Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SystemHelper' = '<SYSTEM32>\syshelper.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsHelper' = '%WINDIR%\sysrtlcw.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SystemDriver' = '%APPDATA%\Sysmrdv\sysmrdv.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SystemSettings' = '%APPDATA%\sysmrdv.exe'
- %APPDATA%\microsoft\word\startup\update.exe
- <Drive name for removable media>:\update.exe
- hidden files
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\41\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\40\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\4\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\39\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\37\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\36\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\35\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\34\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\33\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\32\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\31\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\14\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\3\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\28\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\27\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\25\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\24\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\23\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\21\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\20\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\2\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\19\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\18\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\17\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\16\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\29\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\15\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\43\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\59\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\60\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\61\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\62\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\7\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\8\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\host\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\cache2\doomed\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\muffin\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\security\update.exe
- %LOCALAPPDATA%low\sun\java\jre1.8.0_45_x64\update.exe
- %APPDATA%\update.exe
- %APPDATA%\identities\update.exe
- %APPDATA%\identities\{1bba5dcd-58f3-46ae-861d-68cf42722c36}\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\45\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\57\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\56\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\54\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\53\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\52\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\51\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\50\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\5\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\49\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\46\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\6\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\13\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\12\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\11\update.exe
- %TEMP%\hsperfdata_user\update.exe
- %TEMP%\update.exe
- %LOCALAPPDATA%\programs\common\update.exe
- %LOCALAPPDATA%\programs\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\q0evdndb.default\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\thumbnails\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\startupcache\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\safebrowsing\google4\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\safebrowsing\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\offlinecache\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\cache2\entries\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\cache2\doomed\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\cache2\update.exe
- %TEMP%\microsoft .net framework 4 setup_4.0.30319\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\update.exe
- %LOCALAPPDATA%\mozilla\firefox\update.exe
- %LOCALAPPDATA%\mozilla\update.exe
- %LOCALAPPDATA%\microsoft help\update.exe
- %LOCALAPPDATA%\microsoft\windows sidebar\gadgets\update.exe
- %LOCALAPPDATA%\microsoft\windows sidebar\update.exe
- %LOCALAPPDATA%\microsoft\windows media\12.0\update.exe
- %LOCALAPPDATA%\microsoft\windows media\update.exe
- %LOCALAPPDATA%\microsoft\windows mail\stationery\update.exe
- %LOCALAPPDATA%\microsoft\windows mail\backup\new\update.exe
- %LOCALAPPDATA%\microsoft\windows mail\backup\update.exe
- %LOCALAPPDATA%\microsoft\windows mail\update.exe
- %LOCALAPPDATA%\microsoft\windows\update.exe
- %LOCALAPPDATA%\microsoft\office\groove\user\update.exe
- %LOCALAPPDATA%\microsoft\office\groove\system\update.exe
- %LOCALAPPDATA%\mozilla\firefox\profiles\update.exe
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_10.0.30319\update.exe
- %TEMP%\low\update.exe
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_10.0.30319\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\update.exe
- %LOCALAPPDATA%low\microsoft\internet explorer\services\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\1\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\0\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\update.exe
- %LOCALAPPDATA%low\sun\java\update.exe
- %LOCALAPPDATA%low\sun\update.exe
- %LOCALAPPDATA%low\oracle\java\au\update.exe
- %LOCALAPPDATA%low\oracle\java\update.exe
- %LOCALAPPDATA%low\oracle\update.exe
- %LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\update.exe
- %LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\update.exe
- %LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\update.exe
- %LOCALAPPDATA%low\mozilla\update.exe
- %LOCALAPPDATA%low\microsoft\internet explorer\update.exe
- %TEMP%\opera installer\update.exe
- %LOCALAPPDATA%low\microsoft\update.exe
- %LOCALAPPDATA%low\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\startupcache\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\safebrowsing\google4\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\safebrowsing\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\cache2\entries\update.exe
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\9\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\cache2\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\rehh7ft5.default-release\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\dm02c46v.default\update.exe
- %LOCALAPPDATA%\thunderbird\profiles\update.exe
- %LOCALAPPDATA%\thunderbird\update.exe
- %LOCALAPPDATA%\<INETFILES>\update.exe
- %TEMP%\wpdnse\update.exe
- %APPDATA%\media center programs\update.exe
- %APPDATA%\microsoft\update.exe
- %APPDATA%\microsoft\addins\update.exe
- %APPDATA%\microsoft\credentials\update.exe
- %HOMEPATH%\saved games\update.exe
- %HOMEPATH%\recent\update.exe
- %HOMEPATH%\printhood\update.exe
- %HOMEPATH%\nethood\update.exe
- %HOMEPATH%\links\update.exe
- %HOMEPATH%\favorites\windows live\update.exe
- %HOMEPATH%\favorites\msn websites\update.exe
- %HOMEPATH%\favorites\microsoft websites\update.exe
- %HOMEPATH%\favorites\links for united states\update.exe
- %HOMEPATH%\favorites\links\update.exe
- %HOMEPATH%\favorites\update.exe
- %HOMEPATH%\downloads\update.exe
- %HOMEPATH%\documents\my videos\update.exe
- %HOMEPATH%\documents\my pictures\update.exe
- %HOMEPATH%\searches\update.exe
- %HOMEPATH%\documents\my music\update.exe
- %HOMEPATH%\cookies\update.exe
- %HOMEPATH%\contacts\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\idb\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\default\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\saved-telemetry-pings\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\minidumps\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\extensions\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\datareporting\archived\2024-08\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\datareporting\archived\update.exe
- %HOMEPATH%\documents\update.exe
- %HOMEPATH%\sendto\update.exe
- %HOMEPATH%\start menu\update.exe
- %HOMEPATH%\templates\update.exe
- %TEMP%\is-9slmt.tmp\tmp1964.tmp
- %TEMP%\is-enhbb.tmp\_isetup\_setup64.tmp
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\directories.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\windows_info.txt
- %TEMP%\web data
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_web data
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_history
- %LOCALAPPDATA%\microsoft\office\groove\update.exe
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_history.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\filegrabber\adhd_and_obesity.docx
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\filegrabber\hadac_newsletter_july_2010_final.docx
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}.zip
- %TEMP%\is-enhbb.tmp\is-4gfas.tmp
- %TEMP%\is-enhbb.tmp\is-cijpr.tmp
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\system_info.txt
- %APPDATA%\sysmrdv.exe
- %TEMP%\tmp3322.exe
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\software_info.txt
- %TEMP%\is-bv78k.tmp\_isetup\_setup64.tmp
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\screenshot.jpg
- %TEMP%\tmp9419.exe
- %TEMP%\is-40egf.tmp\tmp1964.tmp
- %TEMP%\tmp5598.exe
- %TEMP%\tmp1964.exe
- %APPDATA%\sysmrdv\sysmrdv.exe
- %WINDIR%\sysrtlcw.exe
- %TEMP%\tmp4270.exe
- <SYSTEM32>\syshelper.exe
- %TEMP%\tmp9244.exe
- D:\update.exe
- C:\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\datareporting\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\crashes\events\update.exe
- %APPDATA%\mozilla\systemextensionsdev\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\update.exe
- %APPDATA%\mozilla\firefox\profiles\update.exe
- %APPDATA%\mozilla\firefox\pending pings\update.exe
- %APPDATA%\mozilla\firefox\crash reports\events\update.exe
- %APPDATA%\mozilla\firefox\crash reports\update.exe
- %APPDATA%\mozilla\firefox\update.exe
- %APPDATA%\mozilla\extensions\update.exe
- %APPDATA%\mozilla\update.exe
- %APPDATA%\microsoft\word\update.exe
- %APPDATA%\microsoft\windows\update.exe
- %APPDATA%\microsoft\uproof\update.exe
- %APPDATA%\microsoft\templates\update.exe
- %APPDATA%\microsoft\systemcertificates\my\ctls\update.exe
- %APPDATA%\microsoft\systemcertificates\my\crls\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\bookmarkbackups\update.exe
- %APPDATA%\microsoft\systemcertificates\my\certificates\update.exe
- %APPDATA%\microsoft\systemcertificates\update.exe
- %APPDATA%\microsoft\protect\s-1-5-21-3691498038-2086406363-2140527554-1000\update.exe
- %APPDATA%\microsoft\protect\update.exe
- %APPDATA%\microsoft\proof\update.exe
- %APPDATA%\microsoft\office\recent\update.exe
- %APPDATA%\microsoft\office\update.exe
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\update.exe
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\implicitappshortcuts\update.exe
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\update.exe
- %APPDATA%\microsoft\internet explorer\quick launch\update.exe
- %APPDATA%\microsoft\internet explorer\update.exe
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3691498038-2086406363-2140527554-1000\update.exe
- %APPDATA%\microsoft\crypto\rsa\update.exe
- %APPDATA%\microsoft\crypto\update.exe
- %APPDATA%\microsoft\systemcertificates\my\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\crashes\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\crashes\events\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\datareporting\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\update.exe
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\update.exe
- %APPDATA%\telegram desktop\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\update.exe
- %APPDATA%\thunderbird\update.exe
- %APPDATA%\thunderbird\crash reports\update.exe
- %APPDATA%\thunderbird\crash reports\events\update.exe
- %APPDATA%\thunderbird\pending pings\update.exe
- %APPDATA%\thunderbird\profiles\update.exe
- %APPDATA%\thunderbird\profiles\dm02c46v.default\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\moz-extension+++d6b3ddfc-c8d2-4cb7-a730-29f01af6f4b1^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.fil...
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\moz-extension+++d6b3ddfc-c8d2-4cb7-a730-29f01af6f4b1^usercontextid=4294967295\idb\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\moz-extension+++d6b3ddfc-c8d2-4cb7-a730-29f01af6f4b1^usercontextid=4294967295\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\update.exe
- %APPDATA%\apphostinterface_1\apphostinterface_1.drv
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\sessionstore-backups\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\security_state\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\saved-telemetry-pings\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\minidumps\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\datareporting\archived\2024-08\update.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\datareporting\archived\update.exe
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\crashes\update.exe
- %TEMP%\history
- %LOCALAPPDATA%\microsoft\office\update.exe
- %LOCALAPPDATA%\microsoft\feeds cache\9lygctr1\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_br\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\no\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\nl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ko\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ja\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\it\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\id\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\he\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\vi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\es\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\en\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\el\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\de\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\da\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\cs\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ca\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\bg\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ar\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_tw\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fil\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_cn\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_pt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ca\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\da\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\de\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\el\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\en\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\es\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\fi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\fr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fil\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\he\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\hi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\hr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\hu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\id\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\it\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ru\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ro\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\bg\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ar\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_tw\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_cn\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\vi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\uk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\tr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\th\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\cs\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\uk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\tr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\th\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\bg\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ar\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\__macosx\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extension state\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extension rules\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\databases\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cache\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\cs\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\update.exe
- %LOCALAPPDATA%\google\chrome\user data\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\visualelements\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\pepperflash\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\locales\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\installer\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\extensions\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\update.exe
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\update.exe
- %LOCALAPPDATA%\google\chrome\application\update.exe
- %LOCALAPPDATA%\google\chrome\update.exe
- %LOCALAPPDATA%\google\update.exe
- %LOCALAPPDATA%\update.exe
- %HOMEPATH%\appdata\update.exe
- %HOMEPATH%\update.exe
- %LOCALAPPDATA%\google\chrome\user data\caps\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\da\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ca\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\de\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ja\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ru\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ro\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_pt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_br\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\no\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\nl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ms\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ko\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\it\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\el\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\id\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\he\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\fil\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\eu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\et\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es_419\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_us\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_gb\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ja\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ko\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\lt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\lv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\th\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ru\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ro\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_pt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_br\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\no\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\tr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ko\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\it\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\da\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\cs\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\uk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\vi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_cn\update.exe
- %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\update.exe
- %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\update.exe
- %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\update.exe
- %LOCALAPPDATA%\microsoft\feeds cache\update.exe
- %LOCALAPPDATA%\microsoft\feeds cache\09emkjp8\update.exe
- %LOCALAPPDATA%\microsoft\feeds cache\17h8i54k\update.exe
- %LOCALAPPDATA%\microsoft\feeds cache\aowdc71i\update.exe
- %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0000b8ef\update.exe
- %LOCALAPPDATA%\microsoft\internet explorer\update.exe
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\update.exe
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\update.exe
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\active\update.exe
- %LOCALAPPDATA%\microsoft\media player\update.exe
- %LOCALAPPDATA%\microsoft\media player\sync playlists\update.exe
- %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\update.exe
- %LOCALAPPDATA%\microsoft\feeds\update.exe
- %LOCALAPPDATA%\microsoft\credentials\update.exe
- %LOCALAPPDATA%\microsoft\update.exe
- %LOCALAPPDATA%\history\update.exe
- %LOCALAPPDATA%\google\chrome\user data\widevinecdm\update.exe
- %LOCALAPPDATA%\google\chrome\user data\swiftshader\update.exe
- %LOCALAPPDATA%\google\chrome\user data\pnacl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\pepperflash\update.exe
- %LOCALAPPDATA%\google\chrome\user data\evwhitelist\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\session storage\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\jumplisticonsold\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\gpucache\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\__macosx\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\__macosx\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_tw\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ca\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\it\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\bg\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\th\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_us\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_gb\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\el\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\de\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\da\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\cs\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ca\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\bg\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ar\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\zh_tw\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\zh_cn\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\uk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\tr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\th\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\sv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\sr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\sl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\sk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ru\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\ro\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\pt_pt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\pt_br\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\pl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\no\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\nl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\__macosx\_locales\vi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es_419\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\et\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ro\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ru\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\tr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\uk\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\vi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_cn\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_tw\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_pt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_br\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\no\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\nl\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lv\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lt\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ko\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ja\update.exe
- %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\id\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hu\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hi\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\he\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fr\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fil\update.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ar\update.exe
- %APPDATA%\screenshot.jpg
- <SYSTEM32>\syshelper.exe
- %WINDIR%\sysrtlcw.exe
- %APPDATA%\sysmrdv\sysmrdv.exe
- %APPDATA%\sysmrdv.exe
- %TEMP%\is-bv78k.tmp\_isetup\_setup64.tmp
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\system_info.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\software_info.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\screenshot.jpg
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\filegrabber\hadac_newsletter_july_2010_final.docx
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\filegrabber\adhd_and_obesity.docx
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\directories.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\windows_info.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_web data
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_history
- %TEMP%\is-9slmt.tmp\tmp1964.tmp
- %TEMP%\is-enhbb.tmp\_isetup\_setup64.tmp
- %TEMP%\is-enhbb.tmp\apphostinterface_1.drv.7z
- %TEMP%\is-enhbb.tmp\7z.exe
- %TEMP%\is-40egf.tmp\tmp1964.tmp
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}\browsers\chrome_history.txt
- %ALLUSERSPROFILE%\{846ee340-7039-11de-9d20-806e6f6e6963}.zip
- from %TEMP%\is-enhbb.tmp\is-4gfas.tmp to %TEMP%\is-enhbb.tmp\7z.exe
- from %TEMP%\is-enhbb.tmp\is-cijpr.tmp to %TEMP%\is-enhbb.tmp\apphostinterface_1.drv.7z
- 'di###trix.world':80
- '62.##.226.191':80
- http://18#.#56.72.8/1.exe
- http://18#.#56.72.8/2.exe
- http://18#.#56.72.8/3.exe
- http://18#.#56.72.8/4.exe
- http://di###trix.world/1.exe
- http://62.##.226.191/1.exe
- http://18#.#56.72.8/zpaxpjz/get.php
- DNS ASK di###trix.world
- '%TEMP%\tmp9244.exe'
- '%TEMP%\tmp4270.exe'
- '<SYSTEM32>\syshelper.exe'
- '%TEMP%\tmp1964.exe' -silent
- '%TEMP%\is-40egf.tmp\tmp1964.tmp' /SL5="$A024C,1967372,813056,%TEMP%\tmp1964.exe" -silent
- '%TEMP%\tmp5598.exe'
- '%TEMP%\tmp9419.exe'
- '%TEMP%\tmp1964.exe' /VERYSILENT
- '%TEMP%\is-9slmt.tmp\tmp1964.tmp' /SL5="$8018C,1967372,813056,%TEMP%\tmp1964.exe" /VERYSILENT
- '%TEMP%\is-enhbb.tmp\7z.exe' x "%TEMP%\is-ENHBB.tmp\AppHostInterface_1.drv.7z" -o"%APPDATA%\AppHostInterface_1" -pmkyOzOvxg7yXsjAH44noXr5HpVjXs94S -y
- '%WINDIR%\syswow64\regsvr32.exe' /s /i:svc "%APPDATA%\AppHostInterface_1\\AppHostInterface_1.drv"
- '<SYSTEM32>\regsvr32.exe' /s /i:svc "%APPDATA%\AppHostInterface_1\\AppHostInterface_1.drv"
- '%TEMP%\tmp4270.exe' ' (with hidden window)
- '%TEMP%\tmp1964.exe' -silent' (with hidden window)
- '%TEMP%\tmp5598.exe' ' (with hidden window)
- '%TEMP%\tmp9419.exe' ' (with hidden window)
- '%TEMP%\tmp1964.exe' /VERYSILENT' (with hidden window)
- '%TEMP%\is-enhbb.tmp\7z.exe' x "%TEMP%\is-ENHBB.tmp\AppHostInterface_1.drv.7z" -o"%APPDATA%\AppHostInterface_1" -pmkyOzOvxg7yXsjAH44noXr5HpVjXs94S -y' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s /i:svc "%APPDATA%\AppHostInterface_1\\AppHostInterface_1.drv"' (with hidden window)