Technical Information
- %WINDIR%\Tasks\globalUpdateUpdateTaskMachineCore.job
- %WINDIR%\Tasks\globalUpdateUpdateTaskMachineUA.job
- %WINDIR%\Tasks\8c608567-314e-47b0-87c1-ac0da490fcc4-3.job
- %WINDIR%\Tasks\8c608567-314e-47b0-87c1-ac0da490fcc4-4.job
- [<HKLM>\SYSTEM\ControlSet001\Services\globalUpdate] 'Start' = '00000002'
- '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regsvc
- '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regserver
- '%PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-4.exe' /fsZIB /bNWhh='S10' /IwuoagBT='%PROGRAM_FILES%\S10\48924.xpi' /fpfLXLm=48924 /yLaSnZ='000841' /WmmVBML='0' /bQgWYRvA='0' /UGYTdg=6FF1EAAF14AD42368CF307B5D8C607D9IE /wYLoQfK=7a33dadb447f6c9d6bee38d8b6eaa523 /zQsPtaEu=1_34_05_29 /IvVrpyZu=1.34.5.29 /tBlrO=1422874441 /iliKNLLXX=http://st###.#atademoserv.com /JQBAGNOE=http://er####.datademoserv.com /lKMjExrwj=300 /pxdmEx=52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com /mSDqfP=0.94 /acBzg=a52c8b690b0a84d679ecc566aaa231f646a33300ba82b47a5a6c34064823d6e72com48924 /EWkUCl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/48924.rdf /ftaBR='S10' /sHcghVcLe='We give superior shopping experience by giving you the best offers instantly!' /QrqIW='smart-saverplus' /LhJNy=ie /EwyWCiAJj='{"asw":[0, 0]}' /ELOhKhi /PNbwa /FRnQcX /QGxSgPsyl='http://up####.datademoserv.com/ff_agent_updates/{CAMP_ID}/update.json' /ENHaV /xojRySStB='installer' /oxdikpMgT='%TEMP%\S10Installer_1422874441.log'
- '%TEMP%\comh.80328\GoogleUpdate.exe' /silent /install "appguid={d66b35db-b2e5-42f7-ad02-bccf77bd0c7e}&appname=11615833-cca6-4099-bc44-02be53d1dac0&needsadmin=True&lang=en"
- '%PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-3.exe' /ItIdMv=uh3v9wr/Fzp00i4Gf3F1fwna7VYUGO8BCY0FE/5q9pGOcWQT0+3NTDpTjhfrajgzjeeDn2Cc8+4Po3ghU8Un1daxBOa6WR1b4/s4vFKe63NQQoW2I8SprDfpY1nV5PXUDLTRajBxJuxhesk4zupl+TUUQ529cCUG0QEEVyjHnVl4wUh6bJDhasKq8msnQUI0ViTy16K5g8kfc081BQHc2hXQwKstKMqWId6B2B/uJCQ3m8ERGlKyrGeXAb7RCn5lMYOCIGvWlhY+DndXV5aWyXTmY5zmGcMgDC2GbwAf2Nf4px5iKsV4IZt/nGAAgnEd7KzA0chFuIWFaNBpY+7q0U+52aqHhu4WN+nvE8E78feHZSP0P/TPE7ozvZrS0vAJYsashYsAqm9XnlU6NjfpJMl6R0xWGfTc/feC1XcGo2813NAm++HzKcUY2pPGhGcP0BRn0Qqmgvaj64pU/pzGD11GAkovOxVsYNQF7OvCYmi3+36XoN6R6PAuvVs0G6P0bvDuKNLWd1v5hvjGLdbhoXiD/Rixap9TuEpJSAlFVJpQoAh0I78JseIJmtQYgMWmHZ74eIpoNl4/bFuVW5ajMPdAd2TevX7nYQqensepeKX1xDR9DWPJ2O7xnKKtvp4q9zHzxRB3HGw0RTYRDX4y9sipzE7vkWqeeJQaWe52GPYzqkVF5yXpLzHsF3X/22eFJSx//mD8090bLcfHPi9eitp8U6pazSHNHtbOkVW5e9oydKSoMKPk2ia+jJrgOVXkIit5oRlpJHyUAeNM89QNFr0hSbVVqSPk7EAno6510Q/Db9bRhIF92TEPc7z9/XaU2GzfWOgvUgE3m/s6AI/1zz501CiOhP/RjNv5+1NurdFIShQJiSvylXXG5KnqLSaO6wQWXx8dOi9PGFZ4I1NuYT4W7NlL6FEULL/5pyQSqLfuJxIxsg9AxWVPaNkgP8nJ/7QeMsYI/BF55qokpqbmDgMxHizWOAwkPt/AVWitkOmPYWrMZunqjobSM0j/BooYE/rKAiNAlNjZYmdDpRKUdaQInI/5oQfEPyjdtMcd3fM2zGpBlCpfW+x+GW58xbu4gMfPuUPZVcKPpu1eiT9eHfQe2mK3qH4sqyvrCYQvi49s5V2yUVDbZm5DJtm0dAEiS0IweKgiaX8lAGUQzHJXtMIlgEtPV8PN+N3nI9aIdoE=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\msiexec.exe' /V
- opera.exe
- firefox.exe
- iexplore.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\baaf5940b56ce61f5956d9680f812004.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\e1316b6811082821ae7408c074518395.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\3b5d467953500afc6ab8c9c540ec10c1.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\de45bfa3c5b6bb74069043e8c3526bfe.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\b726f40f42fb2c1033a86ce05cf1f75d.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\d50e30c0e00bd2bc85fc59d466a7c96e.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\93dd92e65cc3256258a3d9c30641cd16.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\d1c42de98bf6b14945101f9ef90752d8.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\7bc77a81b1829a0662c375d725e7f75a.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\14b09c62a7531fd91de97ab43e76e21a.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\60b3f0577112b6f23ab7fb1be417f0a3.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\installer.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\304e2e29ea3cec7e5a978e0ce591e74c.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\a1f2b816d922500a8be72981f152dd62.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\2188548bd024743e351653a92fb83ef4.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\a89b30cb4f29022bb202cb1dc67304cb.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\38e043d61c4529c197490fce4ef09d0b.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\ae1334576d327d8986f949e9e09dc6f0.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\abca4ae61834427906030ce8996dc57d.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\207.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\98.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\background.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\extension.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\13.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\78.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\102.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\47.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\17.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\463fd26ae90fbf4e728a56c12568986c.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\763828c9e15c6bcba8ddfbb224c4a260.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\browser.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\a953b9f2750b5b9b2b19f6dc4b14c53c.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\background.html
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\dialog.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\search_dialog.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\ffCoreFilesIndex.txt
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\skin.css
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button5.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button3.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon24.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button2.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon48.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\6f884672ca0a420cde0805546894f798.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\update.css
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\popup.html
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button1.png
- %WINDIR%\Installer\3e139.msi
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
- C:\Config.Msi\3e13c.rbs
- %WINDIR%\Installer\MSIA.tmp
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button4.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\panelarrow-up.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon16.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\crossrider_statusbar.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon128.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\a530f2027518f5bf0a4ed49941a442c2.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\028bb427a9f48055fea1d13abcc27318.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\cf89f61db319cb5556997c850cc9d6e9.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\aa9f35c0cada0228c0840babbd6fde7e.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\695149570b3e493b984df085339cb24b.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\5183119dd1f6984bd5437674ae815870.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\098a4e7666842686969d740d81f8d269.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\e42cf254b6b545993cb88732521a1222.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\8cdcc3a8a439e6d15f67406bf02a72d6.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\630435cabe836a12300704ea9619ed6d.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\8bbb1b9a5be2a7e8b934f675da39d0d1.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\260759030a63a1e632629d9191dcf1c0.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\049ce0b9d966e2896955a6e773fb6804.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\2cb864184cde2774c95d51b4637a40bd.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\27a84092223531d6799ae95edb851737.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\300e384d56d470c22f3d8f928f045d69.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\34b1e0c04e296a0c2c91daed58266807.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\d7abf41f42786c5502f720178744855a.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\df25fbc6abea9e6bc6b291d5b546ac90.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\72.js
- %PROGRAM_FILES%\S10\48924.crx
- %TEMP%\comh.80328\psuser.dll
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdate.dll
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
- %TEMP%\comh.80328\psmachine.dll
- %TEMP%\comh.80328\goopdate.dll
- %TEMP%\comh.80328\GoogleUpdateOnDemand.exe
- %TEMP%\comh.80328\npGoogleUpdate4.dll
- %TEMP%\comh.80328\goopdateres_en.dll
- %PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-3.exe
- %TEMP%\Cab4.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
- %PROGRAM_FILES%\S10\360-48924.crx
- %PROGRAM_FILES%\S10\1293297481.mxaddon
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
- %TEMP%\nsr3.tmp\md5dll.dll
- %TEMP%\nsr3.tmp\nsisos.dll
- %TEMP%\nsr3.tmp\inetc.dll
- %TEMP%\nsr3.tmp\UserInfo.dll
- %TEMP%\nsr3.tmp\InstallerUtils2.dll
- %TEMP%\nsr3.tmp\StdUtils.dll
- %TEMP%\nsw2.tmp
- %TEMP%\nsr3.tmp\InstallerUtils.dll
- %TEMP%\nsr3.tmp\System.dll
- %TEMP%\nsr3.tmp\update.json
- %TEMP%\comh.80328\GoogleUpdate.exe
- %TEMP%\comh.80328\GoogleCrashHandler.exe
- %TEMP%\comh.80328\GoogleUpdateHelper.msi
- %TEMP%\comh.80328\GoogleUpdateBroker.exe
- %PROGRAM_FILES%\S10\Uninstall.exe
- %PROGRAM_FILES%\S10\utils.exe
- %TEMP%\nsr3.tmp\24924
- %TEMP%\nsr3.tmp\58931
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\93.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\268.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\91.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\16.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\28.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins.json
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome.manifest
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\183.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\manifest.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\4.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\22.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\177.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\64.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\246.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\14.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\1.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\21.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\104.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\182.js
- %TEMP%\Cab8.tmp
- %TEMP%\Cab6.tmp
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA
- %PROGRAM_FILES%\S10\48924.xpi
- %PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-4.exe
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psuser.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\install.rdf
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\defaults\preferences\prefs.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\locale\en-US\translations.dtd
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
- %TEMP%\nsr3.tmp\ExecDos.dll
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psmachine.dll
- %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
- %PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe
- %WINDIR%\Installer\3e139.msi
- C:\Config.Msi\3e13c.rbs
- %WINDIR%\Installer\3e13b.ipi
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %WINDIR%\Installer\MSIA.tmp
- %TEMP%\Cab4.tmp
- %TEMP%\nsr3.tmp\24924
- %TEMP%\Cab6.tmp
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
- %TEMP%\Cab8.tmp
- 'cr#.#hawte.com':80
- 'www.download.windowsupdate.com':80
- '97#####88.r.cdn77.net':80
- 'ts####.ws.symantec.com':80
- 'er####.datademoserv.com':80
- 'up####.datademoserv.com':80
- 'lo##.##tademoserv.com':80
- 'st###.#atademoserv.com':80
- cr#.#hawte.com/ThawteTimestampingCA.crl
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- ts####.ws.symantec.com/tss-ca-g2.crl
- er####.datademoserv.com/ch-agent-error.gif?ac#######################################################################################################################################################################################################################################################################################################################################################################################################################################
- 97#####88.r.cdn77.net/000841/update.json?rn####
- er####.datademoserv.com/installer-error.gif?ac#######################################################################################################################################################################################################################################################################################################################################################################################################
- up####.datademoserv.com/installer_updates/000841/update.json
- st###.#atademoserv.com/installer.gif?ac###################################################################################################################################################################################################################################################################################################################################################################################################################################
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- lo##.##tademoserv.com/monetization.gif?ev##############################################################################################################################################################################################################################################################################################################################################################
- DNS ASK cr#.#hawte.com
- DNS ASK www.download.windowsupdate.com
- DNS ASK 97#####88.r.cdn77.net
- DNS ASK ts####.ws.symantec.com
- DNS ASK er####.datademoserv.com
- DNS ASK up####.datademoserv.com
- DNS ASK lo##.##tademoserv.com
- DNS ASK st###.#atademoserv.com
- ClassName: 'Shell_TrayWnd' WindowName: ''