Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E923B48A-3FF1-49D3-4FCA-F89F97D41ED4}]
- %TEMP%\76fe33b3\fytqw.dat
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- <LS_APPDATA>\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\administrator\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- <LS_APPDATA>\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- <LS_APPDATA>\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\eo1r@yiuisfs.net\bootstrap.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\eo1r@yiuisfs.net\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\eo1r@yiuisfs.net\install.rdf
- %ProgramFiles(x86)%\saveclicker\41vb.dll
- %ProgramFiles(x86)%\saveclicker\41vb.tlb
- %ProgramFiles(x86)%\saveclicker\41vb.dat
- %ProgramFiles(x86)%\saveclicker\41vb.x64.dll
- %PROGRAMDATA%\saveclicker\fytqw.exe
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- <LS_APPDATA>\torch\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- <LS_APPDATA>\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- %TEMP%\76fe33b3\fytqw.exe
- %TEMP%\76fe33b3\41vb.x64.dll
- %TEMP%\76fe33b3\41vb.tlb
- %TEMP%\76fe33b3\41vb.dll
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\content\bg.js
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\install.rdf
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\chrome.manifest
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\bootstrap.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\lsdb.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\content.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\manifest.json
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\background.html
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\spxixpcsb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- <LS_APPDATA>\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- <LS_APPDATA>\google\chrome\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- %PROGRAMDATA%\saveclicker\fytqw.dat
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\eo1r@yiuisfs.net\content\bg.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\spxixpcsb.js
- <LS_APPDATA>\google\chrome\user data\default\preferences__.tmp
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\aphbjndehljhongejnipkalfhgdomiig\2.1\manifest.json
- %PROGRAMDATA%\e8681721549c82b\{e96338dc-1468-4918-8ec2-8454bffc5025}.20190718024329
- %TEMP%\76fe33b3\fytqw.dat
- %TEMP%\76fe33b3\fytqw.exe
- %TEMP%\76fe33b3\41vb.x64.dll
- %TEMP%\76fe33b3\41vb.tlb
- %TEMP%\76fe33b3\41vb.dll
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\content\bg.js
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\install.rdf
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\chrome.manifest
- %TEMP%\76fe33b3\eo1r@yiuisfs.net\bootstrap.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\lsdb.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\content.js
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\manifest.json
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\background.html
- %TEMP%\76fe33b3\aphbjndehljhongejnipkalfhgdomiig\spxixpcsb.js
- %PROGRAMDATA%\ntuser.pol
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\76fe33b3\fytqw.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveClicker\41VB.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveClicker\41VB.x64.dll"
- '<SYSTEM32>\raserver.exe' /offerraupdate