Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.StartPage1.59403

Added to the Dr.Web virus database: 2020-08-25

Virus description added:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following user processes:
  • firefox.exe
  • iexplore.exe
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system
Creates the following files
  • %TEMP%\local.tmp
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\jquery.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\128.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\16.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\19.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32g.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\38.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\48.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\manifest.json
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\zoomy.js
  • %TEMP%\7z.109f7e\c3\prefs.json
  • %TEMP%\7z.109f7e\qds@qds.json
  • %TEMP%\7z.109f7e\qds@qds.xpi
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.html
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\contentscript.js
  • %LOCALAPPDATA%low\wanggouzhushou\wgzs1.cfg
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\css\ext-main.css
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\jquery.js
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\128.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\16.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\19.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32g.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\38.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\48.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\manifest.json
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\zoomy.js
  • %TEMP%\7z.109f7e\s3\prefs.json
  • %TEMP%\7z.109f7e\setting.dat
  • %LOCALAPPDATA%low\quandashi\qds1.old
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\css\ext-main.css
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\contentscript.js
  • %TEMP%\7z.109f7e\bs\images\new2.png
  • %TEMP%\7z.109f7e\bs\css\ext-main.css
  • %TEMP%\7z.109f7e\bs\default-big.png
  • %TEMP%\7z.109f7e\bs\default.ico
  • %TEMP%\7z.109f7e\bs\extra\iframe.js
  • %TEMP%\7z.109f7e\bs\images\baokuan.png
  • %TEMP%\7z.109f7e\bs\images\baokuan2.png
  • %TEMP%\7z.109f7e\bs\images\huanyipi.png
  • %TEMP%\7z.109f7e\bs\images\lijian.png
  • %TEMP%\7z.109f7e\bs\images\lijian2.png
  • %TEMP%\7z.109f7e\bs\images\logotxt.png
  • %TEMP%\7z.109f7e\bs\images\lookgoods.png
  • %TEMP%\7z.109f7e\bs\images\manjian.png
  • %TEMP%\7z.109f7e\bs\images\manjian2.png
  • %TEMP%\7z.109f7e\bs\images\new.png
  • %TEMP%\7z.109f7e\bs\images\search.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.html
  • %TEMP%\7z.109f7e\bs\images\set.png
  • %TEMP%\7z.109f7e\bs\jquery.js
  • %TEMP%\7z.109f7e\bs\logos\128.png
  • %TEMP%\7z.109f7e\bs\logos\16.png
  • %TEMP%\7z.109f7e\bs\logos\19.png
  • %TEMP%\7z.109f7e\bs\logos\32.png
  • %TEMP%\7z.109f7e\bs\logos\32g.png
  • %TEMP%\7z.109f7e\bs\logos\38.png
  • %TEMP%\7z.109f7e\bs\logos\48.png
  • %TEMP%\7z.109f7e\bs\manifest.xml
  • %TEMP%\7z.109f7e\bs\popup.css
  • %TEMP%\7z.109f7e\bs\popup.html
  • %TEMP%\7z.109f7e\bs\popup.js
  • %TEMP%\7z.109f7e\bs\qds.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.js
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\manifest-000001
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\000001.dbtmp
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\manifest-000002
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\css\ext-main.css
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\extra\iframe.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan2.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\huanyipi.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian2.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\logotxt.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lookgoods.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian2.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new2.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\qds.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\search.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\set.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.html
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.css
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\manifest.json
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\jquery.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\contentscript.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.js
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\48.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\38.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32g.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\19.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\16.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\128.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.html
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.css
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\manifest.json
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\log
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\000003.log
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\css\ext-main.css
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\extra\iframe.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan2.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\huanyipi.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian2.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\logotxt.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lookgoods.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian2.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new.png
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\000002.dbtmp
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new2.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\jquery.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\search.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\set.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\128.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\16.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\19.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\38.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bs\contentscript.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\computed_hashes.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\verified_contents.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.html
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\contentscript.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\48.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.html
  • %TEMP%\7z.109f7e\bs\background.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\qds.js
  • %TEMP%\7z.109f7e\b2\prefs.json
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.html
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.css
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.html
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\logotxt.png
  • %LOCALAPPDATA%\2345explorer\user data\default\page_filev2.dat
  • %LOCALAPPDATA%\2345explorer\user data\default\page_file.dat
  • %TEMP%\fzbktcfzybd.jkd
  • %TEMP%\extra.zip
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\background.html
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\background.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bc\prefs.json
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.html
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bq\prefs.json
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bg\prefs.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\verified_contents.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\computed_hashes.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.html
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bs\background.html
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\38.png
  • %APPDATA%\opera software\opera stable\extensions\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\qds.js
Deletes the following files
  • %TEMP%\extra.zip
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bq\prefs.json
  • %TEMP%\7z.109f7e\bs\background.html
  • %TEMP%\7z.109f7e\bs\background.js
  • %TEMP%\7z.109f7e\bs\contentscript.js
  • %TEMP%\7z.109f7e\bs\css\ext-main.css
  • %TEMP%\7z.109f7e\bs\default-big.png
  • %TEMP%\7z.109f7e\bs\default.ico
  • %TEMP%\7z.109f7e\bs\extra\iframe.js
  • %TEMP%\7z.109f7e\bs\images\baokuan.png
  • %TEMP%\7z.109f7e\bs\images\baokuan2.png
  • %TEMP%\7z.109f7e\bs\images\huanyipi.png
  • %TEMP%\7z.109f7e\bs\images\lijian.png
  • %TEMP%\7z.109f7e\bs\images\lijian2.png
  • %TEMP%\7z.109f7e\bs\images\logotxt.png
  • %TEMP%\7z.109f7e\bs\images\lookgoods.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\bs\images\manjian.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.html
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bq\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\19.png
  • %TEMP%\7z.109f7e\s3\prefs.json
  • %TEMP%\7z.109f7e\bs\images\new2.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\38.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\48.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\manifest.json
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\zoomy.js
  • %TEMP%\7z.109f7e\c3\prefs.json
  • %TEMP%\7z.109f7e\qds@qds.json
  • %TEMP%\7z.109f7e\qds@qds.xpi
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.html
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.js
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\contentscript.js
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\css\ext-main.css
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\jquery.js
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\128.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\16.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\19.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32g.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\38.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\48.png
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\manifest.json
  • %TEMP%\7z.109f7e\s3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\zoomy.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32g.png
  • %TEMP%\7z.109f7e\bg\prefs.json
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\32.png
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\16.png
  • %TEMP%\7z.109f7e\bs\images\search.png
  • %TEMP%\7z.109f7e\bs\images\set.png
  • %TEMP%\7z.109f7e\bs\jquery.js
  • %TEMP%\7z.109f7e\bs\logos\128.png
  • %TEMP%\7z.109f7e\bs\logos\16.png
  • %TEMP%\7z.109f7e\bs\logos\19.png
  • %TEMP%\7z.109f7e\bs\logos\32.png
  • %TEMP%\7z.109f7e\bs\logos\32g.png
  • %TEMP%\7z.109f7e\bs\logos\38.png
  • %TEMP%\7z.109f7e\bs\logos\48.png
  • %TEMP%\7z.109f7e\bs\manifest.xml
  • %TEMP%\7z.109f7e\bs\popup.css
  • %TEMP%\7z.109f7e\bs\popup.html
  • %TEMP%\7z.109f7e\bs\popup.js
  • %TEMP%\7z.109f7e\bs\qds.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.html
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\background.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\contentscript.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\css\ext-main.css
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\jquery.js
  • %TEMP%\7z.109f7e\c3\mkmopioaanjdfgcakgcompjellfodlam\1.1.1.10_0\logos\128.png
  • %TEMP%\7z.109f7e\bs\images\manjian2.png
  • %TEMP%\7z.109f7e\bs\images\new.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\verified_contents.json
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.css
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.html
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\popup.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\qds.js
  • %TEMP%\7z.109f7e\b2\prefs.json
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.html
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\background.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\128.png
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current~rf10a337.tmp
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\manifest-000001
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\background.html
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\background.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\b2\pngdbkjbnipaepjldfjbnnegiepmhegp\1.4.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\logotxt.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lookgoods.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\new2.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\lijian.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\_metadata\computed_hashes.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\huanyipi.png
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\images\baokuan.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\search.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\set.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\jquery.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\128.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\16.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\19.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\32g.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\38.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\logos\48.png
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\manifest.json
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.css
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.html
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\popup.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\qds.js
  • %TEMP%\7z.109f7e\bc\prefs.json
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.html
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\background.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\contentscript.js
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\css\ext-main.css
  • %TEMP%\7z.109f7e\bg\nebcijjbphjmagedbbbjbkfoccjpapil\1.0.1.7_0\extra\iframe.js
  • %TEMP%\7z.109f7e\bc\nebcijjbphjmagedbbbjbkfoccjpapil\1.2.1.7_0\images\manjian2.png
  • %TEMP%\7z.109f7e\setting.dat
Moves the following files
  • from %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\000001.dbtmp to %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current
  • from %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\000002.dbtmp to %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current
  • from %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current to %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current~rf10a337.tmp
Substitutes the following files
  • %LOCALAPPDATA%\google\chrome\user data\default\local extension settings\nebcijjbphjmagedbbbjbkfoccjpapil\current
Network activity
TCP
HTTP GET requests
  • http://gz.##pkdy.net/2.gif?dv####################################################################################################################################################################...
  • http://gz.##pkdy.net/qxz/xbsd.htm?dv#################################################################################################################################################
  • http://gz.##pkdy.net/qxz/dqcnm.htm?dv#####################################################################################################################################################
  • http://gz.##pkdy.net/l17.gif?dv##################################################################################################################################################################...
  • http://gz.##pkdy.net/l13.gif?dv##################################################################################################################################################################...
  • http://cs#.#ipkdy.net/kz20/bd/07324170800202/FZBKTCFZYBD.jkd
  • http://gz.##pkdy.net/l10.gif?dv##################################################################################################################################################################...
  • http://gz.##pkdy.net/7.gif?dv####################################################################################################################################################################...
UDP
  • DNS ASK gz.##pkdy.net
  • DNS ASK cs#.#ipkdy.net

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android