czfwabef.exe

Firefox

WALISON BARBOSA 04293554165

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PluginContains’.
Publisher:
Mozilla Corporation  (signed by WALISON BARBOSA 04293554165)

Product:
Firefox

Version:
51.0.1

MD5:
5813d104170ffa3cc1d5e4c90f2d7a96

SHA-1:
e13aff3c28fdeb493ec04ebbecf000f3cae7fbf5

SHA-256:
aacfdf799fe29c6bd5ff5fdafd8f1e2187f550bec938ea2d5060ffb0d8d89e9a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/19/2025 3:28:54 PM UTC  (today)

File size:
10.1 MB (10,545,128 bytes)

Product version:
51.0.1

Copyright:
©Firefox and Mozilla Developers; available under the MPL 2 license.

Trademarks:
Firefox is a Trademark of The Mozilla Foundation.

Original file name:
firefox.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\czfwabef.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/12/2017 10:00:00 PM

Valid to:
1/13/2018 9:59:59 PM

Subject:
CN=WALISON BARBOSA 04293554165, O=WALISON BARBOSA 04293554165, STREET=AV ANHANGUERA 7840 LOJA 119, L=GOIANIA, S=GOIAS, PostalCode=74.503-100, C=BR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
753BAB040D3646BC92680D068B9C896D

File PE Metadata
Compilation timestamp:
2/23/2017 8:04:25 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA47A5

Entry point:
9C, 54, 54, C7, 44, 24, 08, CF, 09, 15, FF, 9C, 60, E8, 86, 2C, 9F, 00, 9C, 66, 89, 0C, 24, 46, E9, 76, EF, 00, 00, 69, D2, 0A, 00, 00, 00, E8, 6E, 39, 00, 00, F5, 11, D2, 55, F9, 9C, 8D, 6C, 24, 04, 66, 0F, BA, E3, 08, 89, 04, 24, 66, C1, EA, 09, F7, D2, 30, C6, 66, 0F, B6, D3, 51, 66, 0F, AC, DA, 06, 80, D2, 2F, 53, 0F, C0, F1, F6, DA, 68, 97, 06, FC, 2E, 89, 3C, 24, FE, C2, 0F, BA, F9, 1E, 56, 66, 0F, A3, E4, 66, D3, EE, C1, F1, 14, 8B, 55, 08, 0F, B3, D6, 66, F7, D1, F9, 8B, 75, 0C, F6, D1, 39, D7, 66...
 
[+]

Code size:
2.1 MB (2,177,024 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PluginContains

Command:
C:\users\{user}\appdata\local\temp\czfwabef.exe


Scan czfwabef.exe - Powered by Reason Core Security