魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
URL 2018-05-21 23:10:31 2018-05-21 23:12:53 142 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-hpdapp03-1 win7-sp1-x64-hpdapp03-1 KVM 2018-05-21 23:10:31 2018-05-21 23:12:51
魔盾分数

2.5

可疑的

URL信息

URL http://www.hym68.com
VirusTotal VirusTotal链接
VirusTotal扫描时间: 2017-05-20 02:29:10
扫描结果: 0/64 (展开)

特征

创建一个隐藏文件或系统文件
file: C:\Users\test\AppData\Local\Temp\etilqs_QpIBMFnawBXurQW
file: C:\Users\test\AppData\Local\Temp\etilqs_1HWxUeVSYTmP3Xg
file: C:\Users\test\AppData\Local\Temp\etilqs_YxKZUe9Psd9Lw4G
file: C:\Users\test\AppData\Local\Temp\etilqs_kbvTcEcXQDYgM9t
file: C:\Users\test\AppData\Local\Temp\etilqs_IhnIKPAL9xXVgbY
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF25aa1d2.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_f65XMjRotyyY4QQ
file: C:\Users\test\AppData\Local\Temp\etilqs_CFSJc4kJOzHoHgR
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF303757c.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_YICU7pXlUa1Aauo
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF31114c0.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3158715.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_pYdWcKVN2p3As4I
file: C:\Users\test\AppData\Local\Temp\etilqs_INBmeoMceeVGLQU
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32afa0b.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32ea68f.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33323dc.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33b4904.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3437be7.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF350178b.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3501c06.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc546.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc7c2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF363f2b2.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_Fcc9Qgg7Mi0FC9r
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF386c6e0.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_ajGC3wOU0npN7fW
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF38cbb79.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_ZYLfWhWl518UW5q
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3d9558a.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_hAbCb3PIBrt6Ukp
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3e90ca2.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_Xk0VQFPgf3BJnGQ
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF41239d1.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_Bdb8ZuxBIgySW33
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF44b65b1.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF45319c2.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_4m3xtu0PsILfoID
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4591b0c.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_cJEkIDbl0nFmP9f
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4978c11.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_YcWw91wM6psi6Qb
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4a5e15c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4aa9873.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_PoDaPdNSia6BV7S
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4dadf06.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_MI3IE69MTTadbbf
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e271a6.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_EHNKWfnMhd0Q7wq
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e6f9d2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ef1381.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f0e83d.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f8dd6d.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ff28a5.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF50cc682.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_vhe6qHwFjY4QMGn
file: C:\Users\test\AppData\Local\Temp\etilqs_mukbeQpa4o69eN4
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF529d3ac.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF56ed8e4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a12436.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a1eb99.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_R74e8dafqNXIU8W
file: C:\Users\test\AppData\Local\Temp\etilqs_v8tXZozQqpzEkcN
file: C:\Users\test\AppData\Local\Temp\etilqs_VbstY3df9uI0TRK
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5d5ff0f.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_C6PNmCeaPjLdycO
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5e0f855.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF604b364.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_RKZafrImALFaT0t
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF60cc9c4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF615aeeb.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6230313.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6277188.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF62be1a8.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6305405.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF633f7df.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF635cfdb.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF637a7bb.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF639862c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647afdc.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647ee22.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_XsLn5lJFfSqf5hB
file: C:\Users\test\AppData\Local\Temp\etilqs_XA7135xAcmrUepT
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF68790cc.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_seZVFxFwZ9V6zfz
file: C:\Users\test\AppData\Local\Temp\etilqs_aDJF8Vufl4yQScA
file: C:\Users\test\AppData\Local\Temp\etilqs_5fkdGg4A9dEheXU
file: C:\Users\test\AppData\Local\Temp\etilqs_KJJv7AFAT5TBIxY
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF70f3d2a.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_G8cVGNpOTJGqJZ8
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7146db8.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_lbJVOruSJjsUaaJ
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF72bc1d4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF731e63a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF734af67.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7393729.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73b0812.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73cea5c.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_zV6yexR5K4gdStt
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74fd138.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74ffb59.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75a7aed.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75c5615.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75e4b05.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7601261.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF761ea4c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF763c4ad.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF765a058.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76775aa.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7694aae.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76b22f2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76cfe1a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76ed966.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF770ae52.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7728329.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7745d94.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7763283.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7781ae8.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77b4ef1.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77bc801.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77dab85.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77f8562.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7815df7.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7833b0e.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78512eb.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF786e6e4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF788be2c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78a9452.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78c7b6d.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78e4942.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7902710.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF791fa60.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF793db7c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF795b0b0.TMP
尝试通过重复调用同一个API多次以拖延分析时间
Spam: firefox.exe (1160) called API GetSystemTime 45337 times
Spam: firefox.exe (1160) called API GetSystemTimeAsFileTime 55720987 times

运行截图

网络分析

访问主机记录

直接访问 IP地址 国家名
122.114.6.195 China
180.153.105.155 China
180.153.105.162 China
220.181.7.190 China
47.95.49.43 China
58.215.145.224 China
58.215.145.225 China
58.215.145.226 China
58.215.145.227 China
58.215.145.228 China
58.215.145.229 China
58.215.145.246 China

域名解析

域名 响应
www.hym68.com A 122.114.6.195
discuz.gtimg.cn CNAME x2.tcdn.qq.com
A 180.153.105.173
CNAME discuzstatic.tc.qq.com
CNAME discuzstatic.tcdn.qq.com
A 180.153.105.161
A 180.153.105.153
A 180.153.105.159
CNAME x2.tc.qq.com
A 180.153.105.162
A 180.153.105.147
A 180.153.105.155
A 180.153.105.156
A 180.153.105.172
hm.baidu.com CNAME hm.e.shifen.com
A 220.181.7.190
cdn.vaptcha.com CNAME cdn.vaptcha.com.w.kunlunso.com
A 58.215.145.246
A 58.215.145.224
A 58.215.145.225
A 58.215.145.228
A 58.215.145.226
A 58.215.145.229
A 58.215.145.227
api.vaptcha.com A 47.95.49.43
www.zke6.com A 193.112.87.40
www.pgyer.com CNAME bj-lt.pgyer.com
A 120.78.242.5
ym.aekm8.com A 120.79.231.57
cdn-daikuan.360jie.com.cn A 58.216.107.101
CNAME 820.dispatch.spcdntip.com
CNAME sp.splink.spcdntip.com
CNAME cdn-daikuan.360jie.com.cn.cdn.dnsv1.com
www.66xianbao.com
www.qukuailian5.com A 45.249.95.22
www.yangtianya.com A 115.28.141.1
www.weiqingbao.cc A 101.132.98.177
www.yangmaoduo.com A 115.159.59.218
www.work28.com A 58.64.203.104
www.vip008.cc A 58.64.156.147
www.360shouzhuan.com A 121.43.147.217
www.xiaomiwz.com A 104.27.181.189
A 104.27.180.189
www.alaiwz.com A 120.52.19.108
www.wzdquan.com A 118.99.47.11
www.zhifuwz.net A 59.56.78.58
A 183.131.214.49
www.wangxiaoran.cn A 106.14.176.204
www.79tao.com A 47.97.201.248
www.xiaowwz.com A 47.100.31.36
www.machaojin.com A 120.79.67.158
www.lzitb.com A 116.255.151.221
CNAME 399589.vhost388.cloudvhost.cn
www.jbtai.com A 58.211.137.66
www.hbw99.com A 122.114.121.91
CNAME 69306.vhost16.cloudvhost.cn
www.shukoe.com CNAME ew-2mrk6fjt7.aliapp.com
A 121.199.250.220
www.jishuyl.com A 123.129.224.8
www.jiadianxi.com A 101.37.42.184
CNAME il8kdmklsgxu4zk8pazlfqcqegfwzaug.aliyunwaf.com
www.yuhongwang.com CNAME www.yuhongwang.com.w.kunluncan.com
A 220.181.105.154
www.peizizhijia.cn A 120.27.237.227
www.bihang.com A 101.37.189.111
www.163erjiw.com A 103.229.127.67
house.leju.com A 123.59.190.249
CNAME proxy249.leju.com
www.card111.com A 103.39.155.138
www.hc360.com A 182.108.171.241
CNAME opt.xdwscache.ourwebpic.com
A 117.21.168.46
CNAME www.hc360.com.wscdns.com
A 218.87.111.64
www.huoyuanjd.com A 47.52.44.72
www.sojiang.com A 121.43.76.157
www.vaptcha.com A 47.95.161.213

TCP连接

IP地址 端口
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
122.114.6.195 80
180.153.105.155 80
180.153.105.155 80
180.153.105.155 80
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
220.181.7.190 443
47.95.49.43 80
58.215.145.224 443
58.215.145.224 443
58.215.145.225 443
58.215.145.226 80
58.215.145.227 443
58.215.145.227 443
58.215.145.228 443
58.215.145.228 443
58.215.145.228 443
58.215.145.228 443
58.215.145.228 443
58.215.145.229 443
58.215.145.229 80
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443
58.215.145.246 443

UDP连接

IP地址 端口
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53
192.168.122.1 53

HTTP请求

URL HTTP数据
http://www.hym68.com/
GET / HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive

http://www.hym68.com/data/cache/common.js?gO0
GET /data/cache/common.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
GET /template/sxpxb_a5/css/sxpxb.css HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/template/sxpxb_a5/css/sxpxba.css
GET /template/sxpxb_a5/css/sxpxba.css HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/source/plugin/htt_qqlogin/template/image/qq_login.gif
GET /source/plugin/htt_qqlogin/template/image/qq_login.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/cache/logging.js?gO0
GET /data/cache/logging.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/cache/style_5_common.css?gO0
GET /data/cache/style_5_common.css?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/cache/md5.js?gO0
GET /data/cache/md5.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/plugin.php?id=aljrq:xintie
GET /plugin.php?id=aljrq:xintie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/plugin.php?id=aljrq:ht
GET /plugin.php?id=aljrq:ht HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/plugin.php?id=aljrq:view
GET /plugin.php?id=aljrq:view HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://discuz.gtimg.cn/cloud/scripts/discuz_tips.js?v=1
GET /cloud/scripts/discuz_tips.js?v=1 HTTP/1.1
Host: discuz.gtimg.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/

http://www.hym68.com/plugin.php?id=aljrq:dantie
GET /plugin.php?id=aljrq:dantie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/plugin.php?id=aljrq:dtviews
GET /plugin.php?id=aljrq:dtviews HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/plugin.php?id=aljrq:pro
GET /plugin.php?id=aljrq:pro HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/home.php?mod=misc&ac=sendmail&rand=1526915448
GET /home.php?mod=misc&ac=sendmail&rand=1526915448 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/static/image/common/qq_bind_small.gif
GET /static/image/common/qq_bind_small.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/template/sxpxb_a5/style/logo.png
GET /template/sxpxb_a5/style/logo.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/logo/5zhe.jpg
GET /logo/5zhe.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/block/ad/ad143894ac3a52f4b11a092b21783a1d.jpg
GET /data/attachment/block/ad/ad143894ac3a52f4b11a092b21783a1d.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/block/98/9875472b0f9450afd0fa2f1869907675.jpg
GET /data/attachment/block/98/9875472b0f9450afd0fa2f1869907675.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/block/29/29fa98f0d8c0a9b6383fb2642c2180e3.jpg
GET /data/attachment/block/29/29fa98f0d8c0a9b6383fb2642c2180e3.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/block/88/88c81d8d3f9b02d5d4ef354b1b3b66d3.jpg
GET /data/attachment/block/88/88c81d8d3f9b02d5d4ef354b1b3b66d3.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/block/d3/d3069303435fb3aab51ff7be956ef97e.jpg
GET /data/attachment/block/d3/d3069303435fb3aab51ff7be956ef97e.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201704/20/202044xiv3vf22fvv40xo8.png
GET /data/attachment/portal/201704/20/202044xiv3vf22fvv40xo8.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201803/28/144403e0vq424y0y8b4h4z.jpg
GET /data/attachment/portal/201803/28/144403e0vq424y0y8b4h4z.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201803/15/091808rxcpg8zn278p78nn.jpg
GET /data/attachment/portal/201803/15/091808rxcpg8zn278p78nn.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201803/18/181338hwnaxqzsh3lohhae.jpg
GET /data/attachment/portal/201803/18/181338hwnaxqzsh3lohhae.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/forum/201804/11/105109d57s1svs0u7fsihu.jpg
GET /data/attachment/forum/201804/11/105109d57s1svs0u7fsihu.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/forum/201804/18/005522a4mf22166m6wlmu6.jpg
GET /data/attachment/forum/201804/18/005522a4mf22166m6wlmu6.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/forum/201804/08/110407ad3lmqnnqp8l8dbp.png
GET /data/attachment/forum/201804/08/110407ad3lmqnnqp8l8dbp.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/forum/201803/28/075921in9fu5uyffz11he1.jpg
GET /data/attachment/forum/201803/28/075921in9fu5uyffz11he1.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/cache/common_extra.js?gO0
GET /data/cache/common_extra.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/data/attachment/forum/201803/08/104705nyjymbdefn2j9eeb.jpg
GET /data/attachment/forum/201803/08/104705nyjymbdefn2j9eeb.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/forum/201803/08/235432tvmf7oacpc30a2cs.png
GET /data/attachment/forum/201803/08/235432tvmf7oacpc30a2cs.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/uc_server/data/avatar/000/00/00/01_avatar_small.jpg
GET /uc_server/data/avatar/000/00/00/01_avatar_small.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/uc_server/data/avatar/000/00/00/02_avatar_small.jpg
GET /uc_server/data/avatar/000/00/00/02_avatar_small.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/source/plugin/aljrq/images/lj_hash_39.jpg
GET /source/plugin/aljrq/images/lj_hash_39.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201711/29/203005fyz9n4bog445uyhg.jpg
GET /data/attachment/portal/201711/29/203005fyz9n4bog445uyhg.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201703/30/132747uuhphnfk9838ukku.png
GET /data/attachment/portal/201703/30/132747uuhphnfk9838ukku.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201705/24/101242fq3wf76g7bqxxjw2.jpg
GET /data/attachment/portal/201705/24/101242fq3wf76g7bqxxjw2.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/data/attachment/portal/201711/04/122314bxx99g93gr0v98uu.png
GET /data/attachment/portal/201711/04/122314bxx99g93gr0v98uu.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/static/image/common/ad_close.gif
GET /static/image/common/ad_close.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/logo/45.jpg
GET /logo/45.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=D2cm7i; GvhJ_2132_lastact=1526915448%09portal.php%09

http://www.hym68.com/template/sxpxb_a5/css/img/index_icon.png
GET /template/sxpxb_a5/css/img/index_icon.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/template/sxpxb_a5/style/ss.png
GET /template/sxpxb_a5/style/ss.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/article-540-1.html
GET /article-540-1.html HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663

http://www.hym68.com/data/cache/style_5_common.css?gO0
GET /data/cache/style_5_common.css?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4
If-Modified-Since: Mon, 21 May 2018 05:52:29 GMT
If-None-Match: W/"5b025e9d-158b0"

http://www.hym68.com/data/cache/style_5_portal_view.css?gO0
GET /data/cache/style_5_portal_view.css?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/cache/common.js?gO0
GET /data/cache/common.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-d95d"

http://www.hym68.com/data/cache/logging.js?gO0
GET /data/cache/logging.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-186"

http://www.hym68.com/data/cache/md5.js?gO0
GET /data/cache/md5.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-13e7"

http://discuz.gtimg.cn/cloud/scripts/discuz_tips.js?v=1
GET /cloud/scripts/discuz_tips.js?v=1 HTTP/1.1
Host: discuz.gtimg.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
If-Modified-Since: Fri, 30 Aug 2013 01:57:44 GMT

http://www.hym68.com/plugin.php?id=aljrq:xintie
GET /plugin.php?id=aljrq:xintie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/plugin.php?id=aljrq:ht
GET /plugin.php?id=aljrq:ht HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/plugin.php?id=aljrq:view
GET /plugin.php?id=aljrq:view HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/plugin.php?id=aljrq:dantie
GET /plugin.php?id=aljrq:dantie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/plugin.php?id=aljrq:dtviews
GET /plugin.php?id=aljrq:dtviews HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/cache/style_5_common.css?gO0
GET /data/cache/style_5_common.css?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=WT6H00; GvhJ_2132_lastact=1526915458%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 05:52:29 GMT
If-None-Match: W/"5b025e9d-158b0"

http://www.hym68.com/data/cache/style_5_portal_view.css?gO0
GET /data/cache/style_5_portal_view.css?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=WT6H00; GvhJ_2132_lastact=1526915458%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 05:52:37 GMT
If-None-Match: W/"5b025ea5-40ca"

http://www.hym68.com/plugin.php?id=aljrq:pro
GET /plugin.php?id=aljrq:pro HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/cache/forum_viewthread.js?gO0
GET /data/cache/forum_viewthread.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/cache/home.js?gO0
GET /data/cache/home.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/cache/common.js?gO0
GET /data/cache/common.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=t4DodU; GvhJ_2132_lastact=1526915459%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526988065; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526988355; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-d95d"

http://www.hym68.com/data/cache/logging.js?gO0
GET /data/cache/logging.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=t4DodU; GvhJ_2132_lastact=1526915459%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526988065; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526988355; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-186"

http://www.hym68.com/template/sxpxb_a5/css/article.css
GET /template/sxpxb_a5/css/article.css HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/home.php?mod=misc&ac=sendmail&rand=1526915457
GET /home.php?mod=misc&ac=sendmail&rand=1526915457 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/template/sxpxb_a5/css/img/bg.gif
GET /template/sxpxb_a5/css/img/bg.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/template/sxpxb_a5/css/img/infoAd-icon.png
GET /template/sxpxb_a5/css/img/infoAd-icon.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/template/sxpxb_a5/style/weixin_03.jpg
GET /template/sxpxb_a5/style/weixin_03.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/data/cache/md5.js?gO0
GET /data/cache/md5.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-13e7"

http://www.hym68.com/template/sxpxb_a5/css/img/list_style.png
GET /template/sxpxb_a5/css/img/list_style.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/template/sxpxb_a5/css/img/list_bot.png
GET /template/sxpxb_a5/css/img/list_bot.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/template/sxpxb_a5/css/sxpxb.css
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=X34tHx; GvhJ_2132_lastact=1526915448%09home.php%09misc

http://www.hym68.com/template/sxpxb_a5/ad/ad5.jpg
GET /template/sxpxb_a5/ad/ad5.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/template/sxpxb_a5/ad/ad6.jpg
GET /template/sxpxb_a5/ad/ad6.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/attachment/portal/201711/14/120226ljshvglgggam1azj.jpg
GET /data/attachment/portal/201711/14/120226ljshvglgggam1azj.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/data/attachment/portal/201711/14/120226d8eqsyqop8r0q1w4.jpg
GET /data/attachment/portal/201711/14/120226d8eqsyqop8r0q1w4.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/static/image/click/xianhua.gif
GET /static/image/click/xianhua.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/static/image/click/woshou.gif
GET /static/image/click/woshou.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/static/image/click/leiren.gif
GET /static/image/click/leiren.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/static/image/click/luguo.gif
GET /static/image/click/luguo.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/static/image/click/jidan.gif
GET /static/image/click/jidan.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=K0OoLV; GvhJ_2132_lastact=1526915457%09portal.php%09view; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; PHPSESSID=ae6lamcoccsa004bmdbof04ig4

http://www.hym68.com/plugin.php?id=aljrq:xintie
GET /plugin.php?id=aljrq:xintie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/plugin.php?id=aljrq:ht
GET /plugin.php?id=aljrq:ht HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/plugin.php?id=aljrq:view
GET /plugin.php?id=aljrq:view HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/plugin.php?id=aljrq:dantie
GET /plugin.php?id=aljrq:dantie HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/plugin.php?id=aljrq:dtviews
GET /plugin.php?id=aljrq:dtviews HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/plugin.php?id=aljrq:pro
GET /plugin.php?id=aljrq:pro HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/data/cache/forum_viewthread.js?gO0
GET /data/cache/forum_viewthread.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-5de4"

http://www.hym68.com/home.php?mod=misc&ac=sendmail&rand=1526915458
GET /home.php?mod=misc&ac=sendmail&rand=1526915458 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/data/cache/home.js?gO0
GET /data/cache/home.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=CMhR3s; GvhJ_2132_lastact=1526915462%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Mon, 21 May 2018 08:14:43 GMT
If-None-Match: "5b027ff3-7362"

http://www.hym68.com/logo/45.jpg
GET /logo/45.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5; GvhJ_2132_sendmail=1
If-Modified-Since: Sun, 20 May 2018 03:28:08 GMT
If-None-Match: "5b00eb48-2572c"

http://www.hym68.com/template/sxpxb_a5/style/common/pn.png
GET /template/sxpxb_a5/style/common/pn.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/template/sxpxb_a5/style/common/dot.gif
GET /template/sxpxb_a5/style/common/dot.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/logo/45.jpg
GET /logo/45.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Sun, 20 May 2018 03:28:08 GMT
If-None-Match: "5b00eb48-2572c"

http://www.hym68.com/plugin.php?id=vaptcha&type=challenge&scene=&t=1527016482618
GET /plugin.php?id=vaptcha&type=challenge&scene=&t=1527016482618 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://api.vaptcha.com/config?id=59f044cda4860b0ea89a3791&challenge=2e1ff8e37a044b189f5f03ba21194a3f00bfcgjbfehdm0eju&type=float&version=1.0.4&callback=Vaptcha1527016908898
GET /config?id=59f044cda4860b0ea89a3791&challenge=2e1ff8e37a044b189f5f03ba21194a3f00bfcgjbfehdm0eju&type=float&version=1.0.4&callback=Vaptcha1527016908898 HTTP/1.1
Host: api.vaptcha.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html

http://cdn.vaptcha.com/theme.1.2.3.css
GET /theme.1.2.3.css HTTP/1.1
Host: cdn.vaptcha.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: text/css,*/*;q=0.1
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html

http://cdn.vaptcha.com/vaptcha-sdk.1.1.3.js
GET /vaptcha-sdk.1.1.3.js HTTP/1.1
Host: cdn.vaptcha.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html

http://cdn.vaptcha.com/v1.0.1beat.png
GET /v1.0.1beat.png HTTP/1.1
Host: cdn.vaptcha.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://cdn.vaptcha.com/theme.1.2.3.css

http://www.hym68.com/template/sxpxb_a5/style/weixin_03.jpg
GET /template/sxpxb_a5/style/weixin_03.jpg HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5
If-Modified-Since: Sat, 19 May 2018 14:34:01 GMT
If-None-Match: "5b0035d9-20a79"

http://www.hym68.com/data/cache/common_extra.js?gO0
GET /data/cache/common_extra.js?gO0 HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=a9WXzx; GvhJ_2132_lastact=1526915468%09home.php%09misc; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5; GvhJ_2132_sendmail=1
If-Modified-Since: Mon, 21 May 2018 08:14:44 GMT
If-None-Match: "5b027ff4-a221"

http://www.hym68.com/favicon.ico
GET /favicon.ico HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915471%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/misc.php?mod=seccode&action=update&idhash=cSI6a1HY&0.07174324720671665&modid=portal::view
GET /misc.php?mod=seccode&action=update&idhash=cSI6a1HY&0.07174324720671665&modid=portal::view HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915471%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/misc.php?mod=seccode&action=update&idhash=cSK0OoLV&0.6446092966735297&modid=portal::view
GET /misc.php?mod=seccode&action=update&idhash=cSK0OoLV&0.6446092966735297&modid=portal::view HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: */*
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915471%09plugin.php%09; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/misc.php?mod=seccode&update=98380&idhash=cSI6a1HY
GET /misc.php?mod=seccode&update=98380&idhash=cSI6a1HY HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915484%09misc.php%09seccode; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/misc.php?mod=seccode&update=15908&idhash=cSK0OoLV
GET /misc.php?mod=seccode&update=15908&idhash=cSK0OoLV HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915484%09misc.php%09seccode; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/static/image/common/none.gif
GET /static/image/common/none.gif HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/article-540-1.html
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915484%09misc.php%09seccode; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

http://www.hym68.com/template/sxpxb_a5/style/common/px.png
GET /template/sxpxb_a5/style/common/px.png HTTP/1.1
Host: www.hym68.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.9) Gecko/20100101 Firefox/10.0.9
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive
Referer: http://www.hym68.com/data/cache/style_5_common.css?gO0
Cookie: GvhJ_2132_saltkey=FCV599CC; GvhJ_2132_lastvisit=1526911848; GvhJ_2132_sid=cigF99; GvhJ_2132_lastact=1526915484%09misc.php%09seccode; Hm_lvt_c13063811b4000c38466ffae7255c948=1526967134; Hm_lpvt_c13063811b4000c38466ffae7255c948=1526996959; Hm_lvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526967663; Hm_lpvt_eb8baa0516fbd664bed9dcaa9310e7f7=1526996959; PHPSESSID=v6utmjklujj49g54jo7b1p6ph5

投放文件

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 e6536e06739e26d6219c28b7c04b5a54
SHA1 013ad5268680081356d9129028e0924f821ac59c
SHA256 96725eaaf468eb40d5fb556bac15a738266cec7eab059a6bdfb2a7d77ea31b53
SHA512 de3ad9ce33de0077055d2b8bd7f9ab9d9bb813a9606d8e3024f8fabb01022d16954806bae41e1d059713ba01effb69887f3d99c23c439e9f82d34d38b84c28a8
Ssdeep 24:7+/R1hRJN+s0J+sAp+egMHQMHcB6tKfJrHZP0rH424E6LsuREah76wd4+i:7eR1XX+s0J+sRMwM8gKf9SDH64Xa4jl
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 9c93ae4869d9b465f4b9a33d2938037c
SHA1 60b00e6a183fcd0c6df624e8a90a4ace089aed47
SHA256 1fa8b14f20c74f913067d5f81d1722880c7eb7304cfed72a542977b3e5fec724
SHA512 79844e41f7c83386aecea9a1dab5b74747ba72dcbb01e3d7a5489f585763266b68252c6a3f64df4856948f9a5bc1502c1e85dfc675c6dfb48146bf7cdf05f8f0
Ssdeep 24:7+/ShRJN+s0J+sAf+egMHQMHcB6tKfJrHZP0rH424Pp6LREah76wd4+F:7eSXX+s0J+szMwM8gKf9SDG62a4jm
VirusTotal 搜索相关分析

8C1CCd01

文件名 8C1CCd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A5\8C1CCd01
文件大小 29538 bytes
文件类型 ISO-8859 text, with very long lines, with no line terminators
MD5 6881fd73e4a0f55182dd105b118f4b83
SHA1 b8d9b4182c16020210f4f91e8794ce8107519dae
SHA256 82193bab4630d6d26e2b3fcb06b4e6771c281907d2b2de3c2bedc1d479bf0428
SHA512 ae18eaceda9cabcb102f625cd25aec1c08c74578c3b64d263a027c373e68a66578e686de6847f0f1826b69591aaeb460e58f6b877d605d0656de3fe6361bfb71
Ssdeep 768:NfG/Z72op5u/PMusk14ABmNFkglZgylj+KOAADRIbS3OxlEneSNiE5KhAJZ43Eb3:c/Z7p5u/kusDFFkwgyl+vAADqu3OxlE7
VirusTotal 搜索相关分析

webappsstore.sqlite-wal

文件名 webappsstore.sqlite-wal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-wal
文件大小 688664 bytes
文件类型 SQLite Write-Ahead Log, version 3007000
MD5 1c137fbcdf7e71ecb475a3a152aec79a
SHA1 6606924c58addd581918c10c58525d4110639ba8
SHA256 55ddf1b60561b4e9402ef64f3bbf6ee0e7626c57deae3854b8d193be46bf6eff
SHA512 c66b0558d7481251c8d83b7d0e1ebed15fe7d56655494ae8a1630e28712ca31b39c865b552fa7a5f3174152b16d63746bd2ad10137a91722f6910a7306caa5bc
Ssdeep 1536:mLmTTl0mnZTgR0m4JTYi0mSuTfi0mQ+Tii0mjc1T3i0mx:oL
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 fc992822ad8bef29358f73838c5b5e9b
SHA1 954e44c228fd74b298690dce8f1056f283a34048
SHA256 143a17da03e6aadda7181ea85afe6236e85073cfb9c1ec5b1bd07e5e483dac41
SHA512 894e137db4e5d8323af62082ecc8987fcabbe1d48364e8f6dfd2017db65f80a71d50cd9adc65341999ae975ca9b6ff4aab99d5408f673d61098543d0dd8cda84
Ssdeep 24:7+/8hRJN+s0J+sAsW+egMHQMHcB6tKfJrHZP0rH424c6LP5Eah76wd4+xo:7e8XX+s0J+sRMwM8gKf9SDP6ma4jqo
VirusTotal 搜索相关分析

793BEd01

文件名 793BEd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\06\793BEd01
文件大小 24036 bytes
文件类型 HTML document, ISO-8859 text, with very long lines, with no line terminators
MD5 0c22dc457b61cb0038a130ea239787dd
SHA1 8a3dc4c12b92498ada8b7c1f6acb4c3364d0e10a
SHA256 09a777b42c81a77b03d6376116ab15f7609238e90a91f4441b3cd6cc306bd635
SHA512 d244ff9fca81739db0dde2ff5f579b3f3e4f717627a699540de7d0e6bfdff3db764ba7b7c086624a846f6d759c8d3ebdd7dffd6321aef628469c16c0aec4104d
Ssdeep 384:glbtEDSaTtDcuzdFPfRRzWEKm6/nfxLc5RRzg1j1HlfU5oYBpbj7vG5faSKQvhBY:glkcuzdFPKEK9xP1j1Ha5oUpbj7+5SSq
VirusTotal 搜索相关分析

810F4d01

文件名 810F4d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\D8\810F4d01
文件大小 44750 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 70", baseline, precision 8, 596x272, frames 3
MD5 ac1ab8d4bb087e86a9557b3c402237a8
SHA1 e734370edd2b383da81f1a1262a320d729251d12
SHA256 527a51e57507a090872b0e03ae66620d7d49f2ff8071023073092c7a974a7561
SHA512 03f078a6ea8563f50ce40b48f245fa91de8b868d68fe31bae20a7f246a1d611015eb9aaa65ae315e9d8e990a920ddde204a36f2a274a6b0b29b55d2c490b1a87
Ssdeep 768:rJlGhTi2VG039fzfaWsuBrOYAUNVtXlTLhdt7Ehi6UdT5iEPOxTGFERRaHaIHFkr:rJI1939DsDUF14ZQ5i4UT0Em1abNp
VirusTotal 搜索相关分析

668D9d01

文件名 668D9d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C\3A\668D9d01
文件大小 153388 bytes
文件类型 JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=1, software=www.meitu.com], baseline, precision 8, 266x397, frames 3
MD5 a77d241e546b714b1822d2d66b46a814
SHA1 1233402064cd1e08133d677070422db51d2cd9e3
SHA256 2db4ff8a48bdc94895fb89bab9f726299f365b0eee884232e867ad9ea7d8d69a
SHA512 fe1f4ad5891d05776fbd1481c5e1012916e1efee63fe6fafada7d4a5d856cf173a53d115120c910cd7bcccb9a2c386d5d1a6cd20d8fdc6c40acd7f10e5c6b18b
Ssdeep 3072:GJpkczvprcqE7/MAotoRvleQbOpjZSBxO9qwJLruH:aScTBu7/HotoRwQb6CxpwJXuH
VirusTotal 搜索相关分析

9422Cd01

文件名 9422Cd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4\6F\9422Cd01
文件大小 43952 bytes
文件类型 JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 311x120, frames 3
MD5 03899ae5eacf47401c6ec508ce8fcf79
SHA1 af0e6801cbf8f85716558260b141568f7d841054
SHA256 4b7cb1d87247125ba8846902c352f427f22a7976ce32739546646c7b941d620e
SHA512 d7d12318f7b3d0784818038a6eadc5ee82293ea2623d991c8d043771489218842920ceca5facd1bb6ba195bd695a3bd680a6f06cb120aa3335d0d2bb01ddefd4
Ssdeep 768:qZqm555GdT3k555b+55gds/CsHttGAaG5QQof1mM2/yKkADsHe/ay24h1cC5555/:qZqm555eLk555i55uCbaGmQo9tnCD6yN
VirusTotal 搜索相关分析

urlclassifier3.sqlite

文件名 urlclassifier3.sqlite
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite
文件大小 5242880 bytes
文件类型 SQLite 3.x database, user version 7
MD5 78945d1bf7915334616fc863bec9e9ec
SHA1 a42667247c98af48dad62c07a5d9f43ebbc3c6cd
SHA256 8d78a3dc0757b793359483cf365c3f6be9405b1f93cca977b31f80948390fda9
SHA512 f00ab89c6ae170bf78005544dbcf3bfab1c0eebbb4c2d82919f3dec6bc40646879ec30df2e417eed8baa0068f63dc4688f4fe5e3e6a5c0a74617e1efd7c20bef
Ssdeep 24:DL2+w24+zdY1gZCObTENe0SHGES456DlHEEqWERlSTENCfdxv:D6+8Ne0Itr56DlkEqWERlDNKdx
VirusTotal 搜索相关分析

F0983d01

文件名 F0983d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\1C\F0983d01
文件大小 20972 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 80", baseline, precision 8, 390x330, frames 3
MD5 b455b8a24e8f02d91e9883554411ae4e
SHA1 07385cdb927f7e21781baf37eebcf221f47ab4aa
SHA256 098071b570e046fdbc1f1b60968a49af79600351082dd4da28758f2dc92a477b
SHA512 6a9743cd89a3f7512cfa4719198debddc662c1ec6ec080e7966238ef9bd50949975d61d56cde847439d33d4d211b7903bb4a376ae2838a294b26f46b2b8e8bbd
Ssdeep 384:QKrLe5tlJ+29u/KLjxldY+GZYT/iDN1ZdHI0zXxEkrmxKr8NpX1KQ6Ug8:QKr2KKRzY4TaZ1ZdRXxkR9R
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 6db9415e162f99b357e8d60a4d8566a1
SHA1 a2786050b1a2273b542a8e4f2fc23139fe2fd272
SHA256 8e94ae65f1dcdf5c47b33fabb55a05d711492ed7fa18423380922c2198556319
SHA512 467b26ad0580e259f43b6146869044c4d86e83b4b837aa16b9cd013160ea477ac4a292e4c027a7bf830e24aec973c477f345c6c0ea603c5ea533de8d6155bf3d
Ssdeep 24:7+/rhRJN+s0J+sAe+egMHQMHcB6tKfJrHZP0rH42436LhrEah76wd4+r:7erXX+s0J+sGMwM8gKf9SDg6NAa4jY
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 2347d1606339557845add49f5dcef990
SHA1 4b01074351f82b26bc20c5978dd60f671bfce601
SHA256 b6ec9bd1d41c5889c5849a5be25f8bb662385b228a25c70709026b59b76f0802
SHA512 f43b9461b18032678b274773590d04ccec6f4101b28ec18d3fd826e4f401fd1a46101ed081fc59ca7aa901e05f0316caa6b820847ddf5b6080efbca1fb1d1858
Ssdeep 24:7+/2hRJN+s0J+sAD+egMHQMHcB6tKfJrHZP0rH424gp6LxEah76wd4+y:7e2XX+s0J+sDMwM8gKf9SDxp6Wa4j5
VirusTotal 搜索相关分析

E1093d01

文件名 E1093d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\96\E1093d01
文件大小 68038 bytes
文件类型 PNG image data, 341 x 612, 8-bit/color RGBA, non-interlaced
MD5 b161d0f6ec70a4bd31bd0fa44b91c31d
SHA1 6ce83bb6151688729a5f568706d0a1bf340fa92d
SHA256 ce0a275a545b6e575c85f94b1802616e991e28e774344f5424ba3d2f21dab357
SHA512 ae71dd96f7dcfe70e16ac8043b6d97845ea57936769f9e7391a63657712ff731df8367101f72945cb60fb43efab02502a989d3d4d490ccada93c0f733ddcf773
Ssdeep 1536:8bH9UmSo/FFaYW3SB6oNKEOZ5vKaEFhO7NIWIsgkWsi4wTO:8bHTdFF3B6o0DZ5dEm7NIW1I/TO
VirusTotal 搜索相关分析

urlclassifier3.sqlite-journal

文件名 urlclassifier3.sqlite-journal
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-journal
文件大小 164392 bytes
文件类型 SQLite Rollback Journal
MD5 036475dc676d53e30b579c1bdade444c
SHA1 c016921ae800179540dadd8563337cfe858593a6
SHA256 2c22e8b5a366b4b9091ca357f2418151dbd07affc6b48542596f1c36510bec11
SHA512 acfa1fed2e4a0fe63729429a10dbc96e92b48701d280c534252f7f638c7b8700c90b6f61a4c5b722b90b446c8d909704f031786baaabb12cd7eece0e6a9184a5
Ssdeep 24:7+/oZttJwp6LcIw24+zdY1gZCObTENe0SHGES456DlHEEqWERlSTEN0:7eoZttSp6gI8Ne0Itr56DlkEqWERlDN0
VirusTotal 搜索相关分析

5CE2Fd01

文件名 5CE2Fd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\DF\5CE2Fd01
文件大小 226666 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 1052x1687, frames 3
MD5 a35530cf79d01515428307a9e4a343e7
SHA1 5c4a6a817fe018683c6220eed4dc49974fc78a2f
SHA256 690b018e235bd3a139d12c3ce79d34794c9f4f6bbfba4e14c8676615b17ac436
SHA512 7128db103db56a77dcc22160015537c57f29bd358c34c60c3a899573b178f0aecdf98e333b8f3aa77027d5fec925a9c92c71b945e5dd6807947c233670ef603e
Ssdeep 6144:iNw4u16Yl8KUD2ZuLna5izk0PurzTij7stZqEH3uhS:mMF8t1na5izjPfH8ZaS
VirusTotal 搜索相关分析

cookies.sqlite-shm

文件名 cookies.sqlite-shm
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-shm
文件大小 32768 bytes
文件类型 data
MD5 591c8abe14e898a6407717af9fadd3e8
SHA1 d56746bc3168797c80cb5bbe0d60f5c61646efd9
SHA256 71d0ecb44cc17203c22789e5c732c8b84e5a8f7170251dbcea09a2c14af8db7b
SHA512 9448828100b777dde52bc8659a3da4539fff51970202e2948624a081b775a684e0bdb014725020c5a12fc8767dc4a7ce0f1085c3fe99af559b34365d6cdd3528
Ssdeep 3:GOlE2/HewkUlClI8lE2/HewkUlC/lllltlL9//ml/bul/bvlpltllLl16:GKtWXUgbtWXUgt/Z9Xml/Cl/Dl
VirusTotal 搜索相关分析

EFF56d01

文件名 EFF56d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\DC\EFF56d01
文件大小 22847 bytes
文件类型 gzip compressed data, from Unix
MD5 c80e70a4f7f0037570314f978c9c7bd0
SHA1 78d46b174b69f601fd8f84970a69e153e4506f0f
SHA256 5bb2c136fa7f319733bc326c817a9b5778bad11a81f79deafe4798cd8d0212d5
SHA512 39460430ed9b17a71cf8d39ee03143d4d90a4c2eb5a5976277c0fbace1d62a172896ae6da707caa1155c633f6d84e319ad0b290491c555b3610b2658f71ed711
Ssdeep 384:dZn9Ydl0qh/mb6C8M+4CmctKsgVf+OEzFIAtGAQI/DJNTHJ+TGVRIg:dZnyl02u0M+4co+vzFIAUAdJxJ/VRIg
VirusTotal 搜索相关分析

86788d01

文件名 86788d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\ED\86788d01
文件大小 55645 bytes
文件类型 ISO-8859 text, with very long lines, with no line terminators
MD5 36b96b998ca90cf038f8be7e070e52ff
SHA1 d28612b01bb28dfc55cfd2c0cac5b70b51b8c7b0
SHA256 32d18b48813f94a151c321a1ca67846e1882d48695e8cdae107cdc5ef335a7a1
SHA512 a9bc488f812573d2db45b9741e46fa612fa49d1f6ed5f26d354c10690dcca8065f25408c943b62754743d4e74797af4f8f0f7d7fee2195ce314c9a68ec500cf3
Ssdeep 1536:I3ob/A/4i5tVMvc3adF9IIAR3iWmdfRdIEMYmPOc:iVMwadPI9RyRmmc
VirusTotal 搜索相关分析

webappsstore.sqlite-shm

文件名 webappsstore.sqlite-shm
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-shm
文件大小 32768 bytes
文件类型 data
MD5 834b28bf0c070a70c4477bc9720b490e
SHA1 4afef502204e19d103de45c5f164102b0c445887
SHA256 e76506c6e2d36b12e89c132ca8b48ef922a04238da4d5489b28f59e7ea85ca05
SHA512 59a09ba1f6b626e36b0e0a4a7dd918659e37c60b57aaf060b539819eaac0d6651b2dd0a1c592c047b3ece3b81561bb18ea0f3590824862b18feec0b5a3082400
Ssdeep 3:Gq/zUR9FuCH0x8/q/zUR9FuCH0x8zR9//9lgl/gl/gl/gl/gl/gl/ill6vEl4lgS:GqoRuxxUqoRuxxMR9X38qlK
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 567693e8e003962965219848010d52de
SHA1 4897383603f25af149ddd1b71d4b7e3901584c9d
SHA256 34a933576a195d57dac0c49b4339444e591c3aa25b52cfe7971565f805f718fa
SHA512 eb7ebfaccf1b05da280a4b8d55e01de0ef1b6cf0d88f620f2302e02556e255b7ac9d816185de1569f9957ff11c618ef2a567b8e3214470013d70f3d509d332a2
Ssdeep 24:7+/KebhRIN+s0J+sSo+egMHQMHcB6tKfJrHZP0rH424K6LqqEah76wd4+U:7eKebX0+s0J+s6MwM8gKf9SDh6G3a4jn
VirusTotal 搜索相关分析

F90DEd01

文件名 F90DEd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\30\F90DEd01
文件大小 71944 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 50", baseline, precision 8, 672x904, frames 3
MD5 11dd2e2bc92bc9187c527c8d5d42cb74
SHA1 848be9503f20776e194cd77cb32d07ba01e12e2a
SHA256 bf64c6ea0a554fd3929c34456e922df975b553bc770b4a0f7a20743e8e7df2d4
SHA512 6e1be746b00faee38aef24f8283186a6ca3661967f947160ae3dafe554065cde3d63e8b3774a736d5bc6fe389d653a635a9adae80642000d03f00fce9933eb9c
Ssdeep 1536:fwIXiUcUu6N9LuyPaFMtvOOttEX6i4EjLPQh6kFcqZTn:5mBzbqyqiIdF7T
VirusTotal 搜索相关分析

places.sqlite

文件名 places.sqlite
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite
文件大小 10485760 bytes
文件类型 SQLite 3.x database, user version 12
MD5 92ca6109319dafd24a14083a144cb55f
SHA1 4ee9b74355613c29ba0c76ce3cf41f107a5e3ef5
SHA256 2d586a716194c06cc5b175bc876f26adaf54a12fa0ea5b32598291b26f4c5dc6
SHA512 bc30c29064888343365811c6b5c080c3bccc7f039feafc9825a42f650d47d4fa5617dc5776e72bfc7a586b912120afd0b937397b17281d517490d49a60037cb9
Ssdeep 384:ITBj4O4izioOGgwJBaHpunHwTGkE4lhhXBM+jU35UY7LtsyZc4Dpu1Ou1+u12u1r:I9j4Zizior/JBaknQT2uejB/ZctZ
VirusTotal 搜索相关分析

sHRfRnkemptTqcH4R9AbGA==.ico

文件名 sHRfRnkemptTqcH4R9AbGA==.ico
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\sHRfRnkemptTqcH4R9AbGA==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\qoRS7uunTyPuNt5ZB_dUSQ==.ico
文件大小 137 bytes
文件类型 MS Windows icon resource - 1 icon, 16x16
MD5 b66bcbe2cbe33b224622ae9553f2c605
SHA1 b8f3aa4231258e0edcbe0d3830d0549f48bddb3e
SHA256 c7e2e730c3cf3bf4fe5b3a50721028e1b82c01855dc30f0f533e4ac79ca3cdc2
SHA512 f484f4717c2dc35f8c2f150df2de891b019790f029ec2063c33dab342cee3665a87f8dd436e4ce4cee71a021a77d1e61d7399f6792478e160304e51350000c52
Ssdeep 3:cMl7lk12onv//thPl9vt3lyKLcyDf6Q6Q//9Q1JdiocLll2up:PTk1vv/lhPiQcy76QF/W5ioqeup
VirusTotal 搜索相关分析

54DFBd01

文件名 54DFBd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A4\54DFBd01
文件大小 133753 bytes
文件类型 JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=1, software=www.meitu.com], baseline, precision 8, 430x430, frames 3
MD5 f6f5912dbf86fb9319fddf3d8cbd7b6c
SHA1 f9b7cbbcd05d271883aa890749a8bbad3990eaa7
SHA256 bbbf31d21fef1446d12a86298736e3e347d8e2148a19ff0ffdb771e62b119594
SHA512 16ef039207f29d5d7a6a99b5e2a2b351960563bcb382d4d4a4c6a111e39907febab4a61ed52b8fcf91f2bc1af3079d379afeaf68e056269b5f7dc2fe2e939624
Ssdeep 3072:aRP/D3mFw+0Tw915uVciIluxArbL4i8I2WVMdvzs3no7Fzn:SKw7yOVJItrb0i8ILV0zsGFzn
VirusTotal 搜索相关分析

cert8.db

文件名 cert8.db
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cert8.db
文件大小 65536 bytes
文件类型 Berkeley DB 1.85 (Hash, version 2, native byte-order)
MD5 a518a41d5bde9c0a3cd693051510f785
SHA1 dd435f36f339698a54f7033a75661b9885bb3c2d
SHA256 58313be65bce796ba219e2ec6a54435c4c8f3ca94f480d9f2813aa4e8dbc8d27
SHA512 7930df45883279b55e9eeb1f5683ed118cb529d5b788761c8ea09e8f110163b21d4d62e7599a8447d1821d024338e984532924906ed4be435c357aefa90c629d
Ssdeep 384:DM7/gMSXqHDMLEBb8DT4LHGZXqZ60uJzZ+mhrr87NDh/LDUQZDZBkaUegDd5GW4I:DWuhI5DCGwfIYzlfO9FML
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 3447be67055647c79acd5bab10cc67f7
SHA1 73810b4b42786e8ace46541fac04885a231c556e
SHA256 61b00fadda87a647ef3a170c4b53f58ca9d81ad7a1f601b4a62fcedfb5834ab3
SHA512 16898e50b0ae2083b4f4966d239f768036ff736265e4a9d11c2c673be58f1e005d98c8ebea6d59f6813a00d9d0d4778276bb75b2277c0894458aba32ec8cc668
Ssdeep 48:7eCTfYfA+s0J+sjLOMwMnL5Kf9SDU6Wa4jE:7eSgLs0wsjLBLMGU6WxjE
VirusTotal 搜索相关分析

DE623d01

文件名 DE623d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\C5\DE623d01
文件大小 17704 bytes
文件类型 JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 310x120, frames 3
MD5 0815ecd68b9e3a1cd8cfdc0c34e64daa
SHA1 688f52dede4a5df2b62d488aba26ad8ecd6f8d0d
SHA256 e1e91590dc673b93caea9009bcfe743ca96d4872be7b8f693fcc5758bfc94d55
SHA512 0aab9cabe20dbd239c94eb96ee1eae0a70bec1150d6b0fc4710ed1659c0364563f89d59aae017f3add38851219fdd9a6953ecbb75be308118451902f5297eeec
Ssdeep 384:R/ST8ryP6xBNSgiq0eBl6zKkSMf1sK7Twc54rAmZogP5Cw2fIG1yI+T:Ra4ryPwBNSgiqPX6zKkf1R7TwO4rAioU
VirusTotal 搜索相关分析

703A9d01

文件名 703A9d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\60\703A9d01
文件大小 19302 bytes
文件类型 gzip compressed data, from Unix
MD5 2f7eb5059a71f2a73d264d7c8bc67db2
SHA1 904a5800b94842a76c2f89d8ce4fbaae21d1ecc6
SHA256 8772040c22be086fcfe1c11b30d41b0de83300c1e211c4eafde428072e84d35f
SHA512 7053379a29be0b6f7295f3824ccef1aaf81e3838e25452ed967e40d51b61f27df9fdf0cd85bae1e99160a28c6eec1001534f11fff18190c185497a383ed87b31
Ssdeep 384:gAeoobjag/Ab85Z7AqxJ6d0SDOnDmlXHdzyQZ3fa2UDWs8wbFkw3k+:gNoofrAiAqI0SDOnDmRdPaZD9ZU+
VirusTotal 搜索相关分析

0u9zG3TzKYoRkKqp30_ljA==.ico

文件名 0u9zG3TzKYoRkKqp30_ljA==.ico
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\0u9zG3TzKYoRkKqp30_ljA==.ico
文件大小 274 bytes
文件类型 MS Windows icon resource - 1 icon, 16x16
MD5 dcd222d15ecf16ca231f20a0a57f46e3
SHA1 2b16ef96de5d0d54a94fb4a1c7bf9004676b311e
SHA256 e14b374ed072672e3801851d47f12d8b8405dca79bc5bc7cf26b36e0341998c8
SHA512 ec8c6a45096416c5200ad639d55b86b53026147bbf6320efaf3ba0176059197eea8993889a740e492daa3a39ef8c832d3ee4cfa1d464db5ff540b466a52cbad2
Ssdeep 6:Ai1vv/lhPVtIm8DTYHB5gozAUXM/xVUBQUqFnhsBaFLu4027p:A4v/7N2qoPVUGUHcy0
VirusTotal 搜索相关分析

cookies.sqlite-wal

文件名 cookies.sqlite-wal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-wal
文件大小 590288 bytes
文件类型 SQLite Write-Ahead Log, version 3007000
MD5 115a5aa17d1bca55100b4ff78d323a26
SHA1 69987e24c22279d2c3aa9ee1fd29afbb99fbeead
SHA256 acd75f105f591fe665ec818eb119f8433a23f3554026fc07553a9ddf78a0a9ea
SHA512 f2c2a9abb1aa30172be47f7cbbb687057a76b1c3d0e81cca1a4a31e4a7b83d33fe413d26d210297fbe564f1d4f581913d088da532bea3297acf7dafdf49f98c3
Ssdeep 384:c7t/CcKFFbDELc7t/CcKFFbDaL17t/CcKFFbDI7t/CcKFFbDG7t/CcKFFbDv7t/N:0
VirusTotal 搜索相关分析

C6493d01

文件名 C6493d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\95\C6493d01
文件大小 30426 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 70", baseline, precision 8, 720x406, frames 3
MD5 0706fee2470c8b9f299da5845f38f5c5
SHA1 fc03464040bd02c0dfb577693e81bae211927e8d
SHA256 26ee54082d6a9428962adf7d65a0856250179288a9a6f216a82e9a090ceab8fb
SHA512 9ff39118a81aebb35dbe3d24bb89b5e1005724e9b78629fa442f98bd6fe20ab0a8cf4d089ef244c3271d3383eee7d2653f80bcb6b36a811b2ce4b407bcfc5536
Ssdeep 768:hQYDw7p3FOnm7SWJ2IxM1zd8aIaGWmsxWPU8/q:hjSRFgQsd8aIaGWXWM8C
VirusTotal 搜索相关分析

57C43d01

文件名 57C43d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\AD\57C43d01
文件大小 34995 bytes
文件类型 gzip compressed data, from Unix
MD5 895029ab8aabfe527cce45e55b8ffc54
SHA1 b76448a7782ccff11a7c6723572c276bfb98c24e
SHA256 a3fe956392ec6bf540583c9c3d49e51e13ba8b59cd81d28768b6991c0d2be970
SHA512 ff8ba57d91c5158670366b9489fcb3ca1001a66a94b9bdecbf67f1350ea92becc96fa41c31d5965f63ce0970743548a94bab792e59963fb11994aca59af79d14
Ssdeep 768:mMVLDcGQsHv1NGTiNLMkVbHF/ZPEl7ljKhRDbUKgSRYRTmsdH:LVL4GQ8GTiVp/CljKvbUGRYRTmsd
VirusTotal 搜索相关分析

places.sqlite-shm

文件名 places.sqlite-shm
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-shm
文件大小 32768 bytes
文件类型 data
MD5 6128513257e65a4fe6108d8550680650
SHA1 a1f16e82930e82ddc263de86311259cfd53aada2
SHA256 6ef28c318dd9561fecbdd9439cf298c4265f52b6d390cb6e9999e8f462389934
SHA512 d80cdf8a02be3f3b4fec942e591262e2e0acb7ffd22bffd4914b4ecfe6c060664a80e8c3402790038295927717643bea96c9ba5ff4e7169b5d51be079ab24cb5
Ssdeep 3:GdlE5/MbC2LKRUp/ldlE5/MbC2LKRUylraa9//XlIlIlIlIltly/:GDkCtDkH19XXyyyy1
VirusTotal 搜索相关分析

48016d01

文件名 48016d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\77\48016d01
文件大小 51439 bytes
文件类型 PNG image data, 281 x 500, 8-bit/color RGBA, non-interlaced
MD5 b21c90453276268c98111438d89c5eba
SHA1 38daf820fae562463ba9b95e116dd5106a2fde3f
SHA256 b0f430966b10f1e11f40eb9d599e4e70b22977471d4204b2a99910365381a634
SHA512 e291ddefb6fd4f3528281cd0d6057ac9d25ed6ff2be83d26ccf6c9b2b74c09ff12d0e92f06e3bf1282767d0d08a2db1ff8f641d4f99bf85874036e7515b16ba7
Ssdeep 1536:6sj4MCg69Wdlmus9Y31Vg5ht64RypHSKi6zIOnuSGt:6sjQgpdljs9YlVg5bZ4pHSKi6MOuSU
VirusTotal 搜索相关分析

sessionstore.bak

文件名 sessionstore.bak
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.bak
文件大小 6326 bytes
文件类型 ASCII text, with very long lines, with no line terminators
MD5 844013dacaf226bc059296292393a192
SHA1 5c91af2851a08ffa2af8f74f81047433bac8abc1
SHA256 7da0693e49ef52e7082249cdaf1331a4c9b8dcc97bf48f9290a800b2eb7788e0
SHA512 dcc0337450a513f1eda3d430910d023540ee50a4802898f9a6418cc0a9c49e117096580c6da1250f80ee6f13c37f92885e54001add86f69d838e574302a7542b
Ssdeep 96:/9OXi1OPHXi1zMUrmas7WvgKyGHXi1z7JrMVs7WvgK+TviKqkaYtTBtzLYtTBtzZ:/OiGiGZuiRBDzyz9Zi2SU
VirusTotal 搜索相关分析

places.sqlite-wal

文件名 places.sqlite-wal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-wal
文件大小 196784 bytes
文件类型 SQLite Write-Ahead Log, version 3007000
MD5 193b61af4e8b5127d53bfd205ed3d6bc
SHA1 8d6834bea0dd96a75f9c0d0410c83d7efc2b8d77
SHA256 6e38707b9009b637dbf6ffcd0873d8e347eac84e89f979ef7c610507806e351f
SHA512 128694ef47f7d3b0030d5dc4858d87341d85aa8c783a9439164908e8202d3a0499ab6293d2556895ac45a1be7753db75ad41fac51a393f7d50076c2b48b1be3e
Ssdeep 48:eMJQHT+kRb3nIMJQHT+kRb3nTMJQHT+kRb3n2MJQHT+kRb3nimMJQHT+kRb3n8M5:JAvLAvIAvRAv+AvfAvU
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 2ef3f39ab9424d91ba4b24731f64e5f9
SHA1 1dbd96488f7d9d90506392a6be34285abbcb8cd0
SHA256 b3bfa41c327f0c2491322e44fba84f0e7dc8147485074c0059d120edd0563f08
SHA512 41876455a04ff122c8f70d7257bfa2c02f0d5136e0e533b9c8316931338d3e540942bcaca7e2885dbf89fa497c50bd1b86774af0f7ed43aa27c1a0626374a3d6
Ssdeep 24:7+/fhRJN+s0J+sAa+egMHQMHcB6tKfJrHZP0rH42486LxEah76wd4+lM:7efXX+s0J+suMwM8gKf9SDL6Wa4jYM
VirusTotal 搜索相关分析

6D45Bd01

文件名 6D45Bd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\77\6D45Bd01
文件大小 65262 bytes
文件类型 PNG image data, 300 x 250, 8-bit/color RGB, non-interlaced
MD5 65eb15bca8b451cf5fa76d27cb46fba3
SHA1 0264971d78b1c6d7e167c5dbead2f4413d21b8cd
SHA256 8e4a75ac13f9cd5fe3d0e8e19dab4b6447c35702643ac4119314acc2b7f01c0d
SHA512 0d21e941970b196bee1d261e84f87cee33c1894d85012e35b3eb082774e4c359c09f7baa119b6eaa689b65e23d6fed6601ee59670c7d08a627a8cdf50db8a7ac
Ssdeep 1536:Uu/euQFgV9+EtuwAKYPxnXa34Ppe0JzBWVMbU9hdZjqB:B/BvV9+EtuwAjXa3H0TWVMA9dWB
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 da133fcf9cbfc143db52f76038dadfcb
SHA1 1424e0a697388ea9eab749d171ca1c70fccaf045
SHA256 3bfde3145fab5305bede14bd077d2a44e8a3d521c7b1e97cec0b65a998b42ccf
SHA512 8a77087f3b7debe637f7e8842d1a001612c31f24b6fe5b13f98fdd5e6dbdcbe49fce15b1b0a0b5a3a758cd855c2f275d8473b251cc0755a7496a5f2ae3a1a50d
Ssdeep 24:7+/4/hRJN+s0J+sAo+egMHQMHcB6tKfJrHZP0rH424m6LKIEah76wd4+U:7e4/XX+s0J+skMwM8gKf9SDB6Gha4jn
VirusTotal 搜索相关分析

46FA4d01

文件名 46FA4d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\84\46FA4d01
文件大小 41318 bytes
文件类型 JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 1200x60, frames 3
MD5 e91a2fbc3edb72b9456b30f76235022c
SHA1 e47d896a993a6313e11fcee05f6c40f79f748e8c
SHA256 538416e93730bda40df6649491200c7455a2eafe23571764db8b6ba3a73a04a7
SHA512 b4f7f13538fd871cb05ebf0dabcf6a4b11e01ad3b359847311ef1aa412d83bcaab511d3f50392a1f80cf141458a940c10bb1facbbacd46b7043b1aa938cef607
Ssdeep 768:1UtiDq5WHF1pG5eASYFeK11N6+qvGjuY5FNLJlZNqpPG:1OPWl17ASYR11N6+qvKuY5FNLJ/ING
VirusTotal 搜索相关分析

22B99d01

文件名 22B99d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\40\22B99d01
文件大小 41505 bytes
文件类型 HTML document, ISO-8859 text, with very long lines, with no line terminators
MD5 3b8aeef8e88d7055eab143a41208beaf
SHA1 3f91bc87275702ca74d3740e6a99306c02e26918
SHA256 f4ac18f132d042e67863294b7bc7b824c6e77605ecd9ca13b659689d11167be4
SHA512 500df4b64337b6c701019c3947b55f717911949278a110a1e0896e14bfa22092d806f7d73a1c5a35dce1f8d2d3d94f50760adc5d1bb42d1321ebde999f77d576
Ssdeep 768:OxQT/Qa+8vbXWmNYMAM6fplQEJBNcTdlUfSCDqdPtZDTkUz1vwMzmEf0tgBY50Xh:UQTQIWmtWB3SWqBtZDTkUz1v1XFVczwZ
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 2f1ec62ec4d1003dbd26d700855486e1
SHA1 6026bd64f2905eb1b876975dcda421b8e09d86f7
SHA256 b0cae6d3e83c46a10c3da7ecaa5866249841c35ebb1a157bb81d64256b675e09
SHA512 ae6d4b713105336addc5bb6c7e39f27c97d582ab11636f090b376600982a87e6097aba90edd2b9772ac31cb00355798489758a2480de7539938ae11d009bd717
Ssdeep 24:7+/lhRJN+s0J+sA4+egMHQMHcB6tKfJrHZP0rH42466LxEah76wd4+I:7elXX+s0J+s0MwM8gKf9SD16Wa4jT
VirusTotal 搜索相关分析

lxLIs2AH_AMFqw+CHXsXRQ==.ico

文件名 lxLIs2AH_AMFqw+CHXsXRQ==.ico
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\lxLIs2AH_AMFqw+CHXsXRQ==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\3HExo8vWuk4GcU3Ekdx3Pw==.ico
文件大小 464 bytes
文件类型 MS Windows icon resource - 1 icon, 16x16
MD5 d344ff75aafc44866f13bc1144f1ee5f
SHA1 37fa004c894a0d2690b7ef723b37fb037db8010e
SHA256 d67f4503c6fcfe9efae8440e09b3df45ff75adf98e44ffea012aa5780873f3db
SHA512 25918fd8ab26f6c8cbe289e0f1b1845c70c3870037b96bf95df3ca424be69acc6583fa96df88ca49f2fecd127a22d3c662a49288eab8822725859f66975da61e
Ssdeep 12:/Uv/7rddT9zVNYUcT89Km5fZ9NsWXbPYJwlsAlIlzUsE5N:4ddMuKwZ/XbPYyBlIlcN
VirusTotal 搜索相关分析

CA7C3d01

文件名 CA7C3d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5\A5\CA7C3d01
文件大小 31891 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 80", baseline, precision 8, 390x330, frames 3
MD5 9e80201260a4c4cd4d7b9dd56efe5aac
SHA1 14ed753fef49f6c13ae1cc56b94856fb6ecc060d
SHA256 bb960ebb82a4523011c103094c7f07f5854298072dbc5f48afe687c421e408dc
SHA512 054f0e13bcdd2ff0573ebe999b668b00edaa2768ca8fa5d51e3e2cd16dc0acc55219174f361bab17d45474622671ffecb3affce80ebcea9468ddc9011c1b7f35
Ssdeep 768:Qv/3r9E29kwXzQdAlpfr2nc691KSmvBKFGzV:QvDk09D2nc691KSwYGB
VirusTotal 搜索相关分析

5522Ed01

文件名 5522Ed01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\DC\5522Ed01
文件大小 28687 bytes
文件类型 PNG image data, 226 x 425, 8-bit/color RGBA, non-interlaced
MD5 2bbf108e0dc7991f87148b6a88bc9b5f
SHA1 e9ae86a442805e1e35070df44fae700b518f5921
SHA256 6f0c2f4bd04564927ce83b2e9fa65034728c708b25f21a7e71b55c1ac3f35d89
SHA512 4dbcf0c5c338dcbdcb0cf1f86b4bf582f13cc2c11e8877579ef6eaadddaefe96bc0c7b0da8c80d3951ec0e94c3a50894f39757e84c5a8f267de62374172d99ce
Ssdeep 768:mNMJ1alAFfIMakdxe3IUNNY2XgvJGc924YzVrMs/Ko:m6alVwds4uq2X2JGcUHRKo
VirusTotal 搜索相关分析

1C568d01

文件名 1C568d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9\90\1C568d01
文件大小 63592 bytes
文件类型 PNG image data, 394 x 442, 8-bit/color RGBA, non-interlaced
MD5 b8b705025d25e99ccc03586cc9620c8b
SHA1 613575b8b62de6e5ac1ccbed38f9c68bb7d4f2ed
SHA256 90609ba9dee4f6f98b2f66a255c86381c33411d34603230c1e69d5dbda0157d7
SHA512 981b4580c1f677bff2e3fe5702ed74879fa11d16a9597fb93d528d1c4f4e6e7910775c19acc6054e1dc308357447cd3cba387b1c0090a56524718fcf6d35957e
Ssdeep 1536:CRERp/KyxalrNJorCqKYvwp5SCf3NUl/5I4KAR:uERpSI269KYop5JdEvR
VirusTotal 搜索相关分析

369ABd01

文件名 369ABd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\77\369ABd01
文件大小 37969 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 70", baseline, precision 8, 610x690, frames 3
MD5 517781272e69828b09886824cb25b571
SHA1 4633d7adc811715d9ce970ec10967a2eebdef2b5
SHA256 e0f2aaea808c8e8219b16bf9a537930c37ba55ff05fec5049566db3cfec01bba
SHA512 658b699d9cba501fa12fe7b3b61b304b687f9c0599d4c2733831e40f3b7a7020b78943c8f8d43f49a2f78fae2dfe27fee1537381483c58dd43231200ebe44975
Ssdeep 768:2cfxfxQLEh8XaZauNpQ71NuqL5ghUcTeDZNGHldc7m4ws:2cfxfxQLMcaZauTCJd1B2HAm4ws
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 728c342bc9cb55ee79fa41d658e1ff43
SHA1 bbaa3e10acf565026f2ad0a579c8bce0277d696e
SHA256 1bc0474574519277dd815d04aad33be25fde3e5d3b53da591d81defe25ad2f0a
SHA512 37e8a7e84aeba9474e38961597a7e42d688b093a4cda6c3a25ffd1e64821efa7a21647ac631358223e426d538bdab87f7bb05cb228195e6ddb9f5c375fba17aa
Ssdeep 24:7+/uhRJN+s0J+sAf+egMHQMHcB6tKfJrHZP0rH424w6Ln5vEah76wd4+K:7euXX+s0J+sTMwM8gKf9SDD6Wa4jJ
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 9741463b8e40d56165133d4ea857905e
SHA1 f1ce2e1584e68e61010bc0abdf2009f42f8b0b1b
SHA256 a1dd078f808eadcc4a569e59f17e7a53216ffc9b08179f4d38e89ba14ff12173
SHA512 3bffa8af7e6add233b53f9d1cbbfaa6a4941ad4e7715059fff608657b937440e0564698ac603e12f56910c16efe2bdc5024c6dfa9c0e190143e8bf3ea5aea882
Ssdeep 24:7+/MlwhRJN+s0J+sA2+egMHQMHcB6tKfJrHZP0rH424T6LREah76wd4+v:7ekwXX+s0J+sGMwM8gKf9SDg62a4j4
VirusTotal 搜索相关分析

_CACHE_002_

文件名 _CACHE_002_
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_002_
文件大小 4194304 bytes
文件类型 data
MD5 890b082b838fbc1e9f01732f9f614015
SHA1 f6d21b0b707af0e2baad5bce67adebc41561a101
SHA256 36ab365e17bac7fb919b4642ec6794c8da969be9242df80de45b766247bf34d3
SHA512 5c6b6c9c65bfd7a54e2552861175979af66b37b1656891a1e6a5507f7da404ac6030d01f7f83141aebde2b607c3b2140e8fcc10a312d46b7897feb000caaefe8
Ssdeep 1536:gYFundKJfbUMDahV39Pm5hr4d5VSCFpDRAm7uIK1niRAMTywvb7m1cPx457gi:1u4FTsbmPrm5ICFuPPgSS87gi
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 d3cba4e6924d173e99c8a274f3c3c32e
SHA1 52680524971a13e4d045efdc15586bef9c2ddefa
SHA256 0e300fc9595f3cb846416d0c7cd280b448bb33c501c9ae0bb0c488dcfce87dc8
SHA512 d18a6395f16c993beb6a8c81dccbc1db322b09ffe28eaf8b083a559a6623d130e4c2a66d32b24c16acbea36e93b7175d62bcfdce8f23f5048ebf988946514a3c
Ssdeep 24:7+/AhRJN+s0J+sAP+egMHQMHcB6tKfJrHZP0rH424+6LREah76wd4+s:7eAXX+s0J+svMwM8gKf9SDh62a4jH
VirusTotal 搜索相关分析

831C3d01

文件名 831C3d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\02\831C3d01
文件大小 34823 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 50", baseline, precision 8, 448x447, frames 3
MD5 27c80a2ded1e67151fe6f09184bf48d2
SHA1 8175427581bd422be30a48b16e7ce5f317d55051
SHA256 3f4f5c496b94bba3472870fd08bdef837be612d7d67efae2811f9a94c1c09bea
SHA512 739248b27ee7c8ffb5d5e845b07b2d4f761915ac15fc78f1e0b3a3215b255f6b794302d51277c39ab0a80b18466a99811398387f21fa8913363b9860fbc22ce7
Ssdeep 768:3d19DuF7y5jAVnjTGAsfq00EgjgIWUhras/4wKjmD1nxxxwJLtccE:3d19DucNkjCAsf0tjvWCasgGpnxxxwJe
VirusTotal 搜索相关分析

_CACHE_001_

文件名 _CACHE_001_
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_001_
文件大小 4194304 bytes
文件类型 data
MD5 070fd9ca1321d1333d436d9391fe4f36
SHA1 69d783264009668d325f05e870714f02b4bbf4e1
SHA256 85b07c87c39c63b43224b10af204dcfa77ae965157876dc094716a88e9eca57c
SHA512 dbd676a9c68e8b7abe9f98996d54a2f6a3b9a36c1562f66c0963516d0e6e38f26601b3f7358f2b0d6fbb62dec3b2ac59d8a0cd627b6f53b0b3224e70db3475d4
Ssdeep 384:rQihZNp5h/xQPMEGiib8xBSXLc4uraauaOr9pfDsJU2paGabTpJOWNfzVXrwUCE9:bGv1xBSHSasohALIF
VirusTotal 搜索相关分析

3AC21d01

文件名 3AC21d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\5A\3AC21d01
文件大小 37183 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 70", baseline, precision 8, 616x486, frames 3
MD5 00aa5dac6ff352e2270af80f9b89bebe
SHA1 f5255ce1a307c959b4bef02302bffe7558a01374
SHA256 2523510876944054af441f68d5f15f7eea058e9133f69aadcf9caab67153d436
SHA512 c561bbf4198c6d03c5fa37ecaaa5ffc9dfe6a81c69a0c7e65fb03573802c6b3f8b3b1e4ec4ca1a6d06862786c38763bd86282e917d59b53b564de0edfb758767
Ssdeep 768:JeDGEFmanHaTx8tEe1gfzxFoPl75RWBoDLjYFtRTpDin4Y8E:JuGEFmaHkOSXjoPVWB+j+jlmn4YZ
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 022557138cd235ddcecd366dda1e7940
SHA1 c704cde80df2f8a9e5780c1bdda7acb4714c0c37
SHA256 458360bea75fa3bb503a37d9c50a22b47d6c67eae6d4b718f1d96758459833ba
SHA512 08b05f560f265387c4e464e2dc42d3d6d9864fd4e1f8bdae700a4f0dab264abac06d74a65cdce38ef89b6b1120a328e7eaa8c58cf176c35f7754ec72729cfa9a
Ssdeep 24:7+/dhRJN+s0J+sAm+egMHQMHcB6tKfJrHZP0rH424X6LbdEah76wd4+4y:7edXX+s0J+sGMwM8gKf9SD86Ga4jJy
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 faab1ba41487cba578d957f1af6ac94e
SHA1 f09ff7ef91479bd56ada97522fc583fddb8b6211
SHA256 76b3bf609f8f9be2cdbf2eac7e0ea8dce8a41bf7f5059b20bb2a69bb0734414d
SHA512 d14d3daeefad879e362aeb3c16e4f7943c2af5cca69250c82584ef2bcae461d80d81a0beb72c06cc9007a98d4676529548d4f045cf6ac13a2d33eb8d9c343d83
Ssdeep 24:7+/Y1hRJN+s0J+sA8+egMHQMHcB6tKfJrHZP0rH42466LREah76wd4+4:7eY1XX+s0J+sUMwM8gKf9SDp62a4j/
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 f8b4c68b942f4ddd4703d58775bbf4cb
SHA1 409162b93072dcdcf988d9f42781d1468c564443
SHA256 46e49823a639c315a991313312a7f24fded46b21b5c401bcd88e836a17a8531b
SHA512 76e715efcd5bec285f236419e726f166881854401913caa5b2b69e4c93094ff8535db06019025ca315d175a3ceca02a3599ed42e05020a56156a11ece2f44a0d
Ssdeep 24:7+/zhRJN+s0J+sAV+egMHQMHcB6tKfJrHZP0rH424y06LhEah76wd4+F:7ezXX+s0J+sNMwM8gKf9SDS6ma4jq
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 07214b9cef6bf206a85e6f433b5faace
SHA1 4fe504b9b61749be32f9c89f71420325fb7c18b7
SHA256 e4845b6ec82039c8ed2f77bce7a673b95eda5b026791b97ff4faeff0c16e23e7
SHA512 5e3a7d11f6950943fcab03addf483833805dc23bffd92a5527450f17b8341b3034640d0bdc48f8cc55370c4d59c584090ad1e5b7e211da71c882db257971ed88
Ssdeep 24:7+/EhRJN+s0J+sAi3+egMHQMHcB6tKfJrHZP0rH424Df6LjVEah76wd4+b:7eEXX+s0J+s3GMwM8gKf9SDEf62a4jc
VirusTotal 搜索相关分析

_CACHE_003_

文件名 _CACHE_003_
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_003_
文件大小 4194304 bytes
文件类型 data
MD5 e10ddb91b27ecd7d7353b4009aa170e8
SHA1 25b0ffe087aeb6e488c9dfc52e74c7ce5cfeb4ef
SHA256 816d77e59052a9544a7c6266e4ca94d3f6ce2b37ff211e1eb80ee548eb1d4cbc
SHA512 ab8e0b21656815a5bd7281111bc9e9cd5ce1bc77562eb9eca2a3ef82ca08405ff27ebd6c89362caf01d6c23ed40ac71254390ec382ab7a4d5b53dd32a3209e27
Ssdeep 12288:/WMxOOqxgxv4YV3SVJkB3rGZJkxLIFntKFjcFx3zIztpJ0npOKhvftIV6yE8KXqH:/Bl42Sv8kFt4A7dhvftfyENX2O
VirusTotal 搜索相关分析

_CACHE_MAP_

文件名 _CACHE_MAP_
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_MAP_
文件大小 8468 bytes
文件类型 raw G3 data, byte-padded
MD5 ca2bce5a65a727ca4fa205cfe6cc2c6e
SHA1 bc19bc0212b4d4cc41550691b34363d854ca6113
SHA256 2d486fc0383f24229d4c6dfd7d90bf9540190308fead00e6d2c4352a07a26801
SHA512 ee8581cf15035e9b204e9fd2275ca96dc5a32d73e3687f39ce32c9391162454ca66bb77553d75acc2b5427e2bf84c82fb354d11dd0395494e90a592e5ecb2569
Ssdeep 48:/i65fWjrL3njlQQ5IaHQIlY9yDDdnrGRQUelxJ/uTRIKVFCB3/:/injlbJlXdnSKXJ/uTiB
VirusTotal 搜索相关分析

F2102d01

文件名 F2102d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\D3\F2102d01
文件大小 88864 bytes
文件类型 PNG image data, 390 x 327, 8-bit/color RGB, non-interlaced
MD5 6dcddbd4c28916a70f9c4cdb858fb026
SHA1 f9082ae04af37c238c402dd58d2449bf773888ef
SHA256 e98b5a9acb51905cfcbcec004a7beb6ef35786e6b15fece7a723fbba291a9a94
SHA512 14b60f6ba2b3e73d98f14f6df8a22738a71679cdae069b82672eee9b5c52df38d1af1e563457e4f283d1b9659dca6941a5b56930af157e943e303de43e94ad2c
Ssdeep 1536:4TGQxTcSQNZ6r7HbTim0NRpEVtDxNkmtw4QuChK:WnRQNCX0pcD4mnkc
VirusTotal 搜索相关分析

64697d01

文件名 64697d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\72\64697d01
文件大小 58248 bytes
文件类型 PNG image data, 390 x 330, 8-bit/color RGB, non-interlaced
MD5 c2056f2c2a1d5cde6c6115381af7ff39
SHA1 e1ddf86a12622df9972dfd34c0052186f6f04231
SHA256 011918413fe90d9cc85d5c5b40ab41a66781582a9b1a194fd408fee2df37a7d6
SHA512 4bfc514e638fa74f636ca50a9d36d15a35944c3aa2f96cb7288196595eca1905290a10c7070d4b8343b257eb7683ee103a392deff704cf10f93c23e913792537
Ssdeep 1536:FRzBNeTo8gWJm+LbyBpRph9R6cRwfYOKdrPN9P0s7wA93:jneTrBY+/ORpp6cRwfYVb9fJ
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 a08072a66a45cf333c613d79d8e7f1c0
SHA1 64fae4119083084600e1d6b303296f23483d288f
SHA256 b8b03f85aeb1fec9be7fea25bf34105ce443e31bc65a83efb1d8be6894f4733d
SHA512 cfc3cfee387c04ad48fa9365943059eb1b700f0a4c2663d63c6e47c2e501b8ac056b5c670885cf9c7f2ea96e98f511ee257141c0f96a67037db135700d84bda1
Ssdeep 24:7+/FhRJN+s0J+sADi+egMHQMHcB6tKfJrHZP0rH42466Ly1qEah76wd4+U:7eFXX+s0J+s4/MwM8gKf9SD56Ga4jv
VirusTotal 搜索相关分析

permissions.sqlite-journal

文件名 permissions.sqlite-journal
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
文件大小 66064 bytes
文件类型 SQLite Rollback Journal
MD5 393dc808d438d596f1c3fd43b6360c42
SHA1 20c292c63a762a57156afc1038b17cb0c2cd95ea
SHA256 b09b2b6ed2f65e31ab3686aac95f9b193f330c2de8672c6f6b9e2ed0bb1242e4
SHA512 33272fc2397d263941343a0f2cdc18d751e6aa49d3e85ae2a522de60f7b3ac75bf34a601fcace8dbc1603b7881892d409e7bd3d75b77243dfb8ee58d7267c38f
Ssdeep 24:7+/5hRJN+s0J+sAk+egMHQMHcB6tKfJrHZP0rH4242v6LKqEah76wd4+Y:7e5XX+s0J+ssMwM8gKf9SDRv6m3a4j3
VirusTotal 搜索相关分析

permissions.sqlite

文件名 permissions.sqlite
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite
文件大小 98304 bytes
文件类型 SQLite 3.x database, user version 9
MD5 3c0069792104d89265b34f9b3271b1d5
SHA1 9a0e8bf6ed2979959660dee3f1b5825e5a3a7b4e
SHA256 72cb1413ec809d60bb397e1cd6b7a37985025136fd3787fd28f91760f71cdeb9
SHA512 ac511c6f3ef406ffd569da6210edbed14906ac07a993204410854755e9d0f0803ded2775f37dd2931203ae45fb7bcabc67bb1f46b059d37a3a936e37d5b07d2d
Ssdeep 24:DLqqEah76wd4+k6ZkxGhRJN+s0J+sA9+egMHQMHcB6tKfJrHZP0rH424J:DGa4j9GXX+s0J+slMwM8gKf9SDE
VirusTotal 搜索相关分析

1409Bd01

文件名 1409Bd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\B7\1409Bd01
文件大小 28015 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 50", baseline, precision 8, 430x430, frames 3
MD5 e7b438babc6e29cba9ff612c33eac419
SHA1 69fcecb69de4841f019c634c3e6d2fc63a7e29a5
SHA256 41530c845f79c45a56b3f728cc0c35e8be27c167a672292b678697a219833ce0
SHA512 3aff9f663fa6f21b2017ab0b3dc05394ff9901929e0990f727373c7953141e18e018f5cb1cd3c835c70f6773facd9937d8ca20865af06121916f262c725b8744
Ssdeep 768:IVRjqdE5XejeSLIB7POtYqeDvNlTaeOWVaR7zciwCV2uoFpTnNsu:I7q25Xeje48Pbqg15aeOWVaR7zQCV2uQ
VirusTotal 搜索相关分析

ECD55d01

文件名 ECD55d01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\08\ECD55d01
文件大小 28100 bytes
文件类型 JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 50", baseline, precision 8, 430x430, frames 3
MD5 80e48ad8386f75b49fd6c7f9af35d401
SHA1 efcebf553e82854283e857c21a4ef69e37a0e6ff
SHA256 8f81b52ce77d2b4b3f2cae107ce9d6557e1e24ad150f52c4f44c63af072483fd
SHA512 e644503cebba2f31dad50e7017d4d356382d04d96326da295dae0b715f33e79e89adabf4ebaa0c31b0a1b09b94e30fdec0edd7c7171b5b53ac1df7dfdca9639a
Ssdeep 768:IVhSzgwPpveJv5YPJvuS7CVyAeFeHQXdXrzujdX4dnVoSyUYGs5bqQPBbB:ICgwPpveJv5YduS7CVyAeFeHQlrA4dnq
VirusTotal 搜索相关分析

urlclassifier.pset

文件名 urlclassifier.pset
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier.pset
文件大小 32 bytes
文件类型 data
MD5 8e9dbc6e67b3108b335a6f0d6b7d7373
SHA1 2873233af908b57aa3ceb1de1ef095ba09a2b0ca
SHA256 cd0e673429731ec7845b56680010a5df7aeebf3b6a012d68b7464d139b314545
SHA512 63e73f440ee7126cbb9909ee2e919862d7594d91723c2eb5726772ca789a402558ccb826f9c20af3df6d0e21c130bbbcb7de6ebe01ea441f9a373ca1d2f09777
Ssdeep 3:RM/8inqw:RXiB
VirusTotal 搜索相关分析

cookies.sqlite

文件名 cookies.sqlite
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite
文件大小 524288 bytes
文件类型 SQLite 3.x database, user version 7
MD5 b44628dcc6cecb3f9664b139e8e4b3ff
SHA1 2a29268033a1a341c53f86a0a54a7064e684861e
SHA256 1dcee53d1656825e15d31f61aecc24f0a6619d25b8c32e87e66bea241e3036ef
SHA512 89a84f8143d449bc6ae658353613dcbdad2c8f202a5ac6704135eca9ea870ecbed506154aac110518094d2b80d7b0a843dd7b5cecfb36df037fe499206fef6e0
Ssdeep 96:DxWymPK7JXssaJsH+einm7zwMbktJHgVaui9fGN09x6CeTrZ0X4I8zdNRi+DZmL8:symj7tfnCc9fu0GTneIF5FDk8LLy
VirusTotal 搜索相关分析

sessionstore.js

文件名 sessionstore.js
相关文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.js
文件大小 11760 bytes
文件类型 UTF-8 Unicode text, with very long lines, with no line terminators
MD5 c683526c40b69a1c18598e5116b3adbb
SHA1 982dfa1f865410d64a8b1d7c5619e54aadeb6551
SHA256 3e6c4de5b8a312c6f49beae6c268ba1655c37e7dee7592fbce40fa6e03a01613
SHA512 7ad910632e0e86e7dc63d56f45c0df7a67a1778ae85856c8e33e4aa3ec5d3ead904b1cf8790388328ed282bed13fc8b4843ba0f01dd7394d4593b79abb29074c
Ssdeep 192:/CJTJgh7Ih7yKqwqihCQ78iGiGZuiRBDzyz9Zi5SB:qBCsVTjCQIiGiwuiR2i5u
Yara
  • without_images (Rule to detect the no presence of any image)
  • without_attachments (Rule to detect the no presence of any attachment)
  • Big_Numbers1 (Looks for big numbers 32:sized)
  • with_urls (Rule to detect the presence of an or several urls)
VirusTotal 搜索相关分析

8D9XF2FiId5BiBvlVUc6Ag==.ico

文件名 8D9XF2FiId5BiBvlVUc6Ag==.ico
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\8D9XF2FiId5BiBvlVUc6Ag==.ico
文件大小 424 bytes
文件类型 MS Windows icon resource - 1 icon, 16x16
MD5 6506fd27172f6da2d8b281cdad29532e
SHA1 9cfb0754248517a50dfee4cefbe14f6758c5d0b6
SHA256 d0d8db6f04dc8587f81a0e398c02c3ce6de45a7a796437e8a46c58dd0857551a
SHA512 94931cb29cfdac4d530331ec6adc7d66c9752835bef938ac6a8dc3c331283ed1a377586d63bce42f9ebcc8154d9f7fcd17ff5b66fe608e0face7fb227f9d749e
Ssdeep 12:P8v/7qgepUp5xDKKZB+QlTaBJF+hQ5QL3d76sc:fgepXw4QZKJF+OY3d7c
VirusTotal 搜索相关分析

E642Bd01

文件名 E642Bd01
相关文件
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\8B\E642Bd01
文件大小 23090 bytes
文件类型 PNG image data, 229 x 80, 8-bit/color RGBA, non-interlaced
MD5 a61a7697b8ca341a8b78f6ce21a17fe8
SHA1 d0d58b8e410e9fad9751697d5de58ebfb2da3acb
SHA256 869c9bc1af4a81bc9cd989c56252213438ce04cc70dea05d4d28effbfbcd1d83
SHA512 3a2cced56a7e6f3bf4c4851cd1b381057d278a5092ef219496b856bed242750339851e57c443d7aa0123a2e781197dd09cf384d54a596415a965c72601987adc
Ssdeep 384:v50wGG6yEbxz+dbQTpWd0JF4ydjP1w1MIFh64lz9edsrOIU6Z9aBM:xoGQxz+tUAdcF7i/hVlz9edsFUTM
VirusTotal 搜索相关分析

行为分析

互斥量(Mutexes)
  • Local\MSCTF.Asm.MutexDefault1
执行的命令 无信息
创建的服务 无信息
启动的服务 无信息

进程

firefox.exe PID: 1160, 上一级进程 PID: 1896

访问的文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-wal
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\blocklist.xml
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_MAP_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_001_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_002_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_003_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache.Trash
  • C:\Program Files (x86)\Mozilla Firefox\chrome
  • C:\Program Files (x86)\Mozilla Firefox\chrome\icons\default\default.ico
  • C:\Program Files (x86)\Mozilla Firefox\omni.ja
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Mozilla Firefox
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\search.json
  • C:\Program Files (x86)\Mozilla Firefox\distribution\searchplugins
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\searchplugins
  • C:\Program Files (x86)\Mozilla Firefox\searchplugins
  • C:\Program Files (x86)\Mozilla Firefox\searchplugins\*
  • C:\Windows\System32\spool\drivers\color\D65.camp
  • C:\Windows\System32\spool\drivers\color\Photo.gmmp
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Program Files (x86)\Mozilla Firefox\update.locale
  • C:\Program Files (x86)\Mozilla Firefox\chrome\icons\default\main-window.ico
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\content-prefs.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\content-prefs.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\content-prefs.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.bak
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.js
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-shm
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-journal
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-wal
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier.pset
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.rdf
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.sqlite-wal
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\test\AppData\Local\Temp\etilqs_QpIBMFnawBXurQW
  • C:\Users\test\AppData\Local\Temp\etilqs_1HWxUeVSYTmP3Xg
  • C:\Users\test\AppData\Local\Temp\etilqs_YxKZUe9Psd9Lw4G
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\60
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Mozilla
  • C:\Users\test\AppData\Local\Mozilla\Firefox
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\60\703A9d01
  • C:\Users\test\AppData\Local\Temp\etilqs_kbvTcEcXQDYgM9t
  • C:\Users\test\AppData\Local\Temp\etilqs_IhnIKPAL9xXVgbY
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms
  • C:\Windows\SysWOW64\propsys.dll
  • C:\Windows\sysnative\propsys.dll
  • C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  • C:\
  • C:\Program Files (x86)\desktop.ini
  • C:\Program Files (x86)\Mozilla Firefox\
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\ED
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\ED\86788d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\DC
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\DC\EFF56d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\9EylVkFXj05W7m33cbQ4cw==.ico
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PKEFVXFB87R7UKUWUA55.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF25aa1d2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\3HExo8vWuk4GcU3Ekdx3Pw==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\sHRfRnkemptTqcH4R9AbGA==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\qoRS7uunTyPuNt5ZB_dUSQ==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\8D9XF2FiId5BiBvlVUc6Ag==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\0u9zG3TzKYoRkKqp30_ljA==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\+p3qxbTJL55LVApuidqGLw==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\8B
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\8B\E642Bd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\84
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\84\46FA4d01
  • C:\Users\test\AppData\Local\Temp\etilqs_f65XMjRotyyY4QQ
  • C:\Users\test\AppData\Local\Temp\etilqs_CFSJc4kJOzHoHgR
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\50R4BTVNFG6PI0ML6U53.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF303757c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_YICU7pXlUa1Aauo
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\D3
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\D3\F2102d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L10NNXN4SZZZ10VME21T.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF31114c0.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6ZGB4ZTEEEAKWQBI2SOJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3158715.TMP
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\pluginreg.dat
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\plugins
  • C:\Users\test\AppData\Roaming
  • C:\Users\test\AppData\Roaming\Mozilla
  • C:\Users\test\AppData\Roaming\Mozilla\plugins
  • C:\Program Files (x86)\Mozilla Firefox\plugins
  • C:\Users\test\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
  • C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll
  • C:\Windows\SysWOW64\Macromed\Flash
  • C:\Windows\System32\itruscert\NPComBrg701.dll
  • C:\Windows\System32\itruscert
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin
  • C:\Program Files (x86)\Java\jre1.8.0_121
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2
  • C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
  • C:\Program Files (x86)\Microsoft Office\Office14
  • C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR
  • C:\Program Files (x86)\Adobe\Reader 11.0
  • C:\Windows\SysWOW64\Macromed\Flash\*
  • C:\Windows\System32\itruscert\*
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\*
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npdeployJava1.dll
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\*
  • C:\Program Files (x86)\Microsoft Office\Office14\*
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\*
  • C:\Program Files (x86)\Java\jre1.8.0_121\bin\new_plugin
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\*
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
  • C:\Program Files (x86)\Windows Media Player\wmplayer.exe
  • C:\Program Files (x86)\Windows Media Player
  • C:\Program Files (x86)\Windows Media Player\*
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-journal
  • C:\Users\test\AppData\Local\Temp\etilqs_pYdWcKVN2p3As4I
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-shm
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\chromeappsstore.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\chromeappsstore.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\chromeappsstore.sqlite-wal
  • C:\Users\test\AppData\Local\Temp\etilqs_INBmeoMceeVGLQU
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X29DSOT7T5PX5O4EXZK6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32afa0b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1W43QQ7XON5H7V56DL01.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32ea68f.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MZXI9MHH4553RURID8DZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33323dc.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\D8
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\D8\810F4d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\77
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\77\6D45Bd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\4PL8ZGRZTQASFKD7REC2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33b4904.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\30
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\30\F90DEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I2QOHOCFPUS044OMPP2I.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3437be7.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\1C
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\1C\F0983d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P7C9LIR5MUQ5O4GRVWR9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF350178b.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\72
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\72\64697d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FV2CJBZE5U10F995MCVO.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3501c06.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\DF
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\DF\5CE2Fd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5\A5
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5\A5\CA7C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\5A
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\5A\3AC21d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJXYW3UFTHVB71QH78AT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc546.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0LB4K8ASAGNMBSSLAEQV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc7c2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C\3A
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C\3A\668D9d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\02
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\02\831C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\77
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\77\48016d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\B7
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\B7\1409Bd01
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YMY1E4WNIYMOXDT6TSJF.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF363f2b2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Fcc9Qgg7Mi0FC9r
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V3Z3YLTAF3PANR0IURYV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF386c6e0.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_ajGC3wOU0npN7fW
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\95
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\95\C6493d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XJ65CERDGY2BNSTM6E3D.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF38cbb79.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_ZYLfWhWl518UW5q
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\lxLIs2AH_AMFqw+CHXsXRQ==.ico
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DA2WNK1F1ZHHXNSK8Q6G.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3d9558a.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\08
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\08\ECD55d01
  • C:\Users\test\AppData\Local\Temp\etilqs_hAbCb3PIBrt6Ukp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60OXF6KPFXMVEFWO5Y14.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3e90ca2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Xk0VQFPgf3BJnGQ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HKJJ5AJYK96J252W4XFU.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF41239d1.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Bdb8ZuxBIgySW33
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9TE2WGCHC1URNV98UGBX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF44b65b1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ITUKSGAXSVU0ITCVXGUQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF45319c2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_4m3xtu0PsILfoID
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\66A8VDB6YEP93PE75A64.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4591b0c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_cJEkIDbl0nFmP9f
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J2TK11NV9D2N9RZ683IH.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4978c11.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_YcWw91wM6psi6Qb
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D8UWJF8WHN7GANSGHLHG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4a5e15c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7CL2OHPDIQF80O4KDCCX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4aa9873.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_PoDaPdNSia6BV7S
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0ZXZTA9IEAU0S9G2YTR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4dadf06.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_MI3IE69MTTadbbf
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0F68YRR8BGDR27NQLB8B.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e271a6.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A4
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A4\54DFBd01
  • C:\Users\test\AppData\Local\Temp\etilqs_EHNKWfnMhd0Q7wq
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JW8XFYTBW6D376NK4UBX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e6f9d2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\06
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\06\793BEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6GO038XSF921ONW4G0I6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ef1381.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GSYVDN2UAB8GRUEMOKDV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f0e83d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3SEBECE2RAJRRZVC8O6Y.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f8dd6d.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4\6F
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4\6F\9422Cd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\96
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\96\E1093d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\C5
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\C5\DE623d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YBHGOQWRD48QBUOQSQ35.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ff28a5.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\40
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\40\22B99d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\77
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\77\369ABd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RZ2ZR1NAPL7HCHAH2I2Q.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF50cc682.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_vhe6qHwFjY4QMGn
  • C:\Users\test\AppData\Local\Temp\etilqs_mukbeQpa4o69eN4
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7A73QEXS1DGRV5DNCUPI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF529d3ac.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TJDD2JYI0A429C26EAA3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF56ed8e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\58LYR752GI31SAH8FC25.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a12436.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9\90
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9\90\1C568d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\H7QYXWGRY8T08P6HFER1.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a1eb99.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\DC
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\DC\5522Ed01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A5
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A5\8C1CCd01
  • C:\Users\test\AppData\Local\Temp\etilqs_R74e8dafqNXIU8W
  • C:\Users\test\AppData\Local\Temp\etilqs_v8tXZozQqpzEkcN
  • C:\Users\test\AppData\Local\Temp\etilqs_VbstY3df9uI0TRK
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Q6EYR2TU5EPZYGXNA6HE.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5d5ff0f.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_C6PNmCeaPjLdycO
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AUBRMRTDDUHIT2RTCAKJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5e0f855.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9A21KAJMMI3WEG3WIXYB.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF604b364.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_RKZafrImALFaT0t
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7OD7G2ERICY1K74TEQNE.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF60cc9c4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CBDEAX04YBR469H0RM8H.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF615aeeb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2HFZOM1QPNJR2KA9OMHF.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6230313.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\AD
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\AD\57C43d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0YEZLPFB2VPUHMAR534S.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6277188.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\R6SPF3HD2C3M5OQXE9HI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF62be1a8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S9MGTONPRHKYJ5JCLFKR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6305405.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LBHJHKKC3QDN1PMD5XCX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF633f7df.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\358RZYS58CA45PZRR8NV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF635cfdb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\UYBQL0YBS1V1ZOFDPWJU.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF637a7bb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3WZ0QB6YLN1SV8IUDM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF639862c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HBLV5CIMAYU537PUUZCI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647afdc.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HYY9RQQSWGDEPHJL5092.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647ee22.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_XsLn5lJFfSqf5hB
  • C:\Users\test\AppData\Local\Temp\etilqs_XA7135xAcmrUepT
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KTO6C7GPDETP29RZP4EO.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF68790cc.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_seZVFxFwZ9V6zfz
  • C:\Users\test\AppData\Local\Temp\etilqs_aDJF8Vufl4yQScA
  • C:\Users\test\AppData\Local\Temp\etilqs_5fkdGg4A9dEheXU
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore-1.js
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Desktop.ini
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore-1.js\
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\
  • C:\Users\test\AppData\Roaming\Mozilla\
  • C:\Users\test\AppData\Roaming\
  • C:\Users\test\AppData\
  • C:\Users\test\
  • C:\Users\
  • C:
  • \??\MountPointManager
  • C:\Users\test\AppData\Local\Temp\etilqs_KJJv7AFAT5TBIxY
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W3ECITNLLDHM3D084AAS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF70f3d2a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RWCPI33ZIDS5AHTQ0HSU.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_G8cVGNpOTJGqJZ8
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7146db8.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_lbJVOruSJjsUaaJ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VZ40HVBYR4IQTPGOP73Y.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF72bc1d4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6S44HT3WXPBJS50DIEHI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF731e63a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P3DXK7N701KUY31N98MA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF734af67.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T1VV0FF7ZZ38RQJO72PB.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7393729.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YSMP0EAYFSKE69DY64KL.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73b0812.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51KF0LY5BQRUPRDCRZ2B.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73cea5c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_zV6yexR5K4gdStt
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LSERJKIRMLME5QR9CPQG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74fd138.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2PFG6VT1J0O3OR2FSE38.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74ffb59.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SRMXVZUH3248CF226ODM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75a7aed.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I4QKHCSJON91YE9WPCRX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75c5615.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VDH59ZNHORP74Q2OT1PP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75e4b05.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YCML11WKSNR4QB6FCR2N.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7601261.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3WKBT3JZKRA8ANK72EM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF761ea4c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FGGNIAZZYY74J6C394H7.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF763c4ad.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQ4WGIB4H90A2JEEPUYG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF765a058.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XNPVIQ8EKQ4CJDNYGK76.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76775aa.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AO4YGK1I1CKHDH6QKEXC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7694aae.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RVDA8E1II9D6S4QIDUXV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76b22f2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6CKY4SLDJ0R2GL6R9YDJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76cfe1a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HCWK44Q03BL9P61GTFVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76ed966.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GS6D4Q102M3A7PKVYCNP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF770ae52.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HI78QF66CXRH8YIBNBJQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7728329.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LFBNFE106XH942B770DC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7745d94.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\COHLNHQNC0TGAIT197CC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7763283.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\POH8MMHLSNJ0CU6LCG46.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7781ae8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IC3CT0VMJ76D9JYQE1D6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77b4ef1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NA2N3AXOU5QSMHEZJ9W0.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77bc801.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BUIK7KR0QLFKSJTS9XVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77dab85.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KMBQ6HK4Z648C629U9DM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77f8562.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K9QLPEJNAIZBVSVSPOG4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7815df7.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FEOFPRUB2SK48GOAQVMG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7833b0e.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\EGBD0N11Q14U4XOM0W6Q.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78512eb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3RH7NST4TTWX2U3LP1A3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF786e6e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V92SMJWQWO3HV21AXG8R.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF788be2c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0DIWGTHQVW9YD7JOKDPT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78a9452.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AJFA2BRMNTXQOT0DZCVI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78c7b6d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9JUZYYNBX2H0LZV06S39.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78e4942.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S5RNNWZJHPFIMAR0I3IR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7902710.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3M1CGMOD090ET9FV3ZK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF791fa60.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9ABJP20BQQ5DQOADZQQZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF793db7c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L8ACE7XEXMULDL6XEHPG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF795b0b0.TMP
读取的文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\blocklist.xml
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_MAP_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_001_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_002_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_003_
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\search.json
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Program Files (x86)\Mozilla Firefox\update.locale
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\content-prefs.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.js
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-shm
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier.pset
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.sqlite
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\test\AppData\Local\Temp\etilqs_QpIBMFnawBXurQW
  • C:\Users\test\AppData\Local\Temp\etilqs_1HWxUeVSYTmP3Xg
  • C:\Users\test\AppData\Local\Temp\etilqs_YxKZUe9Psd9Lw4G
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\60\703A9d01
  • C:\Users\test\AppData\Local\Temp\etilqs_kbvTcEcXQDYgM9t
  • C:\Users\test\AppData\Local\Temp\etilqs_IhnIKPAL9xXVgbY
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms
  • C:\
  • C:\Program Files (x86)\desktop.ini
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Mozilla Firefox
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\ED\86788d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\DC\EFF56d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PKEFVXFB87R7UKUWUA55.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\8B\E642Bd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\84\46FA4d01
  • C:\Users\test\AppData\Local\Temp\etilqs_f65XMjRotyyY4QQ
  • C:\Users\test\AppData\Local\Temp\etilqs_CFSJc4kJOzHoHgR
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\50R4BTVNFG6PI0ML6U53.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_YICU7pXlUa1Aauo
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\D3\F2102d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L10NNXN4SZZZ10VME21T.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6ZGB4ZTEEEAKWQBI2SOJ.temp
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\pluginreg.dat
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite
  • C:\Users\test\AppData\Local\Temp\etilqs_pYdWcKVN2p3As4I
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-shm
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\chromeappsstore.sqlite
  • C:\Users\test\AppData\Local\Temp\etilqs_INBmeoMceeVGLQU
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X29DSOT7T5PX5O4EXZK6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1W43QQ7XON5H7V56DL01.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MZXI9MHH4553RURID8DZ.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\D8\810F4d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\77\6D45Bd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\4PL8ZGRZTQASFKD7REC2.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\30\F90DEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I2QOHOCFPUS044OMPP2I.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\1C\F0983d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P7C9LIR5MUQ5O4GRVWR9.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\72\64697d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FV2CJBZE5U10F995MCVO.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\DF\5CE2Fd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5\A5\CA7C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\5A\3AC21d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJXYW3UFTHVB71QH78AT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0LB4K8ASAGNMBSSLAEQV.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C\3A\668D9d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\02\831C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\77\48016d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\B7\1409Bd01
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YMY1E4WNIYMOXDT6TSJF.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_Fcc9Qgg7Mi0FC9r
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V3Z3YLTAF3PANR0IURYV.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_ajGC3wOU0npN7fW
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\95\C6493d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XJ65CERDGY2BNSTM6E3D.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_ZYLfWhWl518UW5q
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DA2WNK1F1ZHHXNSK8Q6G.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\08\ECD55d01
  • C:\Users\test\AppData\Local\Temp\etilqs_hAbCb3PIBrt6Ukp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60OXF6KPFXMVEFWO5Y14.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_Xk0VQFPgf3BJnGQ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HKJJ5AJYK96J252W4XFU.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_Bdb8ZuxBIgySW33
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9TE2WGCHC1URNV98UGBX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ITUKSGAXSVU0ITCVXGUQ.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_4m3xtu0PsILfoID
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\66A8VDB6YEP93PE75A64.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_cJEkIDbl0nFmP9f
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J2TK11NV9D2N9RZ683IH.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_YcWw91wM6psi6Qb
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D8UWJF8WHN7GANSGHLHG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7CL2OHPDIQF80O4KDCCX.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_PoDaPdNSia6BV7S
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0ZXZTA9IEAU0S9G2YTR.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_MI3IE69MTTadbbf
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0F68YRR8BGDR27NQLB8B.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A4\54DFBd01
  • C:\Users\test\AppData\Local\Temp\etilqs_EHNKWfnMhd0Q7wq
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JW8XFYTBW6D376NK4UBX.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\06\793BEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6GO038XSF921ONW4G0I6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GSYVDN2UAB8GRUEMOKDV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3SEBECE2RAJRRZVC8O6Y.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4\6F\9422Cd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\96\E1093d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\C5\DE623d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YBHGOQWRD48QBUOQSQ35.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\40\22B99d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\77\369ABd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RZ2ZR1NAPL7HCHAH2I2Q.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_vhe6qHwFjY4QMGn
  • C:\Users\test\AppData\Local\Temp\etilqs_mukbeQpa4o69eN4
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7A73QEXS1DGRV5DNCUPI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TJDD2JYI0A429C26EAA3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\58LYR752GI31SAH8FC25.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9\90\1C568d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\H7QYXWGRY8T08P6HFER1.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\DC\5522Ed01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A5\8C1CCd01
  • C:\Users\test\AppData\Local\Temp\etilqs_R74e8dafqNXIU8W
  • C:\Users\test\AppData\Local\Temp\etilqs_v8tXZozQqpzEkcN
  • C:\Users\test\AppData\Local\Temp\etilqs_VbstY3df9uI0TRK
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Q6EYR2TU5EPZYGXNA6HE.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_C6PNmCeaPjLdycO
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AUBRMRTDDUHIT2RTCAKJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9A21KAJMMI3WEG3WIXYB.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_RKZafrImALFaT0t
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7OD7G2ERICY1K74TEQNE.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CBDEAX04YBR469H0RM8H.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2HFZOM1QPNJR2KA9OMHF.temp
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\AD\57C43d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0YEZLPFB2VPUHMAR534S.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\R6SPF3HD2C3M5OQXE9HI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S9MGTONPRHKYJ5JCLFKR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LBHJHKKC3QDN1PMD5XCX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\358RZYS58CA45PZRR8NV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\UYBQL0YBS1V1ZOFDPWJU.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3WZ0QB6YLN1SV8IUDM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HBLV5CIMAYU537PUUZCI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HYY9RQQSWGDEPHJL5092.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_XsLn5lJFfSqf5hB
  • C:\Users\test\AppData\Local\Temp\etilqs_XA7135xAcmrUepT
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KTO6C7GPDETP29RZP4EO.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_seZVFxFwZ9V6zfz
  • C:\Users\test\AppData\Local\Temp\etilqs_aDJF8Vufl4yQScA
  • C:\Users\test\AppData\Local\Temp\etilqs_5fkdGg4A9dEheXU
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore-1.js
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Desktop.ini
  • C:\Users\test\AppData\Local\Temp\etilqs_KJJv7AFAT5TBIxY
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W3ECITNLLDHM3D084AAS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RWCPI33ZIDS5AHTQ0HSU.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_G8cVGNpOTJGqJZ8
  • C:\Users\test\AppData\Local\Temp\etilqs_lbJVOruSJjsUaaJ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VZ40HVBYR4IQTPGOP73Y.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6S44HT3WXPBJS50DIEHI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P3DXK7N701KUY31N98MA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T1VV0FF7ZZ38RQJO72PB.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YSMP0EAYFSKE69DY64KL.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51KF0LY5BQRUPRDCRZ2B.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_zV6yexR5K4gdStt
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LSERJKIRMLME5QR9CPQG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2PFG6VT1J0O3OR2FSE38.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SRMXVZUH3248CF226ODM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I4QKHCSJON91YE9WPCRX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VDH59ZNHORP74Q2OT1PP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YCML11WKSNR4QB6FCR2N.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3WKBT3JZKRA8ANK72EM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FGGNIAZZYY74J6C394H7.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQ4WGIB4H90A2JEEPUYG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XNPVIQ8EKQ4CJDNYGK76.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AO4YGK1I1CKHDH6QKEXC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RVDA8E1II9D6S4QIDUXV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6CKY4SLDJ0R2GL6R9YDJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HCWK44Q03BL9P61GTFVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GS6D4Q102M3A7PKVYCNP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HI78QF66CXRH8YIBNBJQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LFBNFE106XH942B770DC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\COHLNHQNC0TGAIT197CC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\POH8MMHLSNJ0CU6LCG46.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IC3CT0VMJ76D9JYQE1D6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NA2N3AXOU5QSMHEZJ9W0.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BUIK7KR0QLFKSJTS9XVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KMBQ6HK4Z648C629U9DM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K9QLPEJNAIZBVSVSPOG4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FEOFPRUB2SK48GOAQVMG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\EGBD0N11Q14U4XOM0W6Q.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3RH7NST4TTWX2U3LP1A3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V92SMJWQWO3HV21AXG8R.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0DIWGTHQVW9YD7JOKDPT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AJFA2BRMNTXQOT0DZCVI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9JUZYYNBX2H0LZV06S39.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S5RNNWZJHPFIMAR0I3IR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3M1CGMOD090ET9FV3ZK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9ABJP20BQQ5DQOADZQQZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L8ACE7XEXMULDL6XEHPG.temp
修改的文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\cookies.sqlite-wal
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_MAP_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_001_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_002_
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\_CACHE_003_
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\content-prefs.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.bak
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\places.sqlite-shm
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\downloads.sqlite
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier.pset
  • C:\Users\test\AppData\Local\Temp\etilqs_QpIBMFnawBXurQW
  • C:\Users\test\AppData\Local\Temp\etilqs_1HWxUeVSYTmP3Xg
  • C:\Users\test\AppData\Local\Temp\etilqs_YxKZUe9Psd9Lw4G
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\60\703A9d01
  • C:\Users\test\AppData\Local\Temp\etilqs_kbvTcEcXQDYgM9t
  • C:\Users\test\AppData\Local\Temp\etilqs_IhnIKPAL9xXVgbY
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\ED\86788d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\DC\EFF56d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PKEFVXFB87R7UKUWUA55.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF25aa1d2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\8B\E642Bd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\84\46FA4d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\sHRfRnkemptTqcH4R9AbGA==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\qoRS7uunTyPuNt5ZB_dUSQ==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\8D9XF2FiId5BiBvlVUc6Ag==.ico
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\0u9zG3TzKYoRkKqp30_ljA==.ico
  • C:\Users\test\AppData\Local\Temp\etilqs_f65XMjRotyyY4QQ
  • C:\Users\test\AppData\Local\Temp\etilqs_CFSJc4kJOzHoHgR
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\50R4BTVNFG6PI0ML6U53.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF303757c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_YICU7pXlUa1Aauo
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\D3\F2102d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L10NNXN4SZZZ10VME21T.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF31114c0.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6ZGB4ZTEEEAKWQBI2SOJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3158715.TMP
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite
  • C:\Users\test\AppData\Local\Temp\etilqs_pYdWcKVN2p3As4I
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-wal
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\webappsstore.sqlite-shm
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\chromeappsstore.sqlite
  • C:\Users\test\AppData\Local\Temp\etilqs_INBmeoMceeVGLQU
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X29DSOT7T5PX5O4EXZK6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32afa0b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1W43QQ7XON5H7V56DL01.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32ea68f.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MZXI9MHH4553RURID8DZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33323dc.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\D8\810F4d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\77\6D45Bd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\4PL8ZGRZTQASFKD7REC2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33b4904.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\30\F90DEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I2QOHOCFPUS044OMPP2I.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3437be7.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\1C\F0983d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P7C9LIR5MUQ5O4GRVWR9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF350178b.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\72\64697d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FV2CJBZE5U10F995MCVO.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3501c06.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\DF\5CE2Fd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\5\A5\CA7C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\7\5A\3AC21d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJXYW3UFTHVB71QH78AT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc546.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0LB4K8ASAGNMBSSLAEQV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc7c2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\C\3A\668D9d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\D\02\831C3d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\77\48016d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\B\B7\1409Bd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YMY1E4WNIYMOXDT6TSJF.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF363f2b2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Fcc9Qgg7Mi0FC9r
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V3Z3YLTAF3PANR0IURYV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF386c6e0.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_ajGC3wOU0npN7fW
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\95\C6493d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XJ65CERDGY2BNSTM6E3D.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF38cbb79.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_ZYLfWhWl518UW5q
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DA2WNK1F1ZHHXNSK8Q6G.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3d9558a.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\08\ECD55d01
  • C:\Users\test\AppData\Local\Temp\etilqs_hAbCb3PIBrt6Ukp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60OXF6KPFXMVEFWO5Y14.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3e90ca2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Xk0VQFPgf3BJnGQ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HKJJ5AJYK96J252W4XFU.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF41239d1.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_Bdb8ZuxBIgySW33
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9TE2WGCHC1URNV98UGBX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF44b65b1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ITUKSGAXSVU0ITCVXGUQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF45319c2.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_4m3xtu0PsILfoID
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\66A8VDB6YEP93PE75A64.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4591b0c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_cJEkIDbl0nFmP9f
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J2TK11NV9D2N9RZ683IH.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4978c11.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_YcWw91wM6psi6Qb
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D8UWJF8WHN7GANSGHLHG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4a5e15c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7CL2OHPDIQF80O4KDCCX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4aa9873.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_PoDaPdNSia6BV7S
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0ZXZTA9IEAU0S9G2YTR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4dadf06.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_MI3IE69MTTadbbf
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0F68YRR8BGDR27NQLB8B.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e271a6.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A4\54DFBd01
  • C:\Users\test\AppData\Local\Temp\etilqs_EHNKWfnMhd0Q7wq
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JW8XFYTBW6D376NK4UBX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e6f9d2.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\06\793BEd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6GO038XSF921ONW4G0I6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ef1381.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GSYVDN2UAB8GRUEMOKDV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f0e83d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3SEBECE2RAJRRZVC8O6Y.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f8dd6d.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\4\6F\9422Cd01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\1\96\E1093d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\3\C5\DE623d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YBHGOQWRD48QBUOQSQ35.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ff28a5.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\40\22B99d01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\0\77\369ABd01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RZ2ZR1NAPL7HCHAH2I2Q.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF50cc682.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_vhe6qHwFjY4QMGn
  • C:\Users\test\AppData\Local\Temp\etilqs_mukbeQpa4o69eN4
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7A73QEXS1DGRV5DNCUPI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF529d3ac.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TJDD2JYI0A429C26EAA3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF56ed8e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\58LYR752GI31SAH8FC25.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a12436.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\9\90\1C568d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\H7QYXWGRY8T08P6HFER1.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a1eb99.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\2\DC\5522Ed01
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\F\A5\8C1CCd01
  • C:\Users\test\AppData\Local\Temp\etilqs_R74e8dafqNXIU8W
  • C:\Users\test\AppData\Local\Temp\etilqs_v8tXZozQqpzEkcN
  • C:\Users\test\AppData\Local\Temp\etilqs_VbstY3df9uI0TRK
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Q6EYR2TU5EPZYGXNA6HE.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5d5ff0f.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_C6PNmCeaPjLdycO
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AUBRMRTDDUHIT2RTCAKJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5e0f855.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9A21KAJMMI3WEG3WIXYB.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF604b364.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_RKZafrImALFaT0t
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7OD7G2ERICY1K74TEQNE.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF60cc9c4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CBDEAX04YBR469H0RM8H.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF615aeeb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2HFZOM1QPNJR2KA9OMHF.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6230313.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\Cache\8\AD\57C43d01
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0YEZLPFB2VPUHMAR534S.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6277188.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\R6SPF3HD2C3M5OQXE9HI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF62be1a8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S9MGTONPRHKYJ5JCLFKR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6305405.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LBHJHKKC3QDN1PMD5XCX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF633f7df.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\358RZYS58CA45PZRR8NV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF635cfdb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\UYBQL0YBS1V1ZOFDPWJU.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF637a7bb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3WZ0QB6YLN1SV8IUDM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF639862c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HBLV5CIMAYU537PUUZCI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647afdc.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HYY9RQQSWGDEPHJL5092.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647ee22.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_XsLn5lJFfSqf5hB
  • C:\Users\test\AppData\Local\Temp\etilqs_XA7135xAcmrUepT
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KTO6C7GPDETP29RZP4EO.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF68790cc.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_seZVFxFwZ9V6zfz
  • C:\Users\test\AppData\Local\Temp\etilqs_aDJF8Vufl4yQScA
  • C:\Users\test\AppData\Local\Temp\etilqs_5fkdGg4A9dEheXU
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.js
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore-1.js
  • C:\Users\test\AppData\Local\Temp\etilqs_KJJv7AFAT5TBIxY
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W3ECITNLLDHM3D084AAS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF70f3d2a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RWCPI33ZIDS5AHTQ0HSU.temp
  • C:\Users\test\AppData\Local\Temp\etilqs_G8cVGNpOTJGqJZ8
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7146db8.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_lbJVOruSJjsUaaJ
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VZ40HVBYR4IQTPGOP73Y.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF72bc1d4.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\lxLIs2AH_AMFqw+CHXsXRQ==.ico
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6S44HT3WXPBJS50DIEHI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF731e63a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P3DXK7N701KUY31N98MA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF734af67.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T1VV0FF7ZZ38RQJO72PB.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7393729.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YSMP0EAYFSKE69DY64KL.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73b0812.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51KF0LY5BQRUPRDCRZ2B.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73cea5c.TMP
  • C:\Users\test\AppData\Local\Temp\etilqs_zV6yexR5K4gdStt
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LSERJKIRMLME5QR9CPQG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74fd138.TMP
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\jumpListCache\3HExo8vWuk4GcU3Ekdx3Pw==.ico
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2PFG6VT1J0O3OR2FSE38.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74ffb59.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SRMXVZUH3248CF226ODM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75a7aed.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I4QKHCSJON91YE9WPCRX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75c5615.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VDH59ZNHORP74Q2OT1PP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75e4b05.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YCML11WKSNR4QB6FCR2N.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7601261.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3WKBT3JZKRA8ANK72EM4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF761ea4c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FGGNIAZZYY74J6C394H7.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF763c4ad.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQ4WGIB4H90A2JEEPUYG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF765a058.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XNPVIQ8EKQ4CJDNYGK76.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76775aa.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AO4YGK1I1CKHDH6QKEXC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7694aae.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RVDA8E1II9D6S4QIDUXV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76b22f2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6CKY4SLDJ0R2GL6R9YDJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76cfe1a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HCWK44Q03BL9P61GTFVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76ed966.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GS6D4Q102M3A7PKVYCNP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF770ae52.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HI78QF66CXRH8YIBNBJQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7728329.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LFBNFE106XH942B770DC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7745d94.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\COHLNHQNC0TGAIT197CC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7763283.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\POH8MMHLSNJ0CU6LCG46.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7781ae8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IC3CT0VMJ76D9JYQE1D6.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77b4ef1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NA2N3AXOU5QSMHEZJ9W0.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77bc801.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BUIK7KR0QLFKSJTS9XVZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77dab85.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KMBQ6HK4Z648C629U9DM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77f8562.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K9QLPEJNAIZBVSVSPOG4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7815df7.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FEOFPRUB2SK48GOAQVMG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7833b0e.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\EGBD0N11Q14U4XOM0W6Q.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78512eb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3RH7NST4TTWX2U3LP1A3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF786e6e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\V92SMJWQWO3HV21AXG8R.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF788be2c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0DIWGTHQVW9YD7JOKDPT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78a9452.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AJFA2BRMNTXQOT0DZCVI.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78c7b6d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9JUZYYNBX2H0LZV06S39.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78e4942.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S5RNNWZJHPFIMAR0I3IR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7902710.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y3M1CGMOD090ET9FV3ZK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF791fa60.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9ABJP20BQQ5DQOADZQQZ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF793db7c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L8ACE7XEXMULDL6XEHPG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF795b0b0.TMP
删除的文件
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore.bak
  • C:\Users\test\AppData\Local\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\urlclassifier3.sqlite-journal
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF25aa1d2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF303757c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF31114c0.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3158715.TMP
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\permissions.sqlite-journal
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32afa0b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF32ea68f.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33323dc.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF33b4904.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3437be7.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF350178b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3501c06.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc546.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF35cc7c2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF363f2b2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF386c6e0.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF38cbb79.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3d9558a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF3e90ca2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF41239d1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF44b65b1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF45319c2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4591b0c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4978c11.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4a5e15c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4aa9873.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4dadf06.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e271a6.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4e6f9d2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ef1381.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f0e83d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4f8dd6d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF4ff28a5.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF50cc682.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF529d3ac.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF56ed8e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a12436.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5a1eb99.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5d5ff0f.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF5e0f855.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF604b364.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF60cc9c4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF615aeeb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6230313.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6277188.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF62be1a8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF6305405.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF633f7df.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF635cfdb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF637a7bb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF639862c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647afdc.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF647ee22.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF68790cc.TMP
  • C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\i072kp8z.default-1494515848972\sessionstore-1.js
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF70f3d2a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7146db8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF72bc1d4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF731e63a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF734af67.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7393729.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73b0812.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF73cea5c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74fd138.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF74ffb59.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75a7aed.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75c5615.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF75e4b05.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7601261.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF761ea4c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF763c4ad.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF765a058.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76775aa.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7694aae.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76b22f2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76cfe1a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF76ed966.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF770ae52.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7728329.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7745d94.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7763283.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7781ae8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77b4ef1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77bc801.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77dab85.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF77f8562.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7815df7.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7833b0e.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78512eb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF786e6e4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF788be2c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78a9452.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78c7b6d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF78e4942.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF7902710.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF791fa60.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF793db7c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\969252ce11249fdd.customDestinations-ms~RF795b0b0.TMP
注册表键
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\DriverVersion
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\DriverDate
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0001
  • HKEY_LOCAL_MACHINE\Software\Cisco Systems\VPN Client
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClusSvc
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\ri
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ProfileEnumMode
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ICMProfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\sRGB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\firefox.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\TaskBarIDs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\TaskBarIDs\C:\Program Files (x86)\Mozilla Firefox
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\Folder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\AllFilesystemObjects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CLASSES_ROOT\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_CLASSES_ROOT\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice
  • HKEY_CLASSES_ROOT\exefile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_JumpListItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_JumpListItems
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_TrackDocs
  • HKEY_CURRENT_USER\Software\MozillaPlugins
  • HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=3
  • HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=9
  • HKEY_LOCAL_MACHINE\Software\MozillaPlugins
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@alipay.com/NPComBrg701,version=1.0.2011.701
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader
  • HKEY_LOCAL_MACHINE\Software\JavaSoft\Java Runtime Environment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\JavaSoft\Java Runtime Environment\BrowserJavaVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\JavaSoft\Java Runtime Environment\1.8.0_121
  • HKEY_LOCAL_MACHINE\Software\mozilla.org\Mozilla
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\mozilla.org\Mozilla\CurrentVersion
  • HKEY_LOCAL_MACHINE\software\Adobe\Acrobat Reader
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\11.0\InstallPath
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\QuickTimePlayer.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe\(Default)
  • HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\Installation Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
读取的注册表键
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\DriverVersion
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\DriverDate
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\ri
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ProfileEnumMode
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ICMProfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\sRGB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\TaskBarIDs\C:\Program Files (x86)\Mozilla Firefox
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_JumpListItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_JumpListItems
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\JavaSoft\Java Runtime Environment\BrowserJavaVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\mozilla.org\Mozilla\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\Installation Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
修改的注册表键 无信息
删除的注册表键 无信息
API解析
  • setupapi.dll.SetupDiGetClassDevsW
  • setupapi.dll.SetupDiEnumDeviceInfo
  • setupapi.dll.SetupDiGetDeviceRegistryPropertyW
  • setupapi.dll.SetupDiDestroyDeviceInfoList
  • wintrust.dll.WinVerifyTrust
  • t2embed.dll.TTLoadEmbeddedFont
  • t2embed.dll.TTDeleteEmbeddedFont
  • mscms.dll.CloseColorProfile
  • mscms.dll.DeleteColorTransform
  • mscms.dll.TranslateBitmapBits
  • mscms.dll.TranslateColors
  • mscms.dll.CheckBitmapBits
  • mscms.dll.InstallColorProfileW
  • mscms.dll.UninstallColorProfileW
  • mscms.dll.EnumColorProfilesW
  • mscms.dll.GetStandardColorSpaceProfileW
  • mscms.dll.GetColorProfileHeader
  • mscms.dll.GetColorDirectoryW
  • mscms.dll.CreateProfileFromLogColorSpaceW
  • mscms.dll.CreateMultiProfileTransform
  • mscms.dll.InternalGetDeviceConfig
  • mscms.dll.WcsOpenColorProfileW
  • mscms.dll.WcsGetDefaultColorProfileSize
  • mscms.dll.WcsGetDefaultColorProfile
  • mscms.dll.WcsGetDefaultRenderingIntent
  • mscms.dll.WcsCreateIccProfile
  • mscms.dll.GetColorProfileFromHandle
  • mscms.dll.WcsGetUsePerUserProfiles
  • kernel32.dll.GetVersionExW
  • kernel32.dll.GetNativeSystemInfo
  • ole32.dll.CoInitializeEx
  • ole32.dll.CoUninitialize
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoRevokeInitializeSpy
  • msimg32.dll.AlphaBlend
  • comctl32.dll.#236
  • cryptsp.dll.CryptAcquireContextW
  • cryptsp.dll.CryptGenRandom
  • cryptsp.dll.CryptReleaseContext
  • ntdll.dll.RtlDllShutdownInProgress
  • comctl32.dll.#329
  • linkinfo.dll.IsValidLinkInfo
  • propsys.dll.#417
  • propsys.dll.PSGetNameFromPropertyKey
  • propsys.dll.PSStringFromPropertyKey
  • propsys.dll.InitVariantFromBuffer
  • oleaut32.dll.#9
  • propsys.dll.PropVariantToGUID
  • ole32.dll.PropVariantClear
  • ole32.dll.CoGetMalloc
  • propsys.dll.PSCreateMemoryPropertyStore
  • sechost.dll.ConvertSidToStringSidW
  • profapi.dll.#104
  • linkinfo.dll.CreateLinkInfoW
  • user32.dll.IsCharAlphaW
  • user32.dll.CharPrevW
  • ntshrui.dll.GetNetResourceFromLocalPathW
  • shlwapi.dll.PathRemoveFileSpecW
  • linkinfo.dll.DestroyLinkInfo
  • propsys.dll.PropVariantToBoolean
  • advapi32.dll.GetSecurityInfo
  • advapi32.dll.SetSecurityInfo
  • advapi32.dll.GetSecurityDescriptorControl
  • user32.dll.GetWindowInfo
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • gdi32.dll.GetFontAssocStatus
  • oleaut32.dll.SysAllocString
  • oleaut32.dll.SysStringLen
  • oleaut32.dll.SysFreeString
  • kernel32.dll.GlobalMemoryStatusEx
  • feclient.dll.FeClientInitialize