Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Crossrider.29052

Added to the Dr.Web virus database: 2014-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %WINDIR%\Tasks\127e8e48-1660-471b-b756-cf68ad790db2-4.job
  • %WINDIR%\Tasks\127e8e48-1660-471b-b756-cf68ad790db2-3.job
  • %WINDIR%\Tasks\127e8e48-1660-471b-b756-cf68ad790db2-11.job
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\globalUpdate] 'Start' = '00000002'
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regserver
  • '%PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-4.exe' /installxpi /agentregpath='Information' /extensionfilepath='%PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2.xpi' /appid=50368 /srcid='000972' /subid='0' /zdata='0' /bic=CEC736DE04DE435DA2CE33B6E76F48E7IE /verifier=ca8fb8478f9fa9e6127d265c4a6dd18d /installerversion=1_34_08_12 /installerfullversion=1.34.8.12 /installationtime=1408667783 /statsdomain=http://st###.##putdatacloud.com /errorsdomain=http://er####.#nputdatacloud.com /waitforbrowser=300 /extensionid=ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com /extensionversion=0.95 /prefsbranch=ace85a36c113a4928aa8688a31bd595e7aa144f8ac1f6481f991c18bf0472c970com50368 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/50368.rdf /extensionname='Information' /extensiondesc='Information Helper' /publishername='VisualBee' /defbro=ie /sid=S-1-5-21-2052111302-484763869-725345543-1003 /addinfojson='{"asw":[0, 0, 0],"browser_name":"__BROWSER_NAME__"}' /allusers /allprofiles /checkfflist /autoupdateulr='http://up####.#nputdatacloud.com/ff_agent_updates/{CAMP_ID}/update.json' /showthankyoupage /runfrom='installer' /externallog='%TEMP%\InformationInstaller_1408667783.log'
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /handoff "appguid={396c4c99-88d9-400a-80ed-abc196317a08}&appname=09c77474-482c-4364-8c30-382a9afb2466&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{4826D4B8-C827-4DB0-B5D1-6735B24F17E6}" /silent
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins0ODI2RDRCOC1DODI3LTREQjAtQjVEMS02NzM1QjI0RjE3RTZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHRlc3Rzb3VyY2U9ImF1dG8iIHJlcXVlc3RpZD0iezhFQjMzMUM5LTY5N0MtNDlDNS05QjUwLUU2ODEyNkZERUU4Rn0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI1LjEiIHNwPSJTZXJ2aWNlIFBhY2sgMiIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4yNS4wIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-
  • '%PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-3.exe' /rawdata=j2o3pOzJ3KpfwCzkGIqqhnOMdKm1Urs1R/dyVvWtkx44jwFc0+ZPkLaiqYRrQMwfJlC6jwNEsznyJYdNpmBMeJ5kK8KQIZRy/mei7//jBPlzUfScZK6/eBoT1FWVBAm6e0kDuU1i2oeKYu0CtScy137kI8G/DHyM+RqAykJvBKO+Kh2Fulqqfl2nRathPOmcjD/GK2a9EFKjPDLdBLvS4YAfBkjBi35hngm7rypWgTwOnBtS+DDojCgpRuiIS+rooN2EGqTKukCBh8rJowEJtz18Xw1adxs9tGJLmFLqETQiVdt3Vu8fxTGm+bHvfIS/qpLVVU+zTlX5k8eGIuCM02ZbRlGxG0ShjFarRsc1+35O5JV6LsY6AUfTyav8BK9SZM/0Xo+rmGBhkzH5c/Epv+2qyYpQGMIyo0dgiKhdNMckHRkPxjm1uZ8zFGYQdPbB7OBSnzhw/nFbNw+0v92YkqXyIh1C3m6pFIoafD5a+vOX2HFZDBGGWRGe+VYlgXvwO8H1mCtAKPhIOFoKv4RfLn3rBG1mzQ4zdOlHfdhlydeZkQpverOxeVTvk9tQGc06kI5NyvaX3p8De/e40dztKN8X4rNPvdrlZNkGdEoqY+d19GGK9xTrjnOPU5aecDljbJFoPo33wbnSwOEcIt/8hKH2aW+Gm+It/CwTwMX94AhKuQM1O4io0VMWuW8Gn2kfpGIKjGC/ECqyY4s4sIjJTxiJqeCUw154wL0UIQu2mqC7aL21huvM2xu0i5wqNi8MlHNBfOnQM2sgXLLw3ofWUD7ETc/PyQCFy+gNjjTZLZdlx3WjfvzD8cJqF6KPhywFuwKh/ZgyZYhCtxMsbzEXO2Uy0m4Iwh2JSz83fIr+bPWI6iWnbWznC1e+dZJkp8qZBISyUBqdm7sFEI1TnVRZzPWQEHmB9pDPCzoKgxtEvjqhFvRtDC7dGVIdLtZOUiZ+JTAtpVoDChfYq9ztiEY8D03RNSZmBIr5sEuA0JFo+LIioxm+ktwhQxsTx90HVFTaJmDWx0N4X0KVJ999FDjZtjF3mZNvK0N4kfeWcdwQ/5AKcgwOh2NJLEhY0f48lrZH2SH1fqtmOXi2fqHj7zcE00YM70QKamYBWc0y5mj3GDGBkn/1+232UukvdzC8QOV9mw6UDQginKESTsGOBUlYwtHmwdteDlpTADdjwGrFSWIO4NATIBnx3ZnmdHq50QPeq83Xuhx2apDfPepfnfaCwfv4uH6DGshcZo5blIuc0dX/xgoH3res1g32OQAQ2BlFRFyZhOpsaaIz/2w6Qllfh4R6sHlAPqNPdT7pIZX5OAgxvwwpMNG2HuGZPaX/AcfuiCJGMlpbgZnkx0MAqgLgmEMHyNhETdJKldFqBLKj5dJxpGIqZS1Atj8ORcDZrS36xx2g/js7kn1WDstfo/H2roZiGorJWcJxY4mCE+H8fi4PuulTiYGRKUc4Lbrp1X4I86K4/FpnwT33/6VBFMs6yoNMFRyp3wt5KCW2t2JDydhLUZSoloFclIIhmo8l/VTYAQBusCI/uxv49P4L8eN9ZcZXApI6CgQAnIfOi1P3W0dFGJc7qkCe2EEsK/IgIBinQmLWl2IQP8ADx0Js+elbgMzClLjV+8o2KaPf+evO+7LtAog7iu7zUPGnUdGG1sZv0Byd08sHg4HTgGSxJO/xKjWR94uc9MrtHB3XJE5wLjU=
  • '%TEMP%\comh.232093\GoogleUpdate.exe' /silent /install "appguid={396c4c99-88d9-400a-80ed-abc196317a08}&appname=09c77474-482c-4364-8c30-382a9afb2466&needsadmin=True&lang=en"
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regsvc
  • '%PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-11.exe' /rawdata=TSe78+KHQyZTpph3Q2wrFNXSZPZjs/oRiWsvCBBLgbYn7KEvI/O70mCzdrxvd+v/ObZcM/YrBFe+sPodybYEkfl+qCc2JM7TaCHT3FWELqWpNA6VZvVAWYD5B0vWhv9080Dn/+K7Mauprx7tCCC1sZvdFu7pywgYgIpVldRoDwWQ8g4JpSYSG7EZZPcLnCLOfO5WNbmMMDmxTkDDBO/lg1yO4fVLVz3mkYAb4D3GYylJSzlJ5RzZYYIxmZNanKQsxnU+OZmmZBz0O6K/K92duGC3jj2JSNKJ83nvlqzu3D/wQpygNtkKHr+Kx53YvTF9NngaA4uOh22P282Q18cY9kCpVDibVoefX1P1P5FYocBbRmJdx74J2lcURA0U2hejaYDUiHKxNuIRohDA/90RXumXRt+bs9DvIdQoQfH9Cposu4JR5Qw3+4tb6G9qTb5lYXBDxs9+hZtals2/trqywnryzBHqOVrTu+2ojuP2dC/yo3y2ZZpgZWbhn3IeICq0HsiETeEOnlSciQo4K6uNwAKUd7slicXO7UkvfsLAYKkCIgI3PHdbzeY4voennUyODuALv7xVwqLGqHO43v1hnn2qcAQwUMlZ2GcDgRfL5eAtha1EjSebmARAs9QroIXfIYU5/1serodqIuN02A6ZV4Nsc9o3IzhCxL42rPw//x6SjBTW3o3d7TzaDDz3pY5T1XQV53cgEZHPNL/36hwZcHESq0XtJZd/nTS5WkzU469JFjF+pxhzdPlN4bihDKXzvwD2opGKhpjzr5LHDIDXSsR+rJkayrKpQHOQGooE+yu5OhzSXCRZPKLAKq2Ukyhl5yOVqjDaaqcjMkGltkx5WJFkEBoefbhnRB1xe2xFLW6sDh41E7rpHnNd+yFmH/21TnLuJxnNGDl4IkT8OjbYp71RRfpV7dh0tbC1JEAtxJybEP2it/DtEhWJXQOnx6c8uC2mSAAPosWaHUR/D2Wja636QQpLE7pX1P/uOC3Oy8dElz0VW/J/frRvTelCbT6Eff8bpfk+FsQAmbd5Viz09d6Bh7vp86/6QpIYRQuWhilyTEtBD5iCMo3Qm+sdfJCOR/aUo3NwpSZW3nt2/vd4xCJIbgm0XCmKm26kVHg7exI5/wjDEJJgT+ta0e3P1D7Cw6Z9EGC52YVH4gUYFG0Ferz7h/hR2Iss5kkWD9sF7L4uEnyUUVgJeGFLRUVFEQ8beIw4WcUube1YkuTm0IAABMR+GvEZmG1hNMbhiVpzDGpa1UYsyTZthrlqZYi9eUI19NGcGGLhLgCmnStHx6HclQfasxxrdAvCsY2bTIRh7mskSJGhuGDyb5BjTN8CiEWjuaAHqmnBgH12Ad1R5H8igqHxhkr1SbqnYBQQ8ZBX/KO6qOa3oQUjXNh68ORI7mc+HtH/sJQYca77PvwXB5/EZ+VfFhT0cJOvs2igS2NtQgKVhxY9BaI1CQ9sqwDu3SrbepGIlWsAsf5VLNuUdvKWlDrPtIUaLlTzNrzW/JHxX8cekdA39jznkrZlcRVpupH7HvoGS+t/6oc+nUnvZTbwzplqA/urUmTpFywwoiyLMdxCqr/yxr1erRhabi5lgfV9sQwiQ9xuLDGfzttcvOaZVWQBvW3HNKZAlqexXuCGa3+0/F2hs2duPZGq8RiLPkGNkajBbWgSFJIXpmwjMZHSVVF4E2v64uGipxKX+kR6rOsLAHZUgKmg91MvWbCT96Cd3p5pyLR9m4KGWTaQK3yRo0d4DmGqHnB+GJqcsEivRjORmKJhkJW6p69ENvLi83Br9KyG3d6JJof5sXsjjSnemfMtfH/NmEIBzB9MG0SILE9h9R1hRxBDbxTQLa+II+pOMhqTH/XnvksI6FbgF/SKVMaVP7RNE31g/0m/41ay30+SNt10eYpZnd9CsHpnISLO9BUZoK23YGd8rM0ZSxvSLNCd4XYl7JLkk+E0KeT9aqURbKr+o++x6ADdP1YRN7jwn+I+teeVRApPT4RF7M4wIRAzPEjd+f6E99N+rbkNryDso9TatCiBwvSFDnf1N1T3
Executes the following:
  • '<SYSTEM32>\msiexec.exe' /V
Terminates or attempts to terminate
the following user processes:
  • chrome.exe
  • opera.exe
  • iexplore.exe
  • firefox.exe
Modifies file system :
Creates the following files:
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\background.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\554c97b904407377e7457d4f8a812907.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\ffCoreFilesIndex.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\83293f92657b7de38f411a57e329e7f0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\search_dialog.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\options.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\68a1bf024fd71b57a884f22e05782e2a.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\b85b8412262999a7adb17503204bc6ff.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\a69e8b3bf83a086507cb80fd9311b012.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\dialog.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\b72ef4a1bab1c09360a641f39282c5fb.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\b51f19920553c029bf62d91459d90bd7.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\732da867fe8daa67e5e4bc22a2a323b6.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\9dd7f77644143efb9fba5e1dbbdde7a4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\376f76c70cb3f8372f97b5e72d50a4a3.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\8be2f0b4d269c16f6ca5fd76c90d968f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\browser.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\options.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\1d12607e10f264ccabc616154cac6457.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\8a1ac5816ac3e600cbbaa39fa7e37d39.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\65fe777c6a7917fdab14a6f6e404a164.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\userCode\background.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\246.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\291.js
  • C:\Config.Msi\45d90.rbs
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\220.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\262.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\233.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\14.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\263.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\289.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\260.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\64.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\17.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\78.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\47.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\userCode\extension.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\13.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\184.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\223.js
  • %TEMP%\MSI482e8.LOG
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\102.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\193.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\4485bab81e747fb36c08531c72df0fd5.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\icon48.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\f27862bb4f0370301798fda42fe8756d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\popup.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\button2.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\update.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\d4f41b003a649cc061f5b7f46a68bed4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\11b96732539dae36895613297ee7a238.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\5e76521cf79a6e977405325052de319e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\e6e42cd01e9e453a130a5467220c10b1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\fe693e629ecd466ade340d1a565e5752.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\button5.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\icon128.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\panelarrow-up.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\crossrider_statusbar.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\button4.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\icon24.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\skin.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\button3.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\icon16.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\skin\button1.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\36d15f0fcdcedf115be1a351c1a829ea.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\f23415c18e8001af561674c44c038ebc.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\installer.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\f1a9df967901f23249075801920091e0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\87e65c1d3c936932d421b3d7d2032495.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\bfbd78c16fd622247073462ea6381432.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\3aef15c799c31238b89333939c4a05ec.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\3837918db11af7b86b9be21fe3e715d7.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\1e0a24c6f29bad934605c1dcb6e8f507.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\d6f1b5696850e2919db32b59f6c5604a.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\d1676f0f52e894a9dddea8bb42834cd9.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\d67da80d9313170390099e973161e717.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\c98702dd9d318887ef0a549f3829d1cc.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\3d22a559a7424660298c01f13af3828d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\c051d2f90fb609eb8fc606b77c0faae5.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\e2796ba614d3fe06586df125e880ca3c.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\55aae10525f96db1c8e44d8df54b78fa.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\bd82376012aa63f94ba0553de10b0cc4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\core\fc561459957b5729fdca736a05eb5e5f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\e8139f55ff0ad2af5b69142e5a5ca195.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\76a760622b5671c9362187450d4d469d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome\content\api\28268e6e3f54a0a25e5729d6d3d10311.js
  • %WINDIR%\Installer\MSIA.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
  • %PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-3.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
  • %TEMP%\comh.232093\psuser.dll
  • %TEMP%\comh.232093\psmachine.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %PROGRAM_FILES%\Information\d9ee7eb4-90f9-4c58-b916-628f4d73b1a2.crx
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %TEMP%\Cab4.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA
  • %PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2.crx
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA
  • %TEMP%\Cab6.tmp
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB
  • %TEMP%\nsp3.tmp\ExecDos.dll
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB
  • %PROGRAM_FILES%\Information\7bc1d1c1-c72f-4846-a615-975622ee8e0a.crx
  • %PROGRAM_FILES%\Information\1293297481.mxaddon
  • %TEMP%\comh.232093\npGoogleUpdate4.dll
  • %TEMP%\nsp3.tmp\nsisos.dll
  • %TEMP%\nsp3.tmp\UserInfo.dll
  • %TEMP%\nsp3.tmp\md5dll.dll
  • %TEMP%\nsp3.tmp\update.json
  • %TEMP%\nsp3.tmp\inetc.dll
  • %TEMP%\nsp3.tmp\StdUtils.dll
  • %TEMP%\nso2.tmp
  • %TEMP%\nsp3.tmp\System.dll
  • %TEMP%\nsp3.tmp\InstallerUtils2.dll
  • %TEMP%\nsp3.tmp\InstallerUtils.dll
  • %PROGRAM_FILES%\Information\utils.exe
  • %TEMP%\comh.232093\GoogleUpdateHelper.msi
  • %TEMP%\comh.232093\GoogleUpdateBroker.exe
  • %TEMP%\comh.232093\GoogleUpdateOnDemand.exe
  • %TEMP%\comh.232093\goopdateres_en.dll
  • %TEMP%\comh.232093\goopdate.dll
  • %TEMP%\nsp3.tmp\416094
  • %TEMP%\nsp3.tmp\135892
  • %PROGRAM_FILES%\Information\Uninstall.exe
  • %TEMP%\comh.232093\GoogleUpdate.exe
  • %TEMP%\comh.232093\GoogleCrashHandler.exe
  • %PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-11.exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\286.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\244.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\221.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\93.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\230.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\192.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\273.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\301.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\211.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\296.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\16.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\5.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\7.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\300.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\104.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\9.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\242.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\91.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\281.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\32.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\226.js
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2.xpi
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %TEMP%\Cab8.tmp
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %PROGRAM_FILES%\Information\127e8e48-1660-471b-b756-cf68ad790db2-4.exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\manifest.xml
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins.json
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\180.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\275.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\extensionData\plugins\268.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\install.rdf
  • %WINDIR%\Installer\45d8d.msi
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\locale\en-US\translations.dtd
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\chrome.manifest
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com\defaults\preferences\prefs.js
Deletes the following files:
  • C:\Config.Msi\45d90.rbs
  • %WINDIR%\Installer\MSIA.tmp
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • %WINDIR%\Installer\45d8d.msi
  • %TEMP%\Cab4.tmp
  • %TEMP%\nsp3.tmp\416094
  • %TEMP%\Cab8.tmp
  • %TEMP%\Cab6.tmp
Network activity:
Connects to:
  • 'www.download.windowsupdate.com':80
  • 'cr#.#hawte.com':80
  • 'ts####.ws.symantec.com':80
  • 'lo##.##putdatacloud.com':80
  • 'up####.#nputdatacloud.com':80
  • 'er####.#nputdatacloud.com':80
  • 'st###.##putdatacloud.com':80
TCP:
HTTP GET requests:
  • cr#.#hawte.com/ThawteTimestampingCA.crl
  • ts####.ws.symantec.com/tss-ca-g2.crl
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • up####.#nputdatacloud.com/installer_updates/000972/update.json
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
UDP:
  • DNS ASK www.download.windowsupdate.com
  • DNS ASK cr#.#hawte.com
  • DNS ASK ts####.ws.symantec.com
  • DNS ASK lo##.##putdatacloud.com
  • DNS ASK up####.#nputdatacloud.com
  • DNS ASK er####.#nputdatacloud.com
  • DNS ASK st###.##putdatacloud.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android