Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Crossrider.37215

Добавлен в вирусную базу Dr.Web: 2014-10-28

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %WINDIR%\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-10_user.job
  • <SYSTEM32>\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-10_user
  • %WINDIR%\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3.job
  • <SYSTEM32>\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3
  • %WINDIR%\tasks\globalupdateupdatetaskmachinecore.job
  • <SYSTEM32>\tasks\globalupdateupdatetaskmachinecore
  • %WINDIR%\tasks\globalupdateupdatetaskmachineua.job
  • <SYSTEM32>\tasks\globalupdateupdatetaskmachineua
  • %WINDIR%\tasks\gdwizhf.job
  • <SYSTEM32>\tasks\gdwizhf
  • %WINDIR%\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11.job
  • <SYSTEM32>\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11
  • %WINDIR%\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.job
  • <SYSTEM32>\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7
  • %WINDIR%\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-6.job
  • <SYSTEM32>\tasks\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-6
Sets the following service settings
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdate] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdate] 'ImagePath' = '%ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /svc'
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdatem] 'ImagePath' = '%ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /medsvc'
Creates the following services
  • 'globalUpdate' %ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /svc
  • 'globalUpdatem' %ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /medsvc
Malicious functions
Terminates or attempts to terminate
the following user processes:
  • firefox.exe
Modifies file system
Creates the following files
  • %TEMP%\nsb5c24.tmp
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\19.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\195.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\119.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\7.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\345.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\234.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\391.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\9.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\4.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\281.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\242.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\390.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\91.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\93.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\231.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\background.html
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\14.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\264.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\184.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\223.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\178.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\64.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\97.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\220.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\262.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\246.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\334.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\375.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\289.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\380.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\260.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\263.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\221.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\376.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\123.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\200.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\354.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\783e780fb401d9bc1448a1eef31cfa5f.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\ac5d657affcd7b10ab6bdc0363a781a0.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\03cef3b46445db8ad0046153b35c1946.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\1f97070505532bfd9b5073f60b38b192.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\pageaction.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\e9141739282468247d5ae36bf4158f43.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\a5aaab5bebbd7f2e3d352e99775ce3c7.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\ad79f1cbb18cf027bd3517a30b679f79.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\popup.html
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\f337681bc44d5bdb215081a49674ee43.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2dc54a308ad518a5a1fcd54be4c889d5.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\f09593e1fece838b7e90f88c7e7a4047.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\5fe6d5d02327ed49e23b47caee54b9fe.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\74c0b35d2fd697960159cb89d81caf00.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\23403fb9b92eb91b08d5fdb1cb7e6052.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\80.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\252.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\chromecorefilesindex.txt
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\actions\1.png
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\eeb4cbcd1fb19bbdf0ac6f02f4a5525e.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\179.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\389.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\253.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\385.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\273.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\335.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\180.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\339.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\232.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\manifest.xml
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins.json
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\manifest.json
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon128.png
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon16.png
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon48.png
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\180.js
  • %ProgramFiles(x86)%\97355f6d-768b-4a86-9715-1c4ce7c5b77b\fbf3d3ce-6f5a-4111-a65b-b2cf630ffedb.dll
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\78.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\380.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\376.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\375.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\357.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\354.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\349.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\388.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\385.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\339.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\335.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\334.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\289.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\288.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\281.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\348.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\288.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\389.js
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\2ffd41bf-17b0-4afa-a152-763ae30ba2a8.dll
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-64.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.exe
  • %CommonProgramFiles(x86)%\2a7d1de6-4082-4fcb-a8e7-010fbb1fe317.dll
  • %ProgramFiles(x86)%\97355f6d-768b-4a86-9715-1c4ce7c5b77b\458c7941-000b-419f-9533-7b9abf248706.dll
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\97f4599f-55e5-4d0b-b45d-f14abeca7279.dll
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-6.exe
  • %TEMP%\nsr5c83.tmp\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.dll
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\usercode\extension.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\usercode\background.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\93.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\91.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\78.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\4.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\391.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\280.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\345.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\277.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\273.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\264.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\settings.json
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\123.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\102.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins.json
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\manifest.xml
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\bgnova.html
  • %TEMP%\nsr5c83.tmp\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11.dll
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\usercode\background.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\178.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\usercode\extension.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\13.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\356.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\47.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\17.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\388.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\102.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2f4d720ceab84085c7be81aacee87663.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\179.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\200.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\14.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\263.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\262.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\260.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\253.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\252.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\251.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\250.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\249.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\246.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\242.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\234.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\232.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\231.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\223.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\184.js
  • %TEMP%\nsr5c83.tmp\{ac13ed6f-218e-4377-b0b3-439963a4dd0a}\plugins\390.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\installer.js
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdatebroker.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\1f97070505532bfd9b5073f60b38b192.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\pageaction.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\e9141739282468247d5ae36bf4158f43.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\a5aaab5bebbd7f2e3d352e99775ce3c7.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\783e780fb401d9bc1448a1eef31cfa5f.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\ad79f1cbb18cf027bd3517a30b679f79.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\ac5d657affcd7b10ab6bdc0363a781a0.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\api\03cef3b46445db8ad0046153b35c1946.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\f09593e1fece838b7e90f88c7e7a4047.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\5fe6d5d02327ed49e23b47caee54b9fe.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\74c0b35d2fd697960159cb89d81caf00.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\23403fb9b92eb91b08d5fdb1cb7e6052.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2f4d720ceab84085c7be81aacee87663.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\installer.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\f337681bc44d5bdb215081a49674ee43.js
  • %TEMP%\comh.368480\googleupdateondemand.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\eeb4cbcd1fb19bbdf0ac6f02f4a5525e.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\385.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\273.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\335.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\180.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\339.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\232.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\manifest.xml
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\manifest.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon128.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon16.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\actions\1.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\icons\icon48.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\background.html
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\chromecorefilesindex.txt
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\b594f308fc626254d58f8878f2dcf4ff.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2dc54a308ad518a5a1fcd54be4c889d5.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\79e9509ccd9759a1c828deb32b03eb52.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2a20a2c81dc7e9ae51ea31bfd6f05549.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\app_api.js
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\utils.exe
  • %TEMP%\comh.368480\googlecrashhandler.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-10.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\uninstallbrw.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\uninstall.exe
  • %TEMP%\nsr5c83.tmp\126931
  • %TEMP%\nsr5c83.tmp\6048
  • %TEMP%\nsr5c83.tmp\md5dll.dll
  • %TEMP%\comh.368480\googleupdatebroker.exe
  • %TEMP%\nsr5c83.tmp\nsisos.dll
  • %TEMP%\nsr5c83.tmp\userinfo.dll
  • %TEMP%\nsr5c83.tmp\installerutils2.dll
  • %TEMP%\nsr5c83.tmp\installerutils.dll
  • %TEMP%\nsr5c83.tmp\system.dll
  • %TEMP%\nsr5c83.tmp\stdutils.dll
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\253.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\popup.html
  • %TEMP%\comh.368480\googleupdatehelper.msi
  • %TEMP%\comh.368480\goopdateres_en.dll
  • %TEMP%\comh.368480\googleupdate.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2434f2eb0cd959228ba54ce921cf5d66.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\55f0b0206c32b46ff9b4be996adf764b.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\popupresource\newpopup.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\popupresource\popup.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\0eb63bdc72314e397e82a015fcbe5d89.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\main.js
  • %TEMP%\nsr5c83.tmp\execdos.dll
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\97f4599f-55e5-4d0b-b45d-f14abeca7279.crx
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\goopdate.dll
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdate.exe
  • %TEMP%\comh.368480\psuser.dll
  • %TEMP%\comh.368480\psmachine.dll
  • %TEMP%\comh.368480\npgoogleupdate4.dll
  • %TEMP%\comh.368480\goopdate.dll
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\9.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\79e9509ccd9759a1c828deb32b03eb52.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\354.js
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\psuser.dll
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdatehelper.msi
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\goopdateres_en.dll
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googlecrashhandler.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\settings.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\usercode\background.js
  • %ProgramFiles(x86)%\globalupdate\update\googleupdate.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\psmachine.dll
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\356.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\47.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\17.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\388.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\78.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\102.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\usercode\extension.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\389.js
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\npgoogleupdate4.dll
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2a20a2c81dc7e9ae51ea31bfd6f05549.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\app_api.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\2434f2eb0cd959228ba54ce921cf5d66.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\55f0b0206c32b46ff9b4be996adf764b.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\popupresource\newpopup.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\popupresource\popup.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\0eb63bdc72314e397e82a015fcbe5d89.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\main.js
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11.exe
  • %ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b.crx
  • %APPDATA%\gdwizhf
  • %APPDATA%\gdwizhf.exe
  • %TEMP%\nsr5c83.tmp\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3.dll
  • %TEMP%\msi13745.log
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdateondemand.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\288.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\13.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\80.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\264.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\184.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\281.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\7.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\345.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\234.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\231.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\376.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\4.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\242.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\195.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\390.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\91.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\93.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\221.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\123.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\200.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\179.js
  • %APPDATA%\opera software\opera stable\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\js\lib\b594f308fc626254d58f8878f2dcf4ff.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\19.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\14.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\119.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\223.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\178.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\64.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\97.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\220.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\262.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\246.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\334.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\375.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\289.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\380.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\260.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\263.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\252.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pifjcfjeiidipakpjmebopadnfpnmpjg\1.26.22_0\extensiondata\plugins\391.js
  • %CommonProgramFiles(x86)%\97355f6d-768b-4a86-9715-1c4ce7c5b77b.dll
Deletes the following files
  • %TEMP%\nsr5c83.tmp\126931
  • %APPDATA%\microsoft\windows\cookies\user@ourstatsstaticstack[2].txt
  • %APPDATA%\microsoft\windows\cookies\user@ourstatsstaticstack[1].txt
Substitutes the following files
  • %TEMP%\nsr5c83.tmp\126931
  • %LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies-journal
  • %APPDATA%\Opera Software\Opera Stable\Cookies-journal
Network activity
TCP
HTTP GET requests
  • http://er####.##rstatsstaticstack.com/utility.gif?re##########################################################################
  • http://er####.##rstatsstaticstack.com/utility.gif?re#################################################################################
  • http://up####.##rstatsstaticstack.com/omaha/D950E245-BDB8-451E-B9C5-9F6F17DA8B02/1/ping.xml?ra#######
  • http://lo##.####tatsstaticstack.com/monetization.gif?ra##########################################################################################################################################...
  • http://er####.##rstatsstaticstack.com/ch-agent-error.gif?ac######################################################################################################################################...
  • http://up####.##rstatsstaticstack.com/omaha/D950E245-BDB8-451E-B9C5-9F6F17DA8B02/1/update.xml?ra#######
  • http://up####.##rstatsstaticstack.com/omaha/D950E245-BDB8-451E-B9C5-9F6F17DA8B02/1/update.xml?ra#################################################################################################...
  • http://up####.##rstatsstaticstack.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?ra#######
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
  • http://js.#####atsstaticstack.com/plugin/apps/72891/manifest/1_36_01_22/nova/manifest.xml?ve#############
  • http://er####.##rstatsstaticstack.com/utility.gif?re###############################################################################
  • http://er####.##rstatsstaticstack.com/utility.gif?re#########################################################################################
  • http://er####.##rstatsstaticstack.com/utility.gif?re#####################################################################################
  • http://er####.##rstatsstaticstack.com/utility.gif?re############################################################################
  • http://er####.##rstatsstaticstack.com/utility.gif?re########################################################################
  • http://lo##.####tatsstaticstack.com/monetization.gif?ev##########################################################################################################################################...
  • http://er####.##rstatsstaticstack.com/installer-error.gif?ac#####################################################################################################################################...
  • http://st###.###statsstaticstack.com/installer.gif?ac############################################################################################################################################...
  • http://ip###api.com/
  • http://er####.##rstatsstaticstack.com/utility.gif?re##################################################################################
  • http://js.####ntdemocloud.com/plugin/apps/72891/manifest/1_36_01_22/nova/manifest.xml?ve#############
  • 'go###eapis.com':443
  • UDP
    • DNS ASK er####.##rstatsstaticstack.com
    • DNS ASK ip###api.com
    • DNS ASK st###.###statsstaticstack.com
    • DNS ASK lo##.####tatsstaticstack.com
    • DNS ASK go###eapis.com
    • DNS ASK microsoft.com
    • DNS ASK up####.##rstatsstaticstack.com
    • DNS ASK js.#####atsstaticstack.com
    • DNS ASK js.####ntdemocloud.com
    Miscellaneous
    Creates and executes the following
    • '%TEMP%\comh.368480\googleupdate.exe' /silent /install "appguid={d950e245-bdb8-451e-b9c5-9f6f17da8b02}&appname=807c78fe-4b96-43f7-9fb4-75907433d05c&needsadmin=True&lang=en"
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3.exe' /rawdata=vG1rZ4a0P6KlqIKluMitOgYe821BQcIBIRmKKMvQ/K9Ug+Co6JlYnYj7XJlSg+tkAurS0p5RfxPAoi4XrmZGgEXQsFJBXjppEHycMRLPaKAG+58DYtDdRBEEunvvbUkVv+wq8ssDsA6Fvs837zSXBD9DXxZTqfNe3EAIyjUn+Go7CfgzrPbkCFEF...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /regsvc
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /regserver
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins4OURDQTZBNC1GQURBLTQ0MTItQkQ3MS05Mzc4MjI3QTh...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /handoff "appguid={d950e245-bdb8-451e-b9c5-9f6f17da8b02}&appname=807c78fe-4b96-43f7-9fb4-75907433d05c&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{89DCA6A4-FADA-4412-BD7...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /svc
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11.exe' /rawdata=sgjTV7YEZ9RgTu4uDjnj4/w+9/LUIIgnaMo7srkBeR3001tVUveLmceHO5dwIWpucXPHjyssNMNzX5fxbPUBpYbMXtZjRJNS7yTnvqU2sM3Vi1gESH2Ah09vGzvKuq18gu4KbYGVuqXkBD/ZBwX+mrg9L4vwpa6bzlyIRz1XTgcUPjtOqf4F8g7x...
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.exe' /rawdata=mnmzqgBMzE8tV81BaiqPT/pmcqOSHV3GOorfvHgjnXk/fj0CkBWXks/YAwwb5oQiqwb//4+6SpaedWB4b5HAPY+KvTXcek5jCCWLkM2zgmEPqcjHPCK1YMY1+jsZYNOxoLtjcRXK8o0gks0874e7+ALD5KGdbhoICqdfL82LJPtjQmGcfdv7N+tH...
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.exe' /rawdata=IQVnuk+Sedas9RRI9II/0MjbI8CDfcjMFdJ8cLAeUaYH8jcodqg+7stqoZWb5QrEgV1gQq5qGSDdz707bKh+rp94UNwa2ob7RMyKI3eaDmkLi2Wc/Z5WGrNjSEFNsjQySAY4VgdnxThRQXhzX60PkFF2zoF3/spyw0ypV/eG2D9pg81EK8rUXn1B...
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-6.exe' /rawdata=rcl4QXLoAii6m5Rq9w+hEb2Tosb2/QSS0KSsBO/iFBBHWiYcSU2SAvlmvedyBnuGhNCo1PZVvvPzeRLPlHEjQnTwVYQWOn/ufqMISDu1OV8J5Dewnz+ljYj3F45Rmm3Gitvhhh/yKK/hsKDX0IwRMi6f/pfPrkzy2jmM6jby3GO39TY8Il/FXVYl...
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-3.exe' /rawdata=vG1rZ4a0P6KlqIKluMitOgYe821BQcIBIRmKKMvQ/K9Ug+Co6JlYnYj7XJlSg+tkAurS0p5RfxPAoi4XrmZGgEXQsFJBXjppEHycMRLPaKAG+58DYtDdRBEEunvvbUkVv+wq8ssDsA6Fvs837zSXBD9DXxZTqfNe3EAIyjUn+Go7CfgzrPbkCFEF...' (with hidden window)
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-11.exe' /rawdata=sgjTV7YEZ9RgTu4uDjnj4/w+9/LUIIgnaMo7srkBeR3001tVUveLmceHO5dwIWpucXPHjyssNMNzX5fxbPUBpYbMXtZjRJNS7yTnvqU2sM3Vi1gESH2Ah09vGzvKuq18gu4KbYGVuqXkBD/ZBwX+mrg9L4vwpa6bzlyIRz1XTgcUPjtOqf4F8g7x...' (with hidden window)
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.exe' /rawdata=mnmzqgBMzE8tV81BaiqPT/pmcqOSHV3GOorfvHgjnXk/fj0CkBWXks/YAwwb5oQiqwb//4+6SpaedWB4b5HAPY+KvTXcek5jCCWLkM2zgmEPqcjHPCK1YMY1+jsZYNOxoLtjcRXK8o0gks0874e7+ALD5KGdbhoICqdfL82LJPtjQmGcfdv7N+tH...' (with hidden window)
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-7.exe' /rawdata=IQVnuk+Sedas9RRI9II/0MjbI8CDfcjMFdJ8cLAeUaYH8jcodqg+7stqoZWb5QrEgV1gQq5qGSDdz707bKh+rp94UNwa2ob7RMyKI3eaDmkLi2Wc/Z5WGrNjSEFNsjQySAY4VgdnxThRQXhzX60PkFF2zoF3/spyw0ypV/eG2D9pg81EK8rUXn1B...' (with hidden window)
    • '%ProgramFiles(x86)%\plushd cinema 2.1cv24.03\c318a774-e6c6-4ffb-a1a5-b8b61bdb665b-6.exe' /rawdata=rcl4QXLoAii6m5Rq9w+hEb2Tosb2/QSS0KSsBO/iFBBHWiYcSU2SAvlmvedyBnuGhNCo1PZVvvPzeRLPlHEjQnTwVYQWOn/ufqMISDu1OV8J5Dewnz+ljYj3F45Rmm3Gitvhhh/yKK/hsKDX0IwRMi6f/pfPrkzy2jmM6jby3GO39TY8Il/FXVYl...' (with hidden window)

    Рекомендации по лечению

    1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
    2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
    Скачать Dr.Web

    По серийному номеру

    Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

    На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

    Скачать Dr.Web

    По серийному номеру

    1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
    2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
      • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
      • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
      • выключите устройство и включите его в обычном режиме.

    Подробнее о Dr.Web для Android

    Демо бесплатно на 14 дней

    Выдаётся при установке