Technical Information
- %TEMP%\7zS1.tmp\5158d3e46bf62.exe /s
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\z3p@qmfwbcyy.net\content\bg.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\z3p@qmfwbcyy.net\content\zy.xul
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\5158d3e46bd4d8.21792282.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\z3p@qmfwbcyy.net\install.rdf
- %TEMP%\nsy3.tmp\UserInfo.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\z3p@qmfwbcyy.net\bootstrap.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\z3p@qmfwbcyy.net\chrome.manifest
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\sqlite.js
- %TEMP%\nsy3.tmp\nsJSON.dll
- <LS_APPDATA>\Google\Chrome\User Data\Default\Preferences
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\manifest.json
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\background.html
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\content.js
- <LS_APPDATA>\Google\Chrome\User Data\Default\Extensions\neghkaamekohkibfcejpakaommgmiofp\1\lsdb.js
- %TEMP%\7zS1.tmp\z3p@qmfwbcyy.net\content\zy.xul
- %TEMP%\7zS1.tmp\z3p@qmfwbcyy.net\bootstrap.js
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\content.js
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\lsdb.js
- %TEMP%\7zS1.tmp\z3p@qmfwbcyy.net\content\bg.js
- %TEMP%\7zS1.tmp\z3p@qmfwbcyy.net\chrome.manifest
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\background.html
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\5158d3e46bd4d8.21792282.js
- %TEMP%\7zS1.tmp\5158d3e46bf9c.tlb
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\manifest.json
- %TEMP%\7zS1.tmp\z3p@qmfwbcyy.net\install.rdf
- %TEMP%\7zS1.tmp\5158d3e46bf9c.dll
- %TEMP%\7zS1.tmp\neghkaamekohkibfcejpakaommgmiofp\sqlite.js
- %TEMP%\7zS1.tmp\settings.ini
- %TEMP%\7zS1.tmp\5158d3e46bf62.exe