Technical Information
- [<HKLM>\SYSTEM\ControlSet001\services\WajamUpdater] 'Start' = '00000002'
- '%PROGRAM_FILES%\Wajam\Updater\WajamUpdater.exe'
- '%PROGRAM_FILES%\Wajam\IE\waitBHOEnable.exe'
- '%TEMP%\nsh6A77.tmp\nsA2E7.tmp' net start WajamUpdater
- '%TEMP%\nsh6A77.tmp\ns987A.tmp' net stop WajamUpdater
- '%PROGRAM_FILES%\Wajam\Updater\WajamUpdater.exe' /Service
- '<SYSTEM32>\conhost.exe' --type=renderer --disable-direct-npapi-requests --lang=en-US --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=1460 --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="1992.3.1781721779\1021162633" /prefetch:673131151
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\net1.exe' start WajamUpdater
- '<SYSTEM32>\net.exe' stop WajamUpdater
- '<SYSTEM32>\net1.exe' stop WajamUpdater
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1584.tmp
- <Auxiliary element>
- %APPDATA%\Roaming\Opera Software\Opera Stable\EEFF.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\22B4.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D36.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\17A8.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp
- %TEMP%\etilqs_lHGyXobPA3jJJAy
- %APPDATA%\Roaming\Opera Software\Opera Stable\History Provider Cache
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\LOG
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\LOG
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\887.tmp
- %TEMP%\etilqs_NK7k2kxnmEZvx1x
- %TEMP%\etilqs_OhhsElI8wfBIk2C
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\278A.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\25E3.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\24B9.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\MO1O9A0MPVA5ILN4UA9U.temp
- %PROGRAM_FILES%\Wajam\install.log
- %TEMP%\nsh6A77.tmp\System.dll
- <LS_APPDATA>\Wajam\Chrome\unique_id.txt
- %PROGRAM_FILES%\Wajam\IE\res\wajam.html
- %PROGRAM_FILES%\Wajam\IE\res\alert_window_bho.html
- %PROGRAM_FILES%\Wajam\IE\wajam.dll
- %TEMP%\nsh6A77.tmp\DcryptDll.dll
- %TEMP%\nsh6A77.tmp\IpConfig.dll
- %TEMP%\nsh6A38.tmp
- <LS_APPDATA>\Wajam\Chrome\wajam_121.crx
- %APPDATA%\Roaming\Mozilla\Firefox\Profiles\fzv9i9tr.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
- %APPDATA%\Roaming\Mozilla\Firefox\Profiles\fzv9i9tr.default\extensions\unique_id.txt
- <Current directory>\install2.log
- %PROGRAM_FILES%\Wajam\IE\uninstall.exe
- %TEMP%\nsh6A77.tmp\nsA2E7.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- %TEMP%\nsh6A77.tmp\inetc.dll
- %TEMP%\nsh6A77.tmp\nsisos.dll
- %PROGRAM_FILES%\Wajam\IE\waitBHOEnable.exe
- %PROGRAM_FILES%\Wajam\IE\favicon.ico
- %PROGRAM_FILES%\Wajam\IE\res\wajam_logo.png
- %PROGRAM_FILES%\Wajam\Updater\WajamUpdater.exe
- %TEMP%\nsh6A77.tmp\ns987A.tmp
- %TEMP%\nsh6A77.tmp\nsExec.dll
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D35.tmp~RF620a9.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2294.tmp~RF62451.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1798.tmp~RF61cc3.TMP
- %TEMP%\nsh6A77.tmp\System.dll
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\14B9.tmp~RF61718.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RF6339d.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\277A.tmp~RF627da.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2479.tmp~RF6255a.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2594.tmp~RF6275d.TMP
- %TEMP%\nsh6A77.tmp\nsisos.dll
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- <Current directory>\install2.log
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RF5c976.TMP
- %TEMP%\nsh6A77.tmp\ns987A.tmp
- %TEMP%\nsh6A77.tmp\nsA2E7.tmp
- %TEMP%\nsh6A77.tmp\IpConfig.dll
- %TEMP%\nsh6A77.tmp\nsExec.dll
- %TEMP%\nsh6A77.tmp\inetc.dll
- %PROGRAM_FILES%\Wajam\install.log
- %TEMP%\nsh6A77.tmp\DcryptDll.dll
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2594.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2594.tmp~RF6275d.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\278A.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\277A.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\25E3.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2594.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\24B9.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2479.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2479.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2479.tmp~RF6255a.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\277A.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\277A.tmp~RF627da.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RF6339d.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\887.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Local State
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- from %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\MO1O9A0MPVA5ILN4UA9U.temp to %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\8548f632abe97aa3.customDestinations-ms
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2294.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2294.tmp~RF62451.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\EEFF.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Preferences
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1584.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\14B9.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RF5c976.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\14B9.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\14B9.tmp~RF61718.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D35.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D35.tmp~RF620a9.TMP
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\22B4.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\2294.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D36.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1D35.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\17A8.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1798.tmp
- from %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1798.tmp to %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1798.tmp~RF61cc3.TMP
- DNS ASK re###.opera.com
- DNS ASK sl####i.yandex.ru
- DNS ASK bi##.#ikimedia.org
- DNS ASK au######te.geo.opera.com
- DNS ASK en.###ipedia.org
- DNS ASK ap#.###sys.opera.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK www.ic#.com
- DNS ASK www.google.com
- DNS ASK www.wa##m.com
- DNS ASK www.go##le.ru
- DNS ASK i.##0.ru
- DNS ASK si#####ck2.opera.com
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Roaming\Opera Software\Opera Stable'
- ClassName: 'Chrome_WidgetWin_0' WindowName: ''
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MozillaUIWindowClass' WindowName: ''
- ClassName: 'MozillaContentWindowClass' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MozillaWindowClass' WindowName: ''
- ClassName: 'MozillaDropShadowWindowClass' WindowName: ''