Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e631c1f-635d-4638-8cbd-a47ef3fe7f16}]
- %TEMP%\468f41b7\gyxqmtijhdxo9c7.dat
- %TEMP%\468f41b7\fvbhixccmkeykh.dll
- %TEMP%\468f41b7\fvbhixccmkeykh.tlb
- %TEMP%\468f41b7\fvbhixccmkeykh.x64.dll
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\content\bg.js
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\bootstrap.js
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\chrome.manifest
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\install.rdf
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\yvpiqexrx.js
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\background.html
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\manifest.json
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\content.js
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\administrator\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\administrator\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %LOCALAPPDATA%\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- %LOCALAPPDATA%\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- %LOCALAPPDATA%\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- %LOCALAPPDATA%\torch\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\background.html
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\content.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\lsdb.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\manifest.json
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\acihlncgfcdnblcafahhgngllkimkfda\2.0\yvpiqexrx.js
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\k3tg@l1rltg5.edu\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\k3tg@l1rltg5.edu\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\k3tg@l1rltg5.edu\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\k3tg@l1rltg5.edu\install.rdf
- %ALLUSERSPROFILE%\ntuser.pol
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\k3tg@l1rltg5.edu\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\k3tg@l1rltg5.edu\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\k3tg@l1rltg5.edu\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\k3tg@l1rltg5.edu\install.rdf
- %ProgramFiles(x86)%\gosavee\fvbhixccmkeykh.dll
- %ProgramFiles(x86)%\gosavee\fvbhixccmkeykh.tlb
- %ProgramFiles(x86)%\gosavee\fvbhixccmkeykh.dat
- %ProgramFiles(x86)%\gosavee\fvbhixccmkeykh.x64.dll
- %ALLUSERSPROFILE%\gosavee\gyxqmtijhdxo9c7.exe
- %ALLUSERSPROFILE%\gosavee\gyxqmtijhdxo9c7.dat
- %ALLUSERSPROFILE%\2f597feeb3d4d954\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20250704141550
- %TEMP%\468f41b7\gyxqmtijhdxo9c7.dat
- %TEMP%\468f41b7\fvbhixccmkeykh.dll
- %TEMP%\468f41b7\fvbhixccmkeykh.tlb
- %TEMP%\468f41b7\fvbhixccmkeykh.x64.dll
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\content\bg.js
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\bootstrap.js
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\chrome.manifest
- %TEMP%\468f41b7\k3tg@l1rltg5.edu\install.rdf
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\yvpiqexrx.js
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\background.html
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\manifest.json
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\content.js
- %TEMP%\468f41b7\acihlncgfcdnblcafahhgngllkimkfda\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\local state
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSavee\FvBHIXccMkEykh.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSavee\FvBHIXccMkEykh.x64.dll"
- '<SYSTEM32>\raserver.exe' /offerraupdate