Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBC899BF-B931-5B99-5352-D0637A5FECCF}]
- %TEMP%\17b72d01\sgyrsi.dat
- C:\users\administrator\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- <LS_APPDATA>\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- %PROGRAMDATA%\safewaeb\sgyrsi.dat
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- %PROGRAMDATA%\safewaeb\sgyrsi.exe
- <LS_APPDATA>\packages\windows_ie_ac_001\ac\{fbc899bf-b931-5b99-5352-d0637a5feccf}\safewaeb.2.7.dat
- %ProgramFiles(x86)%\safewaeb\xrchw.x64.dll
- <LS_APPDATA>low\{fbc899bf-b931-5b99-5352-d0637a5feccf}\safewaeb.2.7.dat
- %ProgramFiles(x86)%\safewaeb\xrchw.dat
- %ProgramFiles(x86)%\safewaeb\xrchw.tlb
- %ProgramFiles(x86)%\safewaeb\xrchw.dll
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\cokgtnz@yaufvr.net\install.rdf
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\cokgtnz@yaufvr.net\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\cokgtnz@yaufvr.net\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\cokgtnz@yaufvr.net\bootstrap.js
- <LS_APPDATA>\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- <LS_APPDATA>\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- <LS_APPDATA>\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- <LS_APPDATA>\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\h6d4yhb.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\background.html
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\manifest.json
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\content.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\lsdb.js
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\bootstrap.js
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\chrome.manifest
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\install.rdf
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\content\bg.js
- %TEMP%\17b72d01\xrchw.dll
- %TEMP%\17b72d01\xrchw.tlb
- %TEMP%\17b72d01\xrchw.x64.dll
- %TEMP%\17b72d01\sgyrsi.exe
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- <LS_APPDATA>\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- <LS_APPDATA>\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\lsdb.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\h6d4yhb.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\dlgmikigbkefnilkgolikhdjjlnielod\1.1\content.js
- %PROGRAMDATA%\640713a7f2b4df0a\{497c131e-2032-051b-b32a-c69a960fbb13}
- %TEMP%\17b72d01\sgyrsi.dat
- %TEMP%\17b72d01\sgyrsi.exe
- %TEMP%\17b72d01\xrchw.x64.dll
- %TEMP%\17b72d01\xrchw.tlb
- %TEMP%\17b72d01\xrchw.dll
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\content\bg.js
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\install.rdf
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\chrome.manifest
- %TEMP%\17b72d01\cokgtnz@yaufvr.net\bootstrap.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\lsdb.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\content.js
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\manifest.json
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\background.html
- %TEMP%\17b72d01\dlgmikigbkefnilkgolikhdjjlnielod\h6d4yhb.js
- '%TEMP%\17b72d01\sgyrsi.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\safewaeb\XRchw.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\safewaeb\XRchw.x64.dll"