819149dd126afcee960b3eec51a7dd3bee7a7bd35ac44d9ea365d2b6
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: e5f0161feb4a8a904850314a41884445
SHA256: 003d3034fc3827f26fb8d3be40539afbf7ecb72d81ff90ef06fb06b68eedb270
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 755d788b49d135348bf2ecbc308df9c1
SHA256: f7abbd4e40e63a51c2bce4ee52e1532a8ac8bab2e68331bfb2b99194e183e1d0
1132
setup.exe
C:\Program Files\Mozilla Firefox\crashreporter.exe
executable
MD5: a2f9e89e3ef1c5a8891e46265829e49f
SHA256: 03d63958ee6beb8579741ddef9994694b6afed9a3836468bbc7ac1bbfce027f0
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: ed48c04b51b1c7598325e59492a0eb05
SHA256: c9c25c1b70817a7084255c0688c7e08f461ad9764ba0af8e8bd5415c1e5c38b7
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: 97c3dd6f2671c3569dff6dbcae2fa63a
SHA256: 93f1f0d6c4be2619ab353ed3ae137d7c85c4ad85432021ad122205044abf7c39
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: a88d8023d39d9f06a47444a21d6a9b59
SHA256: bcb536ad27a357d4469d7eca156cf926d797857f98c5f5f3e586d754d2e73517
1132
setup.exe
C:\Program Files\Mozilla Firefox\d3dcompiler_47.dll
executable
MD5: eee83660394f290e3ea5faac41c23a70
SHA256: b35b96b1eb5539a3748b98643172681f9b74d0ec726b05f8c2c248c10888e9a5
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: 9fee5f7a11c9a570431ceb5ca1fc0d1c
SHA256: db1f8acb237f72b0d2cc6131b69e9445da115c7a1e26bc3f10b82f78e60dd6bd
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: 49239305d94b1b5efbb6f6967bb76c61
SHA256: 2fc3af6c78bce970d3098455c364164d1a008c7f991efbcb595a448ad5ed2102
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: f362974aa43eca8557c051557346a8c3
SHA256: 474f8b773177f7470c1ee0bfc4ea650b015558b431dffa029ccaaa5e9c5bd337
1132
setup.exe
C:\Program Files\Mozilla Firefox\firefox.exe
executable
MD5: 8ec11ffea0f73f993c0a093653c5a179
SHA256: 76e344a43910a45679f208f1414bd720ca8efe5ca207d44179737da30aad090b
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: d1c9158902d741d3ee20e20c3c89d9f7
SHA256: b330f5f62548d9d0669c0f2f3725dbdc96a887ee968c8b6004a195a17e1f5a61
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 8d58bc189a53de5cfdc0825f5cd79a5a
SHA256: 422f2e19574844837b7c6fe72ae16d119fccf217fb5f909c1dbba555c9d99f44
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\breakpadinjector.dll
executable
MD5: 15d98a9ca6bf6775767a7afcddaf0a45
SHA256: dd7c3c41819149dd126afcee960b3eec51a7dd3bee7a7bd35ac44d9ea365d2b6
1132
setup.exe
C:\Program Files\Mozilla Firefox\freebl3.dll
executable
MD5: 74ea2d9c5f369d34086da750a723d16f
SHA256: 8dd4061c22a7dd07d764c357e8540f490ba0bffa4ebb59a0aa890cb29e6426a8
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: 758799f297ad9e94bd596e7e6024094b
SHA256: c158a22d32a06e4aeac07b9530523e00d1ee9a8cc75b7d4d6b22214e62eabb08
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: c5a24baf52c2645de26b881db2828361
SHA256: ea545f265338dad581ff13c1dd2560d5555ead108b344fd64e9d59594646e2cc
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: eea0f690520c22902ee8186e3ee61374
SHA256: cb1dcc38491a2cb563da29c4f3359e1008b3c9406a18e7c09e1f9d3a6d370156
1132
setup.exe
C:\Program Files\Mozilla Firefox\libEGL.dll
executable
MD5: deb362354cc5ac9b01fae4aca9e6baf1
SHA256: ec32da7a80dc4a95c1a8413fd1852ae80ed73718e919e175b8dc64204410d698
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: a88d8023d39d9f06a47444a21d6a9b59
SHA256: bcb536ad27a357d4469d7eca156cf926d797857f98c5f5f3e586d754d2e73517
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: 50e68376a7d4d7840c6524a9c00fcdb9
SHA256: 9bae5bc1ce7bf82d52201128aa0ddc06d0394b0e45205af9b1e7319990b27aa6
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: d1c9158902d741d3ee20e20c3c89d9f7
SHA256: b330f5f62548d9d0669c0f2f3725dbdc96a887ee968c8b6004a195a17e1f5a61
1132
setup.exe
C:\Program Files\Mozilla Firefox\lgpllibs.dll
executable
MD5: 0ed9e7559355c15b39e4636fd4344348
SHA256: f1c9e07595e44c2cbd471603b309c7fa6babf7a28ca06c4f380bab382f8ec8bf
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: 97c3dd6f2671c3569dff6dbcae2fa63a
SHA256: 93f1f0d6c4be2619ab353ed3ae137d7c85c4ad85432021ad122205044abf7c39
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: 81f09d71ab79e07d21930ecd57df95d1
SHA256: 8ee9dbe4cfdf102e32ba3f4061961a6af301ab952e4e864e17a8bcb7402a309f
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 17066086b3177bdc0a16776499fbc6e2
SHA256: 3b51ddb3b456c84f203e29846a2bba164167e1bd20c05cf2fed84521fa76b737
1132
setup.exe
C:\Program Files\Mozilla Firefox\IA2Marshal.dll
executable
MD5: 55bd606e396b40dad6956ca38d223b9f
SHA256: ddf57de69aa8791767b8a9263d3bb17df90a002c61a75a73c2604096fe180cfd
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: dfeef8cd90daad0c80698d681e49b20d
SHA256: d027488421b5e1a7c26c746159bb7ee73f87d851a9f4f6a21bc4862d00b81af4
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 7fa9423d1849948455f2fc9f0a96d7b2
SHA256: 9d85d8c191db68c9fbe8de0dac282e45dc98f26251888ffc9ece01ee9254290f
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: 69b12f5c338b0138246b6443a5997eee
SHA256: 11e69c46f7763a393de3586450f5a53353c56949ec69cbeb9c56b4a93559cad1
1132
setup.exe
C:\Program Files\Mozilla Firefox\libGLESv2.dll
executable
MD5: 58c4f63130b4b515dcb9ea2e2718da52
SHA256: a441a1cad1a7117cf6a02176bdc79af24cb9f98beea6208a1d8a4b53cd2a1bb9
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: f362974aa43eca8557c051557346a8c3
SHA256: 474f8b773177f7470c1ee0bfc4ea650b015558b431dffa029ccaaa5e9c5bd337
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: 327f1b9e58956936d510d0e5e6f524e4
SHA256: ad98665e8c68ffc0828783c00f298224825f1fb2d1a55d577140dbdc1a9228c0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: c8ec676609c65cc00e66a547ddff8115
SHA256: 2b0cd0bd73a31d71d3550ef86c185812c0bb87329fb029882188a1de7de7fca9
1132
setup.exe
C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
executable
MD5: 90e9dd5d965d3a90491b77d872224dda
SHA256: 34555a162117ce44e830634d6172c2f76ee6426291e84a5be4ee6c17fcc8b58f
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 66da25982c32a3f79984861ee9f0e823
SHA256: 603bf59bac00f1244d062e8eda22ac026653d9e102ce4c8b38080633b223736d
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-string-l1-1-0.dll
executable
MD5: 1ad74561da672bc860cc305f0cc94fe8
SHA256: f2c325383af283d780d8c7ebfc2fef831c967e26e83d39a35d5df43505a80d83
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: ed48c04b51b1c7598325e59492a0eb05
SHA256: c9c25c1b70817a7084255c0688c7e08f461ad9764ba0af8e8bd5415c1e5c38b7
1132
setup.exe
C:\Program Files\Mozilla Firefox\maintenanceservice.exe
executable
MD5: f042b2fe10c80d0999e3822acc3db75d
SHA256: d2728e0ca133f85ac61439713ea4139c7d6d20ac7b9e14a67519c6f8573f719e
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: e5f0161feb4a8a904850314a41884445
SHA256: 003d3034fc3827f26fb8d3be40539afbf7ecb72d81ff90ef06fb06b68eedb270
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 69f6149abe55ff3be641137f7499e31f
SHA256: 0e953ba767d8fbda286bd1fdbc1e5a2b19c659227abd019cd60e1853e01de7d3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: 9fee5f7a11c9a570431ceb5ca1fc0d1c
SHA256: db1f8acb237f72b0d2cc6131b69e9445da115c7a1e26bc3f10b82f78e60dd6bd
1132
setup.exe
C:\Program Files\Mozilla Firefox\minidump-analyzer.exe
executable
MD5: d917fe837932192c9165160ec3545502
SHA256: c34b33001551aa8dd2a29a5fbff04a652f433d3bffcea7ee729fe15ee97c1298
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 2fe406dbb418d54e9ce82c9bcba21d43
SHA256: e21e9f14cf2a8f53fdb959a08a5e0e7185dfc2f733001bba1a0c90f5f4f30f9d
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 015c4941eaf3f7ffd3f48ec640f3ec4a
SHA256: 8aa6f8acbab2f139a653c54d2c4f4563534ba1422bd1603dd95759d163b669eb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\crashreporter.exe
executable
MD5: a2f9e89e3ef1c5a8891e46265829e49f
SHA256: 03d63958ee6beb8579741ddef9994694b6afed9a3836468bbc7ac1bbfce027f0
1132
setup.exe
C:\Program Files\Mozilla Firefox\mozavcodec.dll
executable
MD5: f74fa5a1f59ff27f35a2204d01665a20
SHA256: 19b82c4789a01ccae02d146ab8623979f5b5977cba83fd876d092b57b6afeeb4
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 755d788b49d135348bf2ecbc308df9c1
SHA256: f7abbd4e40e63a51c2bce4ee52e1532a8ac8bab2e68331bfb2b99194e183e1d0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: 9042c23f952275889348a916822a7758
SHA256: 1ac5c8dcd00ba1e8609b96ec8cc21ecc284f5a463af7cec849730dedce4790a3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\d3dcompiler_47.dll
executable
MD5: eee83660394f290e3ea5faac41c23a70
SHA256: b35b96b1eb5539a3748b98643172681f9b74d0ec726b05f8c2c248c10888e9a5
1132
setup.exe
C:\Program Files\Mozilla Firefox\mozavutil.dll
executable
MD5: 5380af0d8ddbf111554d585ad3f35c27
SHA256: 619f913c46df9612d675a03540fa4966925a06697fe2f77563f23cb0046a08b5
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: 327f1b9e58956936d510d0e5e6f524e4
SHA256: ad98665e8c68ffc0828783c00f298224825f1fb2d1a55d577140dbdc1a9228c0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: f827b6e4fbdffa25efd1e87c5809f4a7
SHA256: ef5a09fab070abf3233f4807c1c52ad79af59dee5ee51167558650a71008f6bb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\firefox.exe
executable
MD5: 8ec11ffea0f73f993c0a093653c5a179
SHA256: 76e344a43910a45679f208f1414bd720ca8efe5ca207d44179737da30aad090b
1132
setup.exe
C:\Program Files\Mozilla Firefox\msvcp140.dll
executable
MD5: b33902774ce0eded02b0cf1b54622736
SHA256: 8cabbd2ad374da8e58374c6915592d217966e7ea7e0d4038aa21a2d92a5a0612
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 7fa9423d1849948455f2fc9f0a96d7b2
SHA256: 9d85d8c191db68c9fbe8de0dac282e45dc98f26251888ffc9ece01ee9254290f
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: 9fb318cf19a44ef13ae5402f1d8247d4
SHA256: 730f8171e52ec6b6cd7301a4bde964f97596a04af4e7443f4fc65cc2c440dc49
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\lgpllibs.dll
executable
MD5: 0ed9e7559355c15b39e4636fd4344348
SHA256: f1c9e07595e44c2cbd471603b309c7fa6babf7a28ca06c4f380bab382f8ec8bf
1132
setup.exe
C:\Program Files\Mozilla Firefox\mozglue.dll
executable
MD5: 806885524d08d59f1c6a2e7608bbc0d1
SHA256: 79f7fe99e103b88fab57fc9a2e60b6e6311e98725920060fb21d11a8c7a66f71
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: c5a24baf52c2645de26b881db2828361
SHA256: ea545f265338dad581ff13c1dd2560d5555ead108b344fd64e9d59594646e2cc
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: a5ad74e07b7dd9985ebd945742dd951a
SHA256: 2f6e53078f58c3febc94045a55a24d4cbf75f49db39c35f55e2ed5fc995ccbab
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\IA2Marshal.dll
executable
MD5: 55bd606e396b40dad6956ca38d223b9f
SHA256: ddf57de69aa8791767b8a9263d3bb17df90a002c61a75a73c2604096fe180cfd
1132
setup.exe
C:\Program Files\Mozilla Firefox\nss3.dll
executable
MD5: 870d3248ff6b36c26728f4a723d84b59
SHA256: ed219fbb28b56f4780287e0eb9b65e28869e492572261a647b4dae58c8a44a74
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 8d58bc189a53de5cfdc0825f5cd79a5a
SHA256: 422f2e19574844837b7c6fe72ae16d119fccf217fb5f909c1dbba555c9d99f44
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: aa73f68027da44967b0d45110528e561
SHA256: 7766b4f519a27f93a6871761a7ec6da0a6eff5971680c8f8da836692239cb8f0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\gmp-clearkey\0.1\clearkey.dll
executable
MD5: d0c0fb49997619d7ac0d9532062f0ed6
SHA256: e691e0df8813b1b1be92d5b58b780d8f1594bbb0edbabab2c80ae4f8f8a2e93d
1132
setup.exe
C:\Program Files\Mozilla Firefox\nssckbi.dll
executable
MD5: 5f1f7dbedd75a0fa2fbc6607d134e8cf
SHA256: 2c5f0ad2e56e49d8a8ef5cd546cf37dc210839ff0e540634c3c36fc1e1e77b94
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-string-l1-1-0.dll
executable
MD5: 1ad74561da672bc860cc305f0cc94fe8
SHA256: f2c325383af283d780d8c7ebfc2fef831c967e26e83d39a35d5df43505a80d83
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: bd9cf95c6035238e0cc503a02444fe0a
SHA256: da3144e488cc4af877f3857dd09681dab736b7b22000984542058ab7c1e8373a
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\freebl3.dll
executable
MD5: 74ea2d9c5f369d34086da750a723d16f
SHA256: 8dd4061c22a7dd07d764c357e8540f490ba0bffa4ebb59a0aa890cb29e6426a8
1132
setup.exe
C:\Program Files\Mozilla Firefox\nssdbm3.dll
executable
MD5: 052a6a414b6a0db60c3cf10c13b57efa
SHA256: 6a6207ef3be5520893e5a0547becbb674bf282fb19edfa3bbef3f93b76e3268c
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: 81f09d71ab79e07d21930ecd57df95d1
SHA256: 8ee9dbe4cfdf102e32ba3f4061961a6af301ab952e4e864e17a8bcb7402a309f
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: e60f256fe916fdfd6147a5ea805f4df6
SHA256: c077169d68393bb4ab0c73c636233380193482c7dbb3e7f994cece906fc4dc61
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\libEGL.dll
executable
MD5: deb362354cc5ac9b01fae4aca9e6baf1
SHA256: ec32da7a80dc4a95c1a8413fd1852ae80ed73718e919e175b8dc64204410d698
1132
setup.exe
C:\Program Files\Mozilla Firefox\pingsender.exe
executable
MD5: ce111670e6b3ca6ea58d85e20fab1893
SHA256: f92216f65d6c96c05bcb4f2122e1655d823e466f6460a5aa73bc46bbadb46763
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: 50e68376a7d4d7840c6524a9c00fcdb9
SHA256: 9bae5bc1ce7bf82d52201128aa0ddc06d0394b0e45205af9b1e7319990b27aa6
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-file-l1-2-0.dll
executable
MD5: 04795fe255b13cd43508855045da9bee
SHA256: d77ff678f5c42e4e3a05268e16d28c0f46fbc8977a626cb21eb515fd8a7b4420
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\libGLESv2.dll
executable
MD5: 58c4f63130b4b515dcb9ea2e2718da52
SHA256: a441a1cad1a7117cf6a02176bdc79af24cb9f98beea6208a1d8a4b53cd2a1bb9
1132
setup.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
executable
MD5: 56feb33c09715a72ce79eea0752aeca1
SHA256: 09595bbfb5d16841eb066d93bb2f149ff76361f269e2952c8c1e2d9052b4114a
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: a5ad74e07b7dd9985ebd945742dd951a
SHA256: 2f6e53078f58c3febc94045a55a24d4cbf75f49db39c35f55e2ed5fc995ccbab
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-file-l1-1-0.dll
executable
MD5: 75882c45313bc7bb78bda029ae0e4d27
SHA256: 453bf1e608cf9115f2810f41fd0ac91451312bc1f68f97d360a5ad8b80b037ef
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\maintenanceservice_installer.exe
executable
MD5: 90e9dd5d965d3a90491b77d872224dda
SHA256: 34555a162117ce44e830634d6172c2f76ee6426291e84a5be4ee6c17fcc8b58f
1132
setup.exe
C:\Program Files\Mozilla Firefox\plugin-hang-ui.exe
executable
MD5: c07bcca5ac04e72bd6bb19961179b2e2
SHA256: 5c8a21f890899cd00e533273279f35a1ad85b27ec0c61d0591cd0c8c9d62da4b
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: 49239305d94b1b5efbb6f6967bb76c61
SHA256: 2fc3af6c78bce970d3098455c364164d1a008c7f991efbcb595a448ad5ed2102
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-file-l2-1-0.dll
executable
MD5: 3f9c8324c0f1dde2c51b4e9b79636bce
SHA256: a7023b95bfe24dc49dc6d48abb2ec8aad9ed14eb09c5a72127a1f1627ce61362
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\maintenanceservice.exe
executable
MD5: f042b2fe10c80d0999e3822acc3db75d
SHA256: d2728e0ca133f85ac61439713ea4139c7d6d20ac7b9e14a67519c6f8573f719e
1132
setup.exe
C:\Program Files\Mozilla Firefox\qipcap.dll
executable
MD5: d518aaa2d1d28207cb33d0dac29ba33a
SHA256: 20927a67552af55cec7d3ac2ae991144599dd29aed1a86a0c85cdd7490a7b0d6
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 69f6149abe55ff3be641137f7499e31f
SHA256: 0e953ba767d8fbda286bd1fdbc1e5a2b19c659227abd019cd60e1853e01de7d3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: e454d64b9dbb9364793d8d42603a2320
SHA256: 9b7ee5bf990cedfd0533a6b3f3bc0c6c42705e894b0e857f57f833d62eefd357
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\minidump-analyzer.exe
executable
MD5: d917fe837932192c9165160ec3545502
SHA256: c34b33001551aa8dd2a29a5fbff04a652f433d3bffcea7ee729fe15ee97c1298
1132
setup.exe
C:\Program Files\Mozilla Firefox\softokn3.dll
executable
MD5: cb1826c76092981a5a6aabcf4a8758b8
SHA256: 31d3534dddddf672d9ef078474c1936f705218d675eb5372ccdbaf39796d10dd
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: f827b6e4fbdffa25efd1e87c5809f4a7
SHA256: ef5a09fab070abf3233f4807c1c52ad79af59dee5ee51167558650a71008f6bb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 1c3bc439342c9a23bf6919b034f480b8
SHA256: 7c0c134240b203eb50e418e2f9e65d586bcc2e6b5023d3cec57eddef8152224b
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\mozavcodec.dll
executable
MD5: f74fa5a1f59ff27f35a2204d01665a20
SHA256: 19b82c4789a01ccae02d146ab8623979f5b5977cba83fd876d092b57b6afeeb4
1132
setup.exe
C:\Program Files\Mozilla Firefox\ucrtbase.dll
executable
MD5: 5d75a76b69aef6323e661cfa34148dbd
SHA256: b674c988f2ae373f03509aa4dca32c3d5ba40ede61fd5ff4aecbe96e248d7972
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: 9fb318cf19a44ef13ae5402f1d8247d4
SHA256: 730f8171e52ec6b6cd7301a4bde964f97596a04af4e7443f4fc65cc2c440dc49
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\AccessibleMarshal.dll
executable
MD5: 806655070271ccafbb4c876b5eb68800
SHA256: 538745db92bb3107331df70fddc78a522919ac4d16b5238ebb37205f754a4cf0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\mozglue.dll
executable
MD5: 806885524d08d59f1c6a2e7608bbc0d1
SHA256: 79f7fe99e103b88fab57fc9a2e60b6e6311e98725920060fb21d11a8c7a66f71
1132
setup.exe
C:\Program Files\Mozilla Firefox\updater.exe
executable
MD5: 020ff0cf3768d548252151e0a42c6bca
SHA256: d62b431d329002403d43eed6a5886ae01d14936db11473bf99f0c3692d2c4735
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: aa73f68027da44967b0d45110528e561
SHA256: 7766b4f519a27f93a6871761a7ec6da0a6eff5971680c8f8da836692239cb8f0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: 9d55d587218b6cb854adef10fe5247df
SHA256: ab507fb1e51881f1e6b3ef600442faadc4280833d5141498a2b7a514ea8d8f89
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\mozavutil.dll
executable
MD5: 5380af0d8ddbf111554d585ad3f35c27
SHA256: 619f913c46df9612d675a03540fa4966925a06697fe2f77563f23cb0046a08b5
1132
setup.exe
C:\Program Files\Mozilla Firefox\vcruntime140.dll
executable
MD5: cc5902b7b94f0e213e02225238723aed
SHA256: dacddfb8c14e2532f6418a3f6460e4206dc578a5338c540e340bc208a4e0685f
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: 9042c23f952275889348a916822a7758
SHA256: 1ac5c8dcd00ba1e8609b96ec8cc21ecc284f5a463af7cec849730dedce4790a3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\api-ms-win-core-console-l1-1-0.dll
executable
MD5: 59199f31338d10b0a8467db002c1cd07
SHA256: 9215a458e79c97d10db3efdf77bf097bc2cc7fa7ad73244453ea67bde70ad3ab
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\msvcp140.dll
executable
MD5: b33902774ce0eded02b0cf1b54622736
SHA256: 8cabbd2ad374da8e58374c6915592d217966e7ea7e0d4038aa21a2d92a5a0612
1132
setup.exe
C:\Program Files\Mozilla Firefox\uninstall\helper.exe
executable
MD5: 48ae6b924f51575cbe360679491b131a
SHA256: 1ffd6bcc0eb76aa68a7bc2c1cfb129ed3da5325e160a106f85316b41910b7711
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 015c4941eaf3f7ffd3f48ec640f3ec4a
SHA256: 8aa6f8acbab2f139a653c54d2c4f4563534ba1422bd1603dd95759d163b669eb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\AccessibleHandler.dll
executable
MD5: 6c0f74144b72108d0b3ed9c9157a7999
SHA256: 13742d27626fe54be315c01317eb609b5c9448b89564a3f162f36cb7a9af4d51
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\nssckbi.dll
executable
MD5: 5f1f7dbedd75a0fa2fbc6607d134e8cf
SHA256: 2c5f0ad2e56e49d8a8ef5cd546cf37dc210839ff0e540634c3c36fc1e1e77b94
1132
setup.exe
C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll
executable
MD5: d0c0fb49997619d7ac0d9532062f0ed6
SHA256: e691e0df8813b1b1be92d5b58b780d8f1594bbb0edbabab2c80ae4f8f8a2e93d
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: bd9cf95c6035238e0cc503a02444fe0a
SHA256: da3144e488cc4af877f3857dd09681dab736b7b22000984542058ab7c1e8373a
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\CertCheck.dll
executable
MD5: 2979f933cbbac19cfe35b1fa02cc95a4
SHA256: bcb6572fcb846d5b4459459a2ef9bde97628782b983eb23fadacbaec76528e6f
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\nss3.dll
executable
MD5: 870d3248ff6b36c26728f4a723d84b59
SHA256: ed219fbb28b56f4780287e0eb9b65e28869e492572261a647b4dae58c8a44a74
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\nsExec.dll
executable
MD5: b55f7f1b17c39018910c23108f929082
SHA256: c4c6fe032f3cd8b31528d7b99661f85ee22cb78746aee98ec568431d4f5043f7
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l2-1-0.dll
executable
MD5: 3f9c8324c0f1dde2c51b4e9b79636bce
SHA256: a7023b95bfe24dc49dc6d48abb2ec8aad9ed14eb09c5a72127a1f1627ce61362
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\InetBgDL.dll
executable
MD5: 73a0bec837004bc5ae5cd0a5b0d3bcf8
SHA256: 0dd38281a824298100b2bc89ee5b8a5c9cd9ec7a3b051dff42037a891fa7c534
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\nssdbm3.dll
executable
MD5: 052a6a414b6a0db60c3cf10c13b57efa
SHA256: 6a6207ef3be5520893e5a0547becbb674bf282fb19edfa3bbef3f93b76e3268c
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ns810B.tmp
executable
MD5: 6b1a2a0cf42150f657c485ed303f2aa5
SHA256: f320491b503bd30990a16dada0d5ab11c0edce1cd2194ed6c3046f276b5c0552
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: e454d64b9dbb9364793d8d42603a2320
SHA256: 9b7ee5bf990cedfd0533a6b3f3bc0c6c42705e894b0e857f57f833d62eefd357
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\nsDialogs.dll
executable
MD5: 42b064366f780c1f298fa3cb3aeae260
SHA256: c13104552b8b553159f50f6e2ca45114493397a6fa4bf2cbb960c4a2bbd349ab
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\pingsender.exe
executable
MD5: ce111670e6b3ca6ea58d85e20fab1893
SHA256: f92216f65d6c96c05bcb4f2122e1655d823e466f6460a5aa73bc46bbadb46763
2544
maintenanceservice_installer.exe
C:\Users\admin\AppData\Local\Temp\nsd82A0.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-1-0.dll
executable
MD5: 75882c45313bc7bb78bda029ae0e4d27
SHA256: 453bf1e608cf9115f2810f41fd0ac91451312bc1f68f97d360a5ad8b80b037ef
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\nsJSON.dll
executable
MD5: e89c7cd9336d61bb500ac3e581601878
SHA256: 431fc2ed27d0b7a1ce80de07989595effcc3ffb1dea1af6c0e178b53f6bd2f1e
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\plugin-container.exe
executable
MD5: 56feb33c09715a72ce79eea0752aeca1
SHA256: 09595bbfb5d16841eb066d93bb2f149ff76361f269e2952c8c1e2d9052b4114a
2544
maintenanceservice_installer.exe
C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
executable
MD5: f042b2fe10c80d0999e3822acc3db75d
SHA256: d2728e0ca133f85ac61439713ea4139c7d6d20ac7b9e14a67519c6f8573f719e
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-2-0.dll
executable
MD5: 04795fe255b13cd43508855045da9bee
SHA256: d77ff678f5c42e4e3a05268e16d28c0f46fbc8977a626cb21eb515fd8a7b4420
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\UserInfo.dll
executable
MD5: 1b446b36f5b4022d50ffdc0cf567b24a
SHA256: 2862c7bc7f11715cebdea003564a0d70bf42b73451e2b672110e1392ec392922
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\softokn3.dll
executable
MD5: cb1826c76092981a5a6aabcf4a8758b8
SHA256: 31d3534dddddf672d9ef078474c1936f705218d675eb5372ccdbaf39796d10dd
2544
maintenanceservice_installer.exe
C:\Program Files\Mozilla Maintenance Service\Uninstall.exe
executable
MD5: 1d8270f4b338380f0621069093ad226f
SHA256: 7a8c947d55c6188c842092d8d9942f39797af1db176d19ae011d2599e0c3a357
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 1c3bc439342c9a23bf6919b034f480b8
SHA256: 7c0c134240b203eb50e418e2f9e65d586bcc2e6b5023d3cec57eddef8152224b
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\UAC.dll
executable
MD5: 113c5f02686d865bc9e8332350274fd1
SHA256: 0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\plugin-hang-ui.exe
executable
MD5: c07bcca5ac04e72bd6bb19961179b2e2
SHA256: 5c8a21f890899cd00e533273279f35a1ad85b27ec0c61d0591cd0c8c9d62da4b
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ShellLink.dll
executable
MD5: d62d3e349689811f838dd10fb216eba1
SHA256: 5d103419245e2a5f124a96cace25d6836b2398edc0aa3919829b0fd6ad8b5d6a
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: e60f256fe916fdfd6147a5ea805f4df6
SHA256: c077169d68393bb4ab0c73c636233380193482c7dbb3e7f994cece906fc4dc61
2708
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsc4289.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\qipcap.dll
executable
MD5: d518aaa2d1d28207cb33d0dac29ba33a
SHA256: 20927a67552af55cec7d3ac2ae991144599dd29aed1a86a0c85cdd7490a7b0d6
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ApplicationID.dll
executable
MD5: 439928666a6baa4f9d2a1b0fb92265ec
SHA256: d43896c0c02bec598b7513b9a8815bb301c6b73da0fb2e0aee99146b4bd5e287
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: 9d55d587218b6cb854adef10fe5247df
SHA256: ab507fb1e51881f1e6b3ef600442faadc4280833d5141498a2b7a514ea8d8f89
3492
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsu3BB3.tmp\UAC.dll
executable
MD5: 113c5f02686d865bc9e8332350274fd1
SHA256: 0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\ucrtbase.dll
executable
MD5: 5d75a76b69aef6323e661cfa34148dbd
SHA256: b674c988f2ae373f03509aa4dca32c3d5ba40ede61fd5ff4aecbe96e248d7972
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\ServicesHelper.dll
executable
MD5: d0b5c37ca029913314dfc21924423c6f
SHA256: 6d2f1df00e70097a667f6020205bbfea67a4fd5e0c244f0400752b4671c0a3f3
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\uninstall\helper.exe
executable
MD5: 48ae6b924f51575cbe360679491b131a
SHA256: 1ffd6bcc0eb76aa68a7bc2c1cfb129ed3da5325e160a106f85316b41910b7711
3492
setup-stub.exe
C:\Users\admin\AppData\Local\Temp\nsu3BB3.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\vcruntime140.dll
executable
MD5: cc5902b7b94f0e213e02225238723aed
SHA256: dacddfb8c14e2532f6418a3f6460e4206dc578a5338c540e340bc208a4e0685f
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\InvokeShellVerb.dll
executable
MD5: 1a6e1ea7e90e50d9a18e034e7cde41a6
SHA256: 2fddc8b8ab4bf4838ea374d25e4cb9e83362c3f1cb24f380137d14c814d56169
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\core\updater.exe
executable
MD5: 020ff0cf3768d548252151e0a42c6bca
SHA256: d62b431d329002403d43eed6a5886ae01d14936db11473bf99f0c3692d2c4735
2200
Firefox Installer.exe
C:\Users\admin\AppData\Local\Temp\7zS89828B1A\setup-stub.exe
executable
MD5: ee4bb53da50a161a1ad3fe2c27388338
SHA256: 2346fc20e79be1395e60b4b97235282a40d901c8c866825cb90436af509f3ae0
284
download.exe
C:\Users\admin\AppData\Local\Temp\7zSC118D65A\setup.exe
executable
MD5: b30da39d6f26e9adbf8aeaeaee9ff195
SHA256: d72f75bae096d6beb1ecf6b7c53dd24ea2a8aa06e6c205d65901b4c40cdc4003
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\liteFirewallW.dll
executable
MD5: 2c8980aa8fad2477864defb3fde39ca4
SHA256: c58dc0e0ef677f88290ce8bbd014d0ef3f70e4fa07f484993e26352102462c2c
1132
setup.exe
C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll
executable
MD5: 806655070271ccafbb4c876b5eb68800
SHA256: 538745db92bb3107331df70fddc78a522919ac4d16b5238ebb37205f754a4cf0
2920
iexplore.exe
C:\Users\admin\Downloads\Firefox Installer.exe
executable
MD5: c54895510e1ec8a46a1ef42b8dbcc040
SHA256: 583f28b1764c19c7740a1c93d64c99424f0739ea9695b4b535f2542e8f5a42e3
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\UAC.dll
executable
MD5: 113c5f02686d865bc9e8332350274fd1
SHA256: 0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.9.1088\widevinecdm.dll
executable
MD5: b3fdfed271b807e434140c4492785f2b
SHA256: 5d2ceb3128260bc1eb7d341414d623487d7120b2fe4abd2a02b81e000874ba50
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\CityHash.dll
executable
MD5: 737379945745bb94f8a0dadcc18cad8d
SHA256: d3d7b3d7a7941d66c7f75257be90b12ac76f787af42cd58f019ce0280972598a
1132
setup.exe
C:\Users\admin\AppData\Local\Temp\nsy76B9.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
1132
setup.exe
C:\Program Files\Mozilla Firefox\AccessibleHandler.dll
executable
MD5: 6c0f74144b72108d0b3ed9c9157a7999
SHA256: 13742d27626fe54be315c01317eb609b5c9448b89564a3f162f36cb7a9af4d51
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-core-console-l1-1-0.dll
executable
MD5: 59199f31338d10b0a8467db002c1cd07
SHA256: 9215a458e79c97d10db3efdf77bf097bc2cc7fa7ad73244453ea67bde70ad3ab
1132
setup.exe
C:\Program Files\Mozilla Firefox\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: 69b12f5c338b0138246b6443a5997eee
SHA256: 11e69c46f7763a393de3586450f5a53353c56949ec69cbeb9c56b4a93559cad1
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: f2f2a749b868749a6f3ecec95ae0175c
SHA256: de5e6e71f77a36a075da9965604b8ca787fed696c289b3058772c26e85bd11b7
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++www.google.com\.metadata
binary
MD5: 586c76f573c3d839b29b66631865691d
SHA256: 441a512eefadfa730869a32dc1ea8134c799b5250d816d2a3ebb1bbce4856d1f
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\https+++www.google.com\.metadata-tmp
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CB5A4F33D4F9F4B6BA8DD50F46634FF3303B0DF1
woff2
MD5: a4346b0326f5c5ce63d548585ad84460
SHA256: 9d421279891140203925021baa9a78bb74e59c6048c75bd926cd124314ec836d
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\36410AD08894B9ED1D2EE50931051BF813B4DFC5
compressed
MD5: 0600f2f790c872f7114c90cd5a79a440
SHA256: 041de1425d8aef8b05c94ad6e7fa405d6563a5e308b75c1a06d89716edbd5246
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7DDE59F39CEB120233DC6C53581C1C7A9CCA9749
compressed
MD5: acdef122c79e65a0d1db5b9290c9f255
SHA256: 98255d5a26df57fdd3f3e32cd12dea266f854923d08d7d6745a1eeab72c9fb66
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8B1DFB2D1BF61CA0366C797106DF4E0A7BB3F11F
image
MD5: 2ab1a4e3078a5d48037a757ecfc5bea9
SHA256: 7bf230c8e27ebbde09538d9a965da99716ac671ae6d0354fc33b1cbb498aff52
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\82B4BB584B56A74539DB923BAD895E653CEE7953
compressed
MD5: b6f6125ed1de8119aa2d9197eb0d2122
SHA256: 8a11e8fcbadbf33fe4f48909fc6694755dc29350d4aa7e4a16a65fa2e52ee3d6
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C1A913C0CF76902CC53CDF7E94AA9379D986B1ED
compressed
MD5: 4802491ea57168890e3b28e8436f1296
SHA256: 137b0f827ba5b363011c060fa6a1a6273b4a70074726771b42419fefd78e5463
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B656A077A8C4FBAE853DC8C1833339F5B650B01B
binary
MD5: 53691fcbecd273bf7b5fabd0d70d410f
SHA256: 5828bbc222f7b7cbe86fac56bd0cb95c598755cbdf3f70068df0c81af01a034c
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C1A913C0CF76902CC53CDF7E94AA9379D986B1ED
compressed
MD5: 3434633de22c0e592b1bb05819900017
SHA256: b482efbf662492217a00286a5873b906ace5531e54a9de10d84b96435b5be0fc
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7688A15618B1053D4650F96D032CE385E539D2FC
woff
MD5: c70a7afcc567986a36788f2f69a88199
SHA256: fb296574509aa26dbe32dddc9c52b5344530eeedc4cafdf1d566a86849e7a6a9
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E5D069D1C65114D7944C42CF6022EFFE5D83BEFB
compressed
MD5: 815c08483e2bc38950f1d6c9b18ed61a
SHA256: 31682281de43db0c964696beed536490f19a09f2f6d8c3d87eb5ad128c0eaef6
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6FB2ABC6C89B16FD957DAD872526ADA754885B3D
compressed
MD5: 7fa66b7c7d836e30d3fb276681fb0d09
SHA256: c1d7ecc6b83f65190d68d681715d8f15e4e14d9c9de9cb6ac084761759246c17
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\298CCA0ADEE113F0A37CE81C679D39A2053C874C
compressed
MD5: 6df04eb99bd88c45577dcb3f2cd3eb0b
SHA256: 484cd4006cea3adf5943dfa036d60945580e86bfb52937ae91acda4b92b7795d
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A6B6D8854E0DF1BD709521CCF24AACEB1B347B8C
image
MD5: 7afa066dcc45f993fc4924d9610d3ba9
SHA256: 8052d07fe8041308a99dbc07328e7b5ab912197c9f7d80b9f9bf4597e5e9f263
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C58B030C00768030A441DADE4B25C51DAFBAD3C6
image
MD5: 6e5c1dc32531ffb04286f550adfd3fb7
SHA256: 4f4d9aa9bd3aaf932c3fff981b277e2c7c958ce5cacc9812b4c64661020f66ba
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\51D136996345DA99A2C877CD1FC75D11B03288AF
compressed
MD5: d442dd29274869cf6b7904b8739c28ea
SHA256: 697c5da932f4674a9eafd44e10b35d6bd3b56908c2ecca02e7d35464bd748656
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\77E008619F4F92C09E7CB593833D068F30FC08AA
der
MD5: 4e11aba2f536ee7460617c630fd8014a
SHA256: ea0b467c2ef90f8f153ff3ac2c4d64d775a524321283338c3a92d8965dc1ce73
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\825674A4452550B0096F71363227688F6A5B1833
der
MD5: 5a119f9f866a05150342a93de32fa6a6
SHA256: f99b8280941a371ee410d6f4da2a8b636eaf3fa5bf8c829ee4b95cffcf568def
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F2B97F92E3F70C27A0378A907B735F535AEA1D45
der
MD5: 3cfb2063fc2c4c35504d07d5670da3f7
SHA256: 7c90694c8d5a7bf597c21acef1040c70affa5ab49a76c72009d041aee82999de
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1A4089C9457019CA78853D28EC8FA0657944591D
der
MD5: 7d43991158d368e47b882b8fd42bc859
SHA256: efdec034d140fb5068fd67995e76e38d748cdf8c2794235d16170b2fa87f3e90
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0D4C2954119BB629608C4FF16F3F3D7718897A1B
compressed
MD5: 6cef794fb03352f0e3f8022309f9a2a1
SHA256: 142c03a1e01aaa4f5bb44c2e8c6ce0fc9fe3465eee1d86db1397569ed5bc9b57
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CD35BF9ACAF0F80ADCDD6E5CB0C9738D3693D033
compressed
MD5: b5f4cdc4906b759581cc05e53a6b1de6
SHA256: aa4ccf8744dd71787d9906ed0dbe0c3171aab6a860e7336b7373649c81e75636
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2538DC9DC0F9ACC902677769A3FF8CAD9B13B6BC
der
MD5: f3ca538bf4878e15f55764b91a0a39db
SHA256: 5a970c6ef43af7af20876045cc9aadc494ce865a3de24a8e6e639c08a13d8cc4
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F0B5C031AE23204AFFB554CE783DAEDAF90803E3
der
MD5: 613ed5be3eae9e8fd7e55254653b4150
SHA256: 3d1c2df5a9b9a51afaba7b54870eeecac49b561a11fc2b4bf1aee150a7608a48
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EBDB640742993C5789D67DFE4A451AEC70D8AACD
compressed
MD5: 71c10520ba4ff4fd7d250d474268e5bd
SHA256: dff69ea4fc2098206e2936cd62160163f2ffbc3e7cea6bb7a167e3554edd416c
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3A95FBE646AA177906BD7107F0B21128E440F98D
der
MD5: 0c15fb69b4a6c416bd9e664883982188
SHA256: e66ccfe9cd7cf3b94feefd9d4db4be21b0f091a846aa1ff9d9c7a0e4fa73b5b9
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CA524AC83D0767A28F09A30E81C3940914C6B064
binary
MD5: 9bbdba599ca02203ce754de2978e2c2f
SHA256: a16eda27f37d3570c512a07ec7cbc699d52a0c02fe25a1189c631a8bce6698f6
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\02777B998A811E25E9B87A963C532169D419822C
binary
MD5: 9b2298833ed55bbfbcce5ac0b63fd7e8
SHA256: 7021af87a82b7ce39089c524b7cfe1f067804e6ba092a0bdfecbe0a0f4c2880f
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: ba6bd4188f20c482a0e5f6fcb86f66af
SHA256: 6a7fd0a37c13cfcd17ac10aac1e35c18d3c677f05bdf896dd6f4319091b61803
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: c5d341c341bdb81162cf458f91efb388
SHA256: 4a96ffb6e3c315d0f2a52c36fc10caa3c5743e89379f21730e83045a64483a70
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\61AA296D88C2C6C81AE53D1FD7E1992C3ABCBC31
binary
MD5: f910540570c8c6c87679aef82c1e1218
SHA256: f08b440d0a2527074ebdfebf4b4ac6337e736f0c28faff53c5fcf2fd84c2c49f
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2C591322F46B97FE966107846308DD1B82E6BCAF
binary
MD5: 1eaa5648b18e0a8b59725b9442ef021e
SHA256: 4c6869c98acccdc41a9f366c1defaaa2f19907e1e4656bc548620b91aa9e6628
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6FCD00F7D189EDB8AEF761BD7CBEBC18C4FE5FFE
binary
MD5: 1e568b2be27baa78d52783f056423fa7
SHA256: 3cec51d0168af1b81e46c8b746b74eac82a8da1b77d277ea4e74e9ec614865d8
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4508064A6DA66EACD0958A25F46A80F0B16B5598
der
MD5: dca81b72eb83c616bf7afa8195401f3e
SHA256: 9f1e6e40c6cbd4e758fb8f326037b8c9b50483bc0dbb7d095fa2613adac386fe
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C68BE9F9588938F51C1798BEB03E95046BCD0580
der
MD5: feb125cd6d99c958429350cb160fa674
SHA256: dee971ba62c75e31b73b2733f9d343d99c2f711d3c708515c34efcbce48dad4c
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: b7f61cf3f11466b3c1b063b12f13613e
SHA256: c7a11c9816967f6c963c076e83ed1f81d15ce8cf00507468d119420cfab2d19e
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F2B7DAE44C4EEC79A0BE0F6D7A187F980BE22BD6
der
MD5: d9d14828c010f38d57328518af2cf182
SHA256: d44912ff2e83180156d3a14d42095c9316f90bbf3e638584a4aeb1735746fc09
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\148B718A7B423BAF84743D9B0E02F9DE680BE5A7
der
MD5: 6a30409c3ac246d9589e8f51161bf548
SHA256: 24a1dc294e624540c628bcbc0312be480856b9131eb3971f611d16c99b34a61d
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A6D45CE508F445AA471F34888001627906F5B797
compressed
MD5: db8d39680969a89da5561e8681f5ac0d
SHA256: 3afeb0ba4925edd5c432479a9cadaf126fa62a86ec0c7e5af544bb384062b5bf
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\88010B03F279648860FC210C854B55E644E0F854
compressed
MD5: d77bfcff160facaf0792e2403d60deb3
SHA256: 2f3f4e31c9dcb33498e7982b318338adaaf9f6d295baf4459660036e29ce10a1
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\47DE7604B80D5AB727A1D64495F813CD99ED2670
image
MD5: 063ae1205895a8c163fae112d6cc056b
SHA256: 9d84ab1732c0be5950c63a873ea2e48c4a5392f55b23703aa5bba8c907a019f0
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CEE1FC16A752B2E2460E4579345F0C96FC3DC077
compressed
MD5: 0387849c5eb020aa176047b503207ac9
SHA256: 0f162148e72e1b1d3e169a27561c5d63277e51929f70f0c17648560996d04203
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\099890660B12CEEAF2BD9B0B4626598C389B16AE
compressed
MD5: 0c40d89bf17155b9b0d306e00ac16ced
SHA256: 6622bbf64a603d76c6dda43379ef34906aac3595a0aab431ac95e9273b8f842c
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BB433C04465D91AA31DB6DC8673E10A7D1D6B664
compressed
MD5: fa6f3ee0ce8f70ea3e1daa3f0bc499aa
SHA256: 04d6cab2a5a0b81fdbaf4ad0e0e1fb229f5a290eb501e61a6ee32422cf72fdee
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B87C7CBAECB08556A2A75B749061C1AC13D7F265
compressed
MD5: c640d78c058ee42013c1dbcadc87fa3a
SHA256: 275e52b467630769b06a21139ebf4b3d15d1eb567be67300b5f9b612c7e47f8d
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9BF34431899AF47BD398DDC153F062924ED621AF
compressed
MD5: b29298f1924fa052c3df0ae900ef1cd9
SHA256: 848884cfaa7bf40f58a21a0be07eb4aade05ac14773c2829245085e674c72429
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: dbd315ef1c096c39850f37d5f3d25099
SHA256: 3a74e4ce1de8a21469dbcf8c75afd8e4671e9b375d112901c4c8e45dfdde9a21
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B783D66F38FA08084A497888B34972325D844E67
compressed
MD5: e56f8bf9224b498c70b9a110a67d6c9d
SHA256: f34c28cf61fc455687f50b9d3b1608c822dd1a223f2360df82e75efb6a4f7514
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E144B3CF73CE2AE1FB0AC26C66F01FF461549CBF
compressed
MD5: aded968d11e33d51017410ed9d244011
SHA256: 8d396866e98faff0d3d047f334e5fba4789731fd3c8b03994529bcc512a15b11
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\85BD63FF08F6AE3E2B438D2E9C94C0CCABCF412F
der
MD5: 011ce04f62552070dfc8939c03d65db4
SHA256: d2cb347ad38a597c4dbc9d37ae676b7aa133be71808e4d846b69d5444b623daf
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CEE1FC16A752B2E2460E4579345F0C96FC3DC077
compressed
MD5: b4c0ff101fe5592a95f25db664d7c76a
SHA256: 08afd4406035342b9e19a06b9d9c49f57e482275184a463b3f585a5bd4249df1
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: 36652a0e70e6675928195618c248491d
SHA256: bdbec23e006d63a30717baef7537138f14b2e22c1e90371138a4ddf3c5480e75
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\87A492928CE2EB0110C3FE211D63ADCC30E74882
image
MD5: dff16e96ebcde3c6b98cb0358aa9518e
SHA256: bba418599fa7efaa849a235b4dadbc3d451d4431987151ffd094200134fa05d1
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2BAD4CAE4357DB769583D2861BC03B1C06ACA044
image
MD5: 3ebcd9ba3a430dc723ea0bfa5d26fabd
SHA256: 63cd65a4726f36e07fc7b033627ad4c3c4bbab79ea10feac56bbb33c45b5ca7b
2132
firefox.exe
C:\Users\admin\AppData\Local\Temp\mozilla-temp-files\mozilla-temp-41
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B5DAB6CF8B2872A35072376047AC64D2EAE99DE6
compressed
MD5: 8c5c0e047efd9de28b72ad07087a9a8f
SHA256: 494e80e5c7bc08a11207e0ea5b35f39ecd3d8bd520f76723b6209f4f35833e3c
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\83B82338841B1EA440FAB0F82B9DA0AD93BAF20C
compressed
MD5: 88ea52aeafa62f35fdf1252928262607
SHA256: 94f601448f90a667ef0d7b2d7a7903af77b4a13382c7e0ec47863c1cc8a6c714
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F6A5C2A142EDDF7FACFC7E85F757466F4592CA2A
woff
MD5: 1a0ca67ed21ea5777d4be5c13102af75
SHA256: 7399e28c7979dde35d7fc7f9f6de7b3a618b5d0080ce36752e5fa908e3618a13
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\87D22879192FE5D7EBCDDC9E475CA74B727C8800
compressed
MD5: 49672fa13d3b402febd4ec5cf8c0cd1d
SHA256: 5aed6b7b8e504f1b39b356c73a24342de252a55cc37d2ea7df5d79ae6b8a1c64
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\6FBD5863EC4AB545C5A70EC9F0166ABE9E8C5CF2
binary
MD5: f24317c56b6965c5a264528f518e443c
SHA256: 1267c89e7b0b3d6ecb9257a9ce7b4dfb7ad85a16798fae6d654c2acfda3d1fdf
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2C89B481C61D1288322AD02A02A14CB3C4CC2BC3
compressed
MD5: 0a6721a4fb9f28f90f6c967b6ff05ddb
SHA256: 0477b4740135c5b450e871404d72cd1b958b33f0c985c077e372696bb73c2d2a
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
binary
MD5: 24d9c535e57f3cd673d5c21765b28f3a
SHA256: 3bfdb92dcc347eb792ffdd1645cbc302af3b9f9eb98a19eb30751a16956367f5
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7F8C746C9323141B6465612B0209E46D0A981BC5
der
MD5: cc14f94da5917bc3ec4a354bfa08af4d
SHA256: 6ef4463858f3d16ada025ad70a7af08230b9bf1c7085d29a1e62f13cd4c10e0f
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1BD911A4E3AF6C3A592D8A511763A94D21A9DF74
der
MD5: 4ab5b93d1b0c7ee0a88d554d3356249b
SHA256: f9bd126d98aea6d492c4c5ce05a4c68cc3320ef1675ea9f75993aea33f0b1b2c
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9F2D973D81FCC185C1FE2DDC53E924583316FAF6
binary
MD5: a5e420ca8e23f9d9ce9ec5a84dc91e46
SHA256: c86ee1d5b2ffb67a0588b55ce2bbc9ed421e32c9442d5a96a13b7a9ef5467e3b
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 332aff94fc65d1fe85094f73f3fc84ec
SHA256: 3979c1277ff093a9287f4f564944a01d8644fec01b3ae652b2d092bfbc2b552c
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite-wal
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: c513f243baadeb352d1631341030d338
SHA256: 15a3b04aef3f550cabeacdca9216289c8afe0715714b42a09bca2ed204d5bca5
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 1e44c172f3c7c61780492cc885001d9c
SHA256: 027715a39666331a128e64a2c8c9ca4e2df2609b60f16d5e81b8e66eb8e73423
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-wal
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: cbdb739a87e6bd41754836de8a5cdb7a
SHA256: 51afa4a1ba3949544d419b8bfebf33b9f71db1719e3db309a1b29409b8d2147d
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-backup
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating
––
MD5:  ––
SHA256:  ––
3776
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.pset
––