Application.Bundler.Somoto.A (AdAware), SearchProtectToolbar.YR (Lavasoft MAS)Behaviour: Malware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 52900543c17a5e7bf2dfca79aff4ed8e
SHA1: bde54935f39a7b826cbd04c655aa542a79100556
SHA256: 1967d352bba17da8da44a54fc2b72e380c0a8b66d565d5fcdbd9ed10d7921c17
SSDeep: 3072:b22ihA0m3BJP0vaUZf3dp5pJL7oCXEIolLb2wbdsIxa4s:0A0m3D0v3ZfN7HQEXolLxpsIa4s
Size: 162096 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-12-17 11:14:12
Analyzed on: Windows7Ada SP1 64-bit
Summary: Malware. Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Application creates the following process(es):
WerFault.exe:3548
WerFault.exe:2924
WerFault.exe:2488
Npjwb.exe:4764
YTAHelper.exe:2072
GLB4191.tmp:2908
ProtectWindowsManager.exe:3696
ProtectWindowsManager.exe:3648
GLJ41D1.tmp:3252
YouTubeAcceleratorService.exe:1348
YouTubeAcceleratorService.exe:1664
YouTubeAcceleratorService.exe:3648
ctmpua.exe:2288
ctmpua.exe:3432
ctmpua.exe:4816
ProtectService.exe:3944
ProtectService.exe:3960
XTab_Setup2121.exe:3784
jsdrv.exe:200
1F52.tmp:3644
wpm_v20.0.0.1953_0302.exe:3616
biclient.exe:2936
biclient.exe:1760
biclient.exe:3896
b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108
ins_yta.exe:1244
QQBrowser.exe:604
QQBrowser.exe:3556
DesktopMessenger.exe:3944
testlsp.exe:4468
powershell.exe:2340
powershell.exe:3496
powershell.exe:4512
powershell.exe:1684
powershell.exe:2388
powershell.exe:2708
setup.exe:3664
setup.exe:1756
HPNotify.exe:2060
cmdshell.exe:4028
ShopperPro.exe:4088
Ussgbdqdxxc.exe:4744
125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092
smt_istartsurf.exe:1836
ins_shopperpro.exe:3416
%original file name%.exe:2636
regsvr32.exe:2428
regsvr32.exe:3248
regsvr32.exe:3604
regsvr32.exe:3144
regsvr32.exe:1116
regsvr32.exe:1868
lspinst.exe:4328
lspinst.exe:3788
YTAHEL~1.EXE:796
DCytaiesmt_smtyc_setup.exe:3580
DCytaiesmt_smtyc_setup.exe:4188
DCytaiesmt_smtyc_setup.exe:3856
DCytaiesmt_smtyc_setup.exe:3976
DCytaiesmt_smtyc_setup.exe:3084
DCytaiesmt_smtyc_setup.exe:4260
spbiu.exe:3144
spbiu.exe:2612
wscript.exe:2072
6650.tmp:3864
INS_SENSE.EXE:4724
taskeng.exe:1420
ytaiesmt_smtyc_setup.exe:3588
INS_IWEBAR.EXE:4644
The Application injects its code into the following process(es):
YouTubeAcceleratorService.exe:2932
YouTubeAccelerator.exe:684
biclient.exe:4192
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process WerFault.exe:3548 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0dd4f150\Report.wer (239494 bytes)
The process WerFault.exe:2924 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0b6b27ab\Report.wer (239478 bytes)
The process WerFault.exe:2488 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_09b1efab\Report.wer (241156 bytes)
The process Npjwb.exe:4764 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\5774 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\hmwmphigb.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA795.tmp (595233 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\b31cdfed-0f00-400c-94a9-14f605306e7a-4.dll (38103 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe (9147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\installer.js (5 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\365718 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\emfom.dll (23 bytes)
%Program Files% (x86)\SensePlus\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\wuogor.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\lutouoko.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\System.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\SensePlus\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\bakxdyd.dll (31241 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5_user.job (74 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\ipgeoapi_com[1].json (40 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5.job (74 bytes)
The process YTAHelper.exe:2072 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.xul (203 bytes)
C:\ProgramData\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
%Program Files% (x86)\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\install.rdf (884 bytes)
C:\ProgramData\YTAHelper\YTAHelper.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\chrome.manifest (111 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\yta_database1_0_0.json (2 bytes)
C:\ProgramData\YTAHelper\YTAHelper64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\YTAHelper_64.png (4 bytes)
The process GLB4191.tmp:2908 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\YouTube Accelerator\~GLH000e.TMP (11493 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001a.TMP (13284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\blank.html (75 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000d.TMP (7861 bytes)
C:\Users\"%CurrentUserName%"\Desktop\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0006.TMP (115350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe (14357 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAuninstall.mht (9 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0011.TMP (34 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001f.TMP (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAIDN.LNG (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0001.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe (19739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe (27818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0004.TMP (16 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0009.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll (3048 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0016.TMP (6341 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0003.TMP (119 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0010.TMP (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\OK.gif (329 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
%Program Files% (x86)\YouTube Accelerator\cabex.dll (98 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000c.TMP (941 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLG49E0.tmp (93076 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0002.TMP (2104 bytes)
%Program Files% (x86)\YouTube Accelerator\temp.000 (51331 bytes)
%Program Files% (x86)\YouTube Accelerator\res\~GLH0014.TMP (75 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe (30222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll (3271 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000a.TMP (18940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll (6691 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000f.TMP (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0007.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe (20746 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll (34861 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll (7687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLC41C0.tmp (3791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLK43D5.tmp (1604 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe (3528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe (20848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLF49E1.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0005.TMP (65 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VADEU.LNG (18 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0012.TMP (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll (4155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page2.mht (1961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0015.TMP (4061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0000.TMP (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx (3175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page1.mht (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Cancel.gif (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe (2082 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAITA.LNG (1660 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe (146 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLJ41D1.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLM45D8.tmp (12 bytes)
C:\Windows\SysWOW64\temp.000 (3624 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000b.TMP (11493 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\~GLH0021.TMP (65 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\comtest.gif (1817 bytes)
%Program Files% (x86)\YouTube Accelerator\INSTALL.LOG (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\progbar.gif (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0020.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe (10592 bytes)
The process ProtectWindowsManager.exe:3696 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\WindowsMangerProtect\update\conf (5 bytes)
The process GLJ41D1.tmp:3252 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\SysWOW64\AniGIF.ocx (172 bytes)
The process YouTubeAcceleratorService.exe:1664 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\YouTube Accelerator\engine.dll (146 bytes)
%Program Files% (x86)\YouTube Accelerator\ipc.dll (286 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (60 bytes)
%Program Files% (x86)\YouTube Accelerator\xmldb.dll (192 bytes)
The process YouTubeAcceleratorService.exe:2932 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\Temp\SBCC0F0.tmp (98 bytes)
C:\Windows\Temp\SBCE919.tmp (44 bytes)
C:\Windows\Temp\SBCFD94.tmp (51193 bytes)
C:\Windows\Temp\SBC72CE.tmp (98 bytes)
%Program Files% (x86)\YouTube Accelerator\helper.dll (200 bytes)
C:\Windows\Temp\SBC14AD.tmp (547 bytes)
C:\Windows\Temp\SBCBBC1.tmp (44 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log (591 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (3076 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log (261752 bytes)
C:\ProgramData\TEMP:56E2E879 (240 bytes)
The process ctmpua.exe:2288 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[4].gif (35 bytes)
The process ctmpua.exe:3432 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[3].gif (35 bytes)
The process ctmpua.exe:4816 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[3].gif (35 bytes)
The process ProtectService.exe:3944 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\msvcp110.dll (536 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (876 bytes)
The process ProtectService.exe:3960 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (49 bytes)
The process XTab_Setup2121.exe:3784 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (17941 bytes)
%Program Files% (x86)\XTab\conf (1594 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1794 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\ver.txt (47 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (1685 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (4 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (21280 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5468 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1028.xpi (15 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn143C.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (15946 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (16990 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
The process YouTubeAccelerator.exe:684 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.bak_tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\SMALLTEST[1].htm (70 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9171.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log_tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9148.tmp (682 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log_tmp (601 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (3671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90D6.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk901F.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log_tmp (300 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90A0.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916D.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90C5.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log_tmp (3 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (408785 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9136.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B1.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log_tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log (76089 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk907E.tmp (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B3.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log_tmp (758 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log_tmp (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9159.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log_tmp (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk915B.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916F.tmp (1 bytes)
The process jsdrv.exe:200 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (6 bytes)
The process 1F52.tmp:3644 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\inetc.dll (44 bytes)
The process wpm_v20.0.0.1953_0302.exe:3616 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (3568 bytes)
The process biclient.exe:2936 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IZSMH2G7.txt (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\vlc_48[1].png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A0GU0ZSM.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\C7DICHCP.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0BISIEEE.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ga[1].js (25835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9GM47V2A.txt (116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[1].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[1].htm (4339 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-istartsurf[1].htm (1054 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\247cff67b7ccf545bc359dea5d4fdcca[1].htm (35176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XBFPV72L.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe (43024 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VWCSVYJT.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Z4XAPYNG.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CAECMN2Q.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VSU9UM32.txt (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9WGP90AI.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L7G4BE9A.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[1].htm (1059 bytes)
The process biclient.exe:4192 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Y2YQ0ZN9.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.7 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.4 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.5 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.2 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.3 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.0 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.1 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BFIYZCSM.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\40da6fd4d86af64fa44c08b317ad86e7[1].htm (36028 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.6 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe (12251 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8IZK4DIW.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XRSM1SYU.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[5].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyoLightGrayStripesBG[1].jpg (439 bytes)
The process biclient.exe:1760 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0ZXSMBUT.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\G4EMRU6A.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2YAKCMQE.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\11H1CVWK.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F8VDJPMY.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MCEUOC87.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ARAVBC6Q.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XT3O6SY5.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\5ee27ba0e055bb4684b8648858d31d9a[1].htm (34716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FFA3HBHT.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BDVF95Q7.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3KR1O1W4.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
The process biclient.exe:3896 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\N3J3D9ZZ.txt (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[2].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IWHOVB19.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[2].png (1277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\8b685dcf684f214ea8b00dc2c916e842[1].htm (34823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TE7T15RC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FNHOZK1G.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UEDY9YTQ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\32X7O7GH.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Q8XWSLCR.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\YK3867F1.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\eula[1].htm (1058 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0982L053.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8SWC09PC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[2].htm (1061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TZJ60FG3.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[2].htm (4391 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\1K9S4IKF.txt (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2I762JJ4.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LEX2PBNZ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L4B69UQE.txt (129 bytes)
The process b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\334.js (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\dd664ae6f5b9fff9189830efc4277c1f.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\e8bf7602a41c0cdd14ad3540f08069cf.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\d0ac5e3ab61d9c9d036ca53d47b29da9.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\cf410972f8f7d9ce4b77ee942f1466ad.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\e0aa67c698a956adcab1a009989465d9.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\a212c1cc5036af14d61114d057025057.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d7a9ef674b92bd799ec4bb2c4ad621ef.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\9c5116558c43d87c3a32571c768872c8.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\be649c4e3a3e93d8a40243a4b8fc8344.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\b7b54f267e564c72cde2760d1dbd8ba2.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\e5f493e4f10da2ac3e336eaebbe86097.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\b4bb02edd36de53e69ba6b93fbbaf546.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d3f76309e3ba67b37724cd13c2a877ab.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\0177f7adb3a7120281e3dc4ad27672bd.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\192.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\7bded2a2506031aee5561ee8095bfcda.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\cd42e843c315396a255ec90674730514.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\337.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\281.js (461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\f533812f59e22810ff3bc56548ce46a5.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\527d5f3becaec0408e1ef15ac8f13bb8.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\491bb26de8d74c88f4ef82985489e2a7.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\f15d508ac04f84271fdf78b6cd665aeb.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\390.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\162678864fe0dce10da8913dbd7ae511.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome.manifest (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\ef5f49cce70bb46b02b28579a3bd464b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\3d33016b291b0f7bcfe763a02760e8c7.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\skin.css (949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\a4216ae64b11870b51e4b6ddf906205d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\fc95591e3359f30c3025d78dffef3f08.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\23ee7c2ff74dde91e4fef185b27fc94c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\1d8df16ea3f4be636f5817d37d006df5.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\userCode\extension.js (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\193.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\defaults\preferences\prefs.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\57897893dc3d4deec228a28f1d8f10b2.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\e38361e1c88892cbd641c1625e826699.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\0d3c7da494fcbab7f37c0e38eed8654c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d599fcb25ec9c785d2c1d66a72962be4.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\83bbdd4a0fff63d909d0a0d0e0e6bd38.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\0f728b47f95c6ce7ef2de6868fd3ac67.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\3c15b1a00edb4ad7a7b6ea0c2f029e60.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\356.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\b23a8e0fe71c1dea24c69cf3bfa392b4.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\c0f52d7d6baeb5125934e7f4ae3aaaff.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\7fb62ef1207bd6500db94456a32fafff.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\34b8f82350c85955993d9f02d0941792.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\b33ac672edd3e152a7f18f3bbccca9ef.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\a6bfe546fc476bf6efa27bce866a3a5f.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\a3dd82821479da5accbcad4543805ae5.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\447b6d228c0833ca1c3560e0acb7ff93.js (659 bytes)
The process ins_yta.exe:1244 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLB4191.tmp (144 bytes)
The process QQBrowser.exe:604 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\scrollbar.bmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code6.jpg (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5D5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\remoterequest.js (2 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe (14022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml (553 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5C5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\vi\locale.properties (2 bytes)
The process QQBrowser.exe:3556 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (148 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (40 bytes)
The process DesktopMessenger.exe:3944 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[2].gif (35 bytes)
The process testlsp.exe:4468 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log (372618 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log (2150 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log (1295 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log (449 bytes)
The process powershell.exe:2340 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1GTL8DZTBO258N0GHLR0.temp (196 bytes)
The process powershell.exe:3496 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7O3W63F2E3I22BLN6TOW.temp (196 bytes)
The process powershell.exe:4512 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D34R02L3N7OKWC8P2R3J.temp (196 bytes)
The process powershell.exe:1684 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XZNWAHWP4KMSA08GUC3P.temp (196 bytes)
The process powershell.exe:2388 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZG7QQZ7AW1JD8CDIB6CZ.temp (196 bytes)
The process powershell.exe:2708 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L0DHHN7AY5J5O0FAV13K.temp (196 bytes)
The process setup.exe:3664 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files%\Common Files\ShopperPro\spbii64.exe (17848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\MoreInfo.dll (15 bytes)
%Program Files%\Common Files\ShopperPro\spbia.exe (11344 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.exe (33633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll (11659 bytes)
%Program Files%\Common Files\ShopperPro\spbiw.sys (1552 bytes)
%Program Files%\Common Files\ShopperPro\spbii32.exe (13368 bytes)
%Program Files% (x86)\ShopperPro\Updater.exe (25112 bytes)
%Program Files%\Common Files\ShopperPro\spbiu.exe (69777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\jsdrv.exe (100669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn697C.tmp (360871 bytes)
%Program Files% (x86)\ShopperPro\FireFox\chrome.manifest (113 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\System.dll (23 bytes)
%Program Files%\Common Files\ShopperPro\spbici32.dll (37025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (100378 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.dll (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsExec.dll (14 bytes)
C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (1 bytes)
%Program Files% (x86)\ShopperPro\FireFox\install.rdf (828 bytes)
%Program Files%\Common Files\ShopperPro\spbici64.dll (48241 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.json (11 bytes)
%Program Files% (x86)\ShopperPro\SPRemove.exe (20416 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro64.dll (18424 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.ej (14 bytes)
%Program Files% (x86)\ShopperPro\manifest.json (595 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)
The process setup.exe:1756 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_60.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_65.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c5.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a5.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f349.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2935.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f648.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f429.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f637.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-active.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f682.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a3.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_72.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_62.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23eb.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f699.png (691 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute.png (445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f453.png (867 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68e.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f1.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f472.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f645.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2601.png (626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23e9.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44c.png (812 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f518.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f237.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40d.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23-20e3.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b9.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f476.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f501.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f608.png (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f511.png (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a3.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2139.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f301.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe (21399 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40b.png (910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f521.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus-active.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68b.png (681 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a7.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f308.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f406.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ac.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ec.png (773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cb.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50a.png (708 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264d.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\30-20e3.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25c0.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE-GRAPHICS (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_02.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a0.png (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a9.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_20.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f506.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_49.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7.png (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4af.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f196.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f564.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f631.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_78.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f485.png (602 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fc.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53b.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ba.png (517 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none-blue.png (755 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f602.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f539.png (308 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f380.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f558.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31b.png (826 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (22093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55b.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f416.png (569 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21a9.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2734.png (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\send_message.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_44.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264b.png (701 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_56.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fe.png (472 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f6.png (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f335.png (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274e.png (442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2665.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21aa.png (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f364.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_55.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fb.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2648.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f400.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f561.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f303.png (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f425.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f694.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d3.png (590 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2716.png (443 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f459.png (978 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f508.png (293 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2615.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60f.png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fb.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f467.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f427.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f487.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52e.png (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44e.png (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f305.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40a.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f341.png (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f615.png (623 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2194.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f373.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31d.png (878 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f5.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f194.png (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f629.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a8.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f497.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f310.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f626.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2049.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f408.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f343.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\260e.png (963 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b4.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c1.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f451.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b50.png (552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61b.png (848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f523.png (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f647.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f517.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_57.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3f0.png (511 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4be.png (359 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb-1f1f7.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f236.png (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_11.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f316.png (981 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_73.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a9.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\35-20e3.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f352.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\libs.js (4316 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c5.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49c.png (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69f.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f525.png (991 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f414.png (935 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f613.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f515.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c9.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64d.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-active.png (410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c9.png (699 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_71.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f693.png (743 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2796.png (184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2753.png (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63c.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f442.png (928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69d.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f371.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f620.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e4.png (495 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f004.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f498.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f376.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62f.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f684.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f493.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_38.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2693.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\default_photo.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a4.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a2.png (767 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68f.png (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49d.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit-active.png (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f457.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31f.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_59.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f407.png (908 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ab.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f624.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45c.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f423.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f509.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a6.png (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f354.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f384.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f567.png (629 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7-1f1fa.png (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b1.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f649.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fc.png (659 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ac.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45e.png (639 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ed.png (420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60a.png (839 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f379.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f606.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4de.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b6.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f535.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25aa.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5ff.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\24c2.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f402.png (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52b.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a2.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f553.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f234.png (526 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_25.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2795.png (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3eb.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f504.png (643 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_37.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e6.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48d.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f5.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_47.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36b.png (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a9.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c4.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f696.png (986 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50c.png (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f2.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f340.png (739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_26.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f500.png (542 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f21a.png (596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fd.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f455.png (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34f.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f348.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2195.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f519.png (730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f304.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25b6.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f356.png (916 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_28.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f2.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c3.png (449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27bf.png (725 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\263a.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\36-20e3.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f412.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61f.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f639.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f690.png (774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ba.png (789 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f681.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f198.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f382.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_14.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2708.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ea.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62a.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52f.png (820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55a.png (889 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f446.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33b.png (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e9.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll (8406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e0.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f410.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_77.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f495.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f435.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47b.png (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b8.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\261d.png (585 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\settings.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_69.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b4.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55c.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2714.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f502.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c7.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61d.png (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f622.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ae.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51b.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2649.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ea.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a1.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f390.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c5.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42a.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f625.png (957 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\main.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_30.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f560.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53a.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ca.png (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e8.png (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_41.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6aa.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\203c.png (210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_13.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51d.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31a.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-out.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea-1f1f8.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42c.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f4.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec-1f1e7.png (747 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f195.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60b.png (931 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f300.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2705.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb.png (362 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f470.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f358.png (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\33-20e3.png (554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35e.png (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-close.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ac.png (556 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f342.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_53.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f503.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f437.png (958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f202.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b05.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ed.png (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49f.png (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f338.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\index.html (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f566.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2733.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53c.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2728.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f418.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f491.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f344.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4db.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_16.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fd.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2652.png (430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49b.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_32.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_22.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c7.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f636.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e7.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34b.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2663.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50e.png (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f232.png (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f484.png (574 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f555.png (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d2.png (901 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_43.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50b.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f346.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f551.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f529.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ab.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51f.png (619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231b.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f452.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fc.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_67.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_35.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64e.png (772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\ae.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2755.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f623.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_19.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f557.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f431.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d5.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_76.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f482.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f357.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f4.png (603 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31c.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17e.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f632.png (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b0.png (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f0cf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e6.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ab.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e2.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f685.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_54.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f355.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_34.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_63.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f351.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f251.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c4.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f462.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_03.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f687.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f426.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f627.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37c.png (621 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f413.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ee.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2712.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\34-20e3.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b06.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f605.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48b.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f319.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ef.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f403.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47d.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\32-20e3.png (518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f448.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_08.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f640.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f530.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f363.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f454.png (992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fe.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ba.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50f.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f680.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f314.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61e.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\37-20e3.png (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270b.png (496 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f450.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f527.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3299.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a6.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a0.png (833 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f309.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e2.png (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27b0.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ee.png (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bb.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f538.png (307 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f393.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bf.png (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f374.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e7.png (656 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f405.png (926 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60e.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f460.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f638.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4aa.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47f.png (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_80.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f633.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2744.png (698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f8.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit.png (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f479.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_66.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f520.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2122.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f365.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2934.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e3.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f171.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36a.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa.png (451 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f683.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f490.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f522.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f0.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41c.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c0.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1b.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264f.png (462 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f439.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f510.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38f.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2754.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264c.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ff.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f607.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f528.png (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f18e.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b8.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_79.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b0.png (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25ab.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f466.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38d.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3aa.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f603.png (850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26be.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d9.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61a.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f440.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69b.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fa.png (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2660.png (500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4eb.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f562.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f192.png (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main_test.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\hatter.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f19a.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2600.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4df.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a7.png (337 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f616.png (885 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f359.png (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f367.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f197.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f239.png (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f514.png (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f312.png (956 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_64.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f692.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f3.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48e.png (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f475.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b7.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f532.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_33.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c3.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c6.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37a.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f191.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f494.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f315.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f618.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_15.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f334.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c2.png (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f444.png (766 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30e.png (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fc.png (539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270c.png (685 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f604.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63d.png (968 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f370.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f695.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fd.png (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a7.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea.png (378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26d4.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\message.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f306.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f507.png (882 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b0.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f609.png (788 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f307.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a2.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1c.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f619.png (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8.png (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44d.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef-1f1f5.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ea.png (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f391.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f458.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267f.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bd.png (616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2651.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f443.png (857 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f688.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f534.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f461.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ae.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2197.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e3.png (389 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45a.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f409.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bb.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3297.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f332.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52a.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264e.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f23a.png (549 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68c.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43e.png (573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48c.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c1.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f438.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f3.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f415.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_50.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_45.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45f.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ce.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f1.png (251 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\303d.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f353.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ef.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus-active.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f6.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_17.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0-1f1f7.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_04.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f464.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f302.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52c.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f317.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f697.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f449.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a5.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f7.png (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2797.png (284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f250.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b6.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55e.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2198.png (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d4.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e5.png (315 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f377.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c0.png (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f401.png (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f488.png (492 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68d.png (514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f492.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f516.png (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f383.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b9.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f526.png (589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f536.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f193.png (528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f411.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f233.png (533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f3.png (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f422.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51a.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f330.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f478.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_75.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f385.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f360.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f477.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_31.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2614.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f691.png (791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2199.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f433.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f480.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f235.png (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_12.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_24.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f378.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69a.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3030.png (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31e.png (902 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b2.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f22f.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9-1f1ea.png (267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fb.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c6.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f552.png (702 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45d.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267b.png (951 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ec.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49e.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42b.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f524.png (608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fa.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f686.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f468.png (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bb.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2747.png (473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f612.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f559.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_58.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_18.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b5.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f471.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e4.png (494 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62b.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d8.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\jquery.min.js (4267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fb.png (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47e.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cc.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f420.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c8.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f698.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ce.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f387.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b5.png (437 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f617.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f366.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f238.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f614.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f550.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cd.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f9.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa-1f1f8.png (310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6af.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f611.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f362.png (780 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f456.png (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a4.png (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c0.png (781 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fe.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f428.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50d.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\Data\Config.xml (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f434.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f199.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f419.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f347.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a0.png (655 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoDB13.tmp\nsisFirewall.dll (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_68.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c2.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f646.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\a9.png (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\e50a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d6.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2653.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ec.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ea.png (551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27a1.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f339.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f445.png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f473.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d1.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c1.png (223 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34e.png (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f489.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f311.png (712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f170.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f486.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e9.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ae.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f531.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2650.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f512.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ad.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_42.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-icon.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2196.png (356 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_46.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f556.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264a.png (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_52.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f481.png (972 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bc.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f331.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f350.png (595 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a8.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55f.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_21.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49a.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35d.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f635.png (770 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bd.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_10.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cf.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f333.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274c.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f345.png (881 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f337.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee.png (302 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270f.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8-1f1f3.png (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43d.png (466 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f447.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4da.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e8.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e1.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26aa.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_05.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_51.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f313.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f424.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_40.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_27.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f381.png (477 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_29.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17f.png (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2757.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270a.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2611.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f465.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_09.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a5.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b8.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62e.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f3.png (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b7.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2764.png (513 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f537.png (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d0.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d7.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f634.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f392.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f386.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2668.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f5.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_61.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f533.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f389.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c4.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f372.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log.png (670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_23.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f496.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bf.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ab.png (735 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e0.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f483.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_39.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ca.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f554.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b07.png (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef.png (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b7.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f621.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f388.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2666.png (407 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f369.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f463.png (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f565.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2709.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c8.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2702.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37b.png (875 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f436.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e5.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f201.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30a.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f689.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a1.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f375.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_74.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b3.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b1.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\31-20e3.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f318.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ed.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3be.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f432.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f368.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_70.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231a.png (754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f601.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f474.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64b.png (945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f600.png (815 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69e.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62c.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f513.png (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f417.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f630.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_01.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f499.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f430.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53d.png (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f421.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bc.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\38-20e3.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55d.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a6.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b55.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48a.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\39-20e3.png (527 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a1.png (738 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f563.png (787 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f469.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main.html (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f610.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_36.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f9.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a8.png (555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f505.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_06.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b1.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f404.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_07.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e7.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f628.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f361.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6be.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee-1f1f9.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f320.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3af.png (1 bytes)
The process HPNotify.exe:2060 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\conf (1480 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (24 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (24 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (24 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (49 bytes)
The process cmdshell.exe:4028 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\XTab\HPNotify.exe (675 bytes)
The process ShopperPro.exe:4088 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\ShopperPro\config.json (487 bytes)
C:\ProgramData\ShopperPro\ShopperPro.dll (2321 bytes)
%Program Files% (x86)\ShopperPro\config.json (1254 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (291 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\database1_0_0.ej (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\config.json (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\database1_0_0.json (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\install.rdf (828 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (22786 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\chrome.manifest (113 bytes)
C:\ProgramData\ShopperPro\database1_0_0.ej (14 bytes)
C:\ProgramData\ShopperPro\ShopperPro64.dll (3361 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\config.json (767 bytes)
The process Ussgbdqdxxc.exe:4744 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\installer.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\System.dll (808 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\125b6778-a7b3-42de-b39a-7082dbd6c683-4.dll (38103 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\lutouoko.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp (4 bytes)
%Program Files% (x86)\iWebar\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\wuogor.dll (8 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\133 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\340584 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA60F.tmp (601872 bytes)
%Program Files% (x86)\iWebar\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\hmwmphigb.dll (14 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\bakxdyd.dll (31241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe (9147 bytes)
The process 125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\08698225a6048f6e460097f16e02e704.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\71d4611ff095ba11d5170e66cbcb1f99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\e495468dafb76cfdaf72e5fa8d28a349.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\64e8d4e87627d5c1948a0bcef5d8bddf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\27cf8aa127aac261d305fe9089529830.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins.json (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\3d80de7fb266005117ceaafcc80fdce9.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\cd81bdfb69d0d25218ce67718be563af.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\385.js (805 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\1780bb19c407d25583ce46e040481d99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\85ea74e5af2c1af63fce579c5ab50f9f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome.manifest (622 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\b25ebd4eb2e834fb9cccdc10bb148863.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\fbbdb0f74062a849bda57f6fe11fcf32.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\f769131cae2813ce580e9e94c4e96f9c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\e7c458df68b2cf4608fc221688ae08ca.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\ebf33cc6f061080861c3e83c583756dc.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\290.js (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\fd27a2fb33b55a5f18ab50f4ba936cd4.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\0bec9e6b7afcc4c4516f35378da8e8f9.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\af5a57f759bd1cf2e294bcfccaf931fb.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\686b2fd98f5ea3e56eaaef1af8491492.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\3e381797919b94e2bb615148f7e47028.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\56d8099de7f917a05ebc946e4ff23a90.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\ffb8884740ec4a25e7613eb834ca1913.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\79f3c8aab387a44396d3dacdadf581ca.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\0034b573374c522556781d729432c887.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\525208f03fe2d8bef8b7bb6b8ef4fce1.js (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\287fabae0a36fcfbc8d77dcdaaaad216.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\8c01eaa93fd0bc0662848c840cae8041.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\b790483a12fb1b0b6cd3863184729b25.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\633a77e2ae00bb6d6d2e3abbbbe03912.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\269585125e1cb71c5dfc6f15d18aba48.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\userCode\extension.js (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\01b19a2e32d1a93bc2187a399e31eb51.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\edc254d662db048aede80d03ff95a848.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\5647e30e6af0add68690b1d263429c43.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\eca39140ee956f1f06527fb9ad62e501.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\b7c3eebfc78cf0199ff6ad83ec7241bf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\e83df05e1cf9ce178c9205b266814e5e.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\69a7dc8ac94d415bb9c821991dc88c28.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\skin.css (899 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\29d9a644a93fb36aff415aeea5c35684.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\8c47021875b6fd49edb959b301d1c49a.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\437c9512ae40f6cf2212e22d83fc0762.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\6aacfc15412fb43d4bcd12a55d84a7ac.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\1358a6937d07734cf85a79aaec52d489.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\a48b2e165ded142e4fd41c767365d414.js (26 bytes)
The process smt_istartsurf.exe:1836 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (76650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowser.exe (5199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\sweetsearch!1.0.0.1031.xpi (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (16944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg2.zip (259958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\conf (79 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\quick_searchff#5.4.10.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\UninstallManager.exe (60186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg1.zip (172558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox.png (545 bytes)
The process ins_shopperpro.exe:3416 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup1.exe (144456 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61CF.tmp (155198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup.exe (1606835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\D1958.dll (30 bytes)
The process %original file name%.exe:2636 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe (8409 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nshCF02.tmp (7098 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\config.ini (113 bytes)
The process regsvr32.exe:3248 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\YTAHelper\YTAHelper.dll (409 bytes)
The process regsvr32.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\YTAHelper\YTAHelper64.dll (491 bytes)
The process regsvr32.exe:1116 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\ShopperPro\ShopperPro64.dll (528 bytes)
The process regsvr32.exe:1868 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\ShopperPro\ShopperPro.dll (442 bytes)
The process lspinst.exe:4328 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\YouTube Accelerator\instlsp.log (295 bytes)
C:\ProgramData\TEMP:56E2E879 (417 bytes)
The process lspinst.exe:3788 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\YouTube Accelerator\instlsp.log (253 bytes)
C:\ProgramData\TEMP:56E2E879 (417 bytes)
The process YTAHEL~1.EXE:796 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\YTAHelper\FireFox\content\YTAHelper_64.png (4 bytes)
%Program Files% (x86)\YTAHelper\FireFox\chrome.manifest (111 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.exe (32784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\YTAHelper\FireFox\install.rdf (884 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\jsdrv.exe (100669 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.exe (100378 bytes)
C:\Users\Public\Documents\YTAHelper\JsDriver\Config.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B02.tmp (118586 bytes)
%Program Files% (x86)\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.dll (13584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll (11667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\System.dll (23 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper64.dll (16424 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\MoreInfo.dll (15 bytes)
The process DCytaiesmt_smtyc_setup.exe:3580 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe (7726 bytes)
The process DCytaiesmt_smtyc_setup.exe:3856 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe (48375 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe (31105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe (18619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe (7726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe (50552 bytes)
The process DCytaiesmt_smtyc_setup.exe:4260 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log (15488 bytes)
The process spbiu.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\ShopperPro\spbihe.js (435 bytes)
The process spbiu.exe:2612 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\ProgramData\ShopperPro\spbihe.js (435 bytes)
%Program Files%\Common Files\ShopperPro\spbia.exe (327 bytes)
The process 6650.tmp:3864 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\inetc.dll (44 bytes)
The process INS_SENSE.EXE:4724 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Sgfzhi.tmp (390774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Npjwb.exe (1335155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\pvgykk.dll (2121 bytes)
The process taskeng.exe:1420 makes changes in the file system.
The Application creates and/or writes to the following file(s):
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (291 bytes)
The process ytaiesmt_smtyc_setup.exe:3588 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\4D90EAE405E9E2FF (34773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\D1989.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe (379403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3247.tmp (35697 bytes)
The process INS_IWEBAR.EXE:4644 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\pvgykk.dll (2121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Ussgbdqdxxc.exe (1340508 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Rtmrbzobbxy.tmp (392398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\gzxaaspvo.dll (30 bytes)
Registry activity
The process WerFault.exe:3548 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"
The process WerFault.exe:2924 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"
The process WerFault.exe:2488 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"
The process Npjwb.exe:4764 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"CrPublisherId" = "20891"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "35 11 53 32 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"DisplayVersion" = "1.36.01.22"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"
[HKLM\SOFTWARE\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "69 41 55 2F FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"DisplayIcon" = "%Program Files% (x86)\SensePlus\utils.exe"
[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"
[HKLM\SOFTWARE\Wow6432Node\SensePlus\Installer]
"BundledFirefox" = "1"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"Publisher" = "Sense "
"DisplayName" = "SensePlus"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 59 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"CrAppId" = "70299"
"UninstallString" = "%Program Files% (x86)\SensePlus\Uninstall.exe /fcp=1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKCU\Software\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"
[HKCU\Software\InstalledBrowserExtensions\Sense ]
"70299" = "SensePlus"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process YTAHelper.exe:2072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"UserId" = "%%PIXGUID(aff=smtyc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
"{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}" = "Type: REG_SZ, Length: 0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "CF DC F1 27 FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "Type: REG_SZ, Length: 0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
"{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"
"NoExplore" = "1"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"CONFIGLOCATION" = "C:\ProgramData\YTAHelper"
"Version" = "1.5.4.199"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 50 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Aff" = "Type: REG_SZ, Length: 0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator\ExtraInfo]
"DBVersion" = "1.0.0.1"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"DBLocation" = "C:\ProgramData\YTAHelper"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process GLB4191.tmp:2908 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Goobzo\YouTube Accelerator]
"InstallTime" = "1429596744"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage" = "0"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"ShowAds" = "1"
[HKCU\Software\Goobzo\YouTube Accelerator]
"(Default)" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Aff" = "smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,"
[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowAds" = "1"
[HKCU\Software\Goobzo\Language\YouTubeAccelerator\Settings]
"CurrentLanguage" = "1033"
[HKCU\Software\Goobzo\YouTube Accelerator]
"DontShowAccelerationNotSupported" = "1"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Publisher" = "Goobzo Ltd."
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LspInstall" = "%Program Files% (x86)\YouTube Accelerator\"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32]
"AniGIF.ocx" = "1"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"ZippedRules" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"URLInfoAbout" = "http://www.youtubeaccelerator.com/support/"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"InstallTime" = "1429596744"
"DllInstall" = "%Program Files% (x86)\YouTube Accelerator\"
[HKCU\Software\Goobzo\YouTube Accelerator]
"Beta" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayIcon" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe,-0"
"InstallLocation" = "%Program Files% (x86)\YouTube Accelerator"
[HKCU\Software\Goobzo\YouTube Accelerator]
"HideAccList" = "0"
"ShowTrayIcon" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"HelpLink" = "http://www.youtubeaccelerator.com/about/"
[HKCU\Software\Goobzo\YouTube Accelerator]
"BuildNumber" = "102"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"UninstallString" = "%Program Files% (x86)\YouTube Accelerator\YTAUninstall.exe"
[HKCU\Software\Goobzo\YouTube Accelerator]
"Version" = "3.3.9.6"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Contact" = "support@youtubeaccelerator.com"
"DisplayVersion" = "3396(build_102)"
[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayName" = "YouTube Accelerator"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"(Default)" = ""
[HKCU\Software\Goobzo\YouTube Accelerator]
"Aff" = "smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Version" = "3.3.9.6"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\YouTube Accelerator]
"Order" = "E0 80 00 00 00 20 00 00 0D C0 10 00 00 10 00 00"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Beta" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application" = "http://www.fileextensionpro.com/redir.aspx?s=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&LangID=x&Ext=%s"
[HKCU\Software\Goobzo\YouTube Accelerator]
"RunFinishInstall" = "1"
[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Engine]
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"tver"
[HKCU\Software\Goobzo\YouTube Accelerator]
"Br"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"BrName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"HideAccList"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Engine]
"Mode"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Goobzo\YouTube Accelerator]
"BrName"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Br"
"ShowTrayIcon"
The Application disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"YouTubeAccelerator"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VARemove"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"
The process ProtectWindowsManager.exe:3696 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"
The process ProtectWindowsManager.exe:3648 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\services\eventlog\Application\WindowsMangerProtect]
"EventMessageFile" = "C:\ProgramData\WindowsMangerPro盺}"
"TypesSupported" = "7"
The process GLJ41D1.tmp:3252 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5]
"(Default)" = "Animation GIF Control"
[HKCR\AniGIFPpg2.AniGIFPpg2]
"(Default)" = "AniGIFPpg2 Class"
[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ToolboxBitmap32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx, 1"
[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus]
"(Default)" = "0"
[HKCR\AniGIFCtrl.AniGIF\CLSID]
"(Default)" = "{82351441-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "IAniGIF"
[HKCR\AniGIFPpg.AniGIFPpg]
"(Default)" = "AniGIFPpg Class"
[HKCR\AniGIFPpg2.AniGIFPpg2.1]
"(Default)" = "AniGIFPpg2 Class"
[HKCR\AniGIFPpg.AniGIFPpg\CurVer]
"(Default)" = "AniGIFPpg.AniGIFPpg.1"
[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}]
"(Default)" = "IAniGIFEvents"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus\1]
"(Default)" = "131473"
[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "IAniGIF"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "Animation GIF Control"
[HKCR\AniGIFCtrl.AniGIF\CurVer]
"(Default)" = "AniGIFCtrl.AniGIF"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb\0]
"(Default)" = "&Properties,0,2"
[HKCR\AniGIFPpg2.AniGIFPpg2\CurVer]
"(Default)" = "AniGIFPpg2.AniGIFPpg2.1"
[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"Version" = "1.5"
[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}]
"(Default)" = "AniGIFPpg Class"
[HKCR\AniGIFCtrl.AniGIF]
"(Default)" = "Animation GIF Control"
[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\AniGIFPpg.AniGIFPpg.1]
"(Default)" = "AniGIFPpg Class"
[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"Version" = "1.5"
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Version]
"(Default)" = "1.5"
[HKCR\AniGIFPpg.AniGIFPpg.1\CLSID]
"(Default)" = "{6DC82D15-92F2-11D1-A255-00A0C932C7DF}"
[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"
[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"
[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\0\win32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"
[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\FLAGS]
"(Default)" = "2"
[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}]
"(Default)" = "IAniGIFEvents"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb]
"(Default)" = ""
[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"Version" = "1.5"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ProgID]
"(Default)" = "AniGIFCtrl.AniGIF"
[HKCR\AniGIFCtrl.AniGIF\Insertable]
"(Default)" = ""
[HKCR\AniGIFPpg2.AniGIFPpg2.1\CLSID]
"(Default)" = "{61AB12E1-A5FF-11D1-B2E9-444553540000}"
[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}]
"(Default)" = "AniGIFPpg2 Class"
[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\HELPDIR]
"(Default)" = "C:\Windows\SysWow64\"
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"
[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"Version" = "1.5"
[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"
[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
"ThreadingModel" = "Apartment"
The Application deletes the following registry key(s):
[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Programmable]
The process YouTubeAcceleratorService.exe:1348 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "04 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
The process YouTubeAcceleratorService.exe:1664 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "01 00 00 00"
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\InProcServer32]
"ThreadingModel" = "Both"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{K7C0DB872A3F777C0}" = "E8 93 CD 16 42 17 1F FF FF FF FF 64 22 18 AF D9"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"(Default)" = "Seeking"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\InProcServer32]
"(Default)" = "C:\Windows\SysWOW64\quartz.dll"
The Application deletes the following value(s) in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"0"
The process YouTubeAcceleratorService.exe:2932 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ}JbXMHpbpODr"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 06 00 00 00 09 00 00 00 00 00 00 00"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKU\.DEFAULT\Software\GOOBZO\YouTube Accelerator]
"LastUpdateTime" = "1429596791"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LSPTestSucceeded" = "1"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "09 00 00 00"
[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"XMLVersion" = "0"
"XMLUpdateFailed" = "0"
[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPPW" = "GLA9Y4un"
[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"VA_Aff" = "NONE"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|ab@_w}Yu`gBISI`@Ndl"
[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"UpdateReason" = "0"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "7A 33 65 29 FA 7B D0 01"
[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAPW" = "mm7DBqQs"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"
[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAIDV" = "0"
"SBPIDV" = "0"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"
[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"resver" = "1.0.0.8"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"
[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPID" = "134bc0d4-cd69-4c5d-bd9b-0a36a7095905"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "7A 33 65 29 FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LspVersion" = "1.0.0.1"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "YeDT^L`~p"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAID" = "7f18dd1b-ec41-4752-9468-5f9624612952"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
The Application deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"Uojvoqeov"
"qvorsEtjxw"
"qvbbRNdMg"
"cgcdxuSksc"
"LdsE"
"fSXewhkfv"
"yxQHXfdfitoe"
"pxylOXnGwpXkz"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"jugyvwoEcjGw"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"rffapxdttSchh"
"yEsrDTepOCs"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"hFLwn"
"DxOl"
"FdUXjkIpvn"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"qPacydvhduuR"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"MNEMOyZJWG"
"omdjT"
[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"uqmpybcjdI"
"pseKcc"
The process YouTubeAcceleratorService.exe:3648 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "07 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
The process ctmpua.exe:2288 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\BI]
"w2mi" = "false"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5E 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process ctmpua.exe:3432 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\BI]
"w2mi" = "false"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5F 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process ctmpua.exe:4816 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\BI]
"w2mi" = "false"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5D 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process ProtectService.exe:3944 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 49 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\IHProtect]
"ptid" = "smt"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"
The process ProtectService.exe:3960 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 05 00 00 00 09 00 00 00 00 00 00 00"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"
The process XTab_Setup2121.exe:3784 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\XTab"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
"{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" = "1"
[HKLM\SOFTWARE\Wow6432Node\supTab]
"ptid" = "smt"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"TopResultURL" = "http://www.bing.com/search?q={searchTerms}&src=IE-TopResult&FORM=IETR02"
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 47 00 00 00 09 00 00 00 00 00 00 00"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0]
"(Default)" = "SupTabLib"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURL" = "http://www.bing.com/favicon.ico"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
"(Default)" = "IETabPage Class"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved]
"{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" = ""
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\Version]
"(Default)" = "1.0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico"
"DisplayName" = "Bing"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconURL" = "http://www.google.com/favicon.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}"
[HKLM\SOFTWARE\Wow6432Node\SupDp]
"dir" = "%Program Files% (x86)\XTab"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconURL" = "http://do-search.com//favicon.ico"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"
[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"
[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"
[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"TopResultURL" = "http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"TopResultURL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\PROTECTEDMODESECURITY]
"CheckedValue" = "PMIL"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURLFallback" = "http://www.bing.com/favicon.ico"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"DisplayName" = "Google"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"DisplayName" = "e"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\PROTECTEDMODESECURITY]
"DefaultValue" = "PMIL"
[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{E733165D-CBCF-4FDA-883E-ADEF965B476C}.ico"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"
The process YouTubeAccelerator.exe:684 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Goobzo\YouTube Accelerator]
"UiResVer" = "1000008"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "3B 5A C5 2D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "0C 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "D6 80 6E 2B FA 7B D0 01"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\"
[HKCU\Software\Goobzo\YouTube Accelerator]
"CommTestBootNeeded" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 54 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TimeLimit" = "1"
"TimeStamp" = "1429596761"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process jsdrv.exe:200 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro\JsDriver\Tracer]
"TraceLevel" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "47 38 DC 29 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "D6 80 6E 2B FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 51 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process 1F52.tmp:3644 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "8C ED 90 F5 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4B 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process wpm_v20.0.0.1953_0302.exe:3616 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process biclient.exe:2936 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "25 CC 85 1E BF 72 D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "AD D1 5A E2 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process biclient.exe:4192 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "70 71 C8 61 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5C 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process biclient.exe:1760 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "3E 84 1A 21 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "0E 99 D6 26 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4E 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process biclient.exe:3896 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "A8 FB 71 F5 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 48 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKLM\SOFTWARE\Wow6432Node\SensePlus\BdC8v2inq6DW0g 17Itij/Ao6qs7VY2UO/GLLUG vwECX0QzvPokNprJa 54LBUUswWEm5FuqOnu5tFjnTqkaee0MtijumFPn5RIL3h694Qb26mrJ47q4ZppeNcqx5gSlSy5rqRSjxMv SwJaW0v4syWcWjxlduFPAWXIrOGxo8=]
"Ep6RiGazZALFlmrTnWf1Z5S23oPOb5Bdil0Tu6jOzEGh4I/ pY/mBVxLTMDLxoAWZLmghf/uhnKXU2ew/DoyBxlJZSV EJNyM3nX5DIcxGhQnPmv0Vh3JNSqHfUZQcT8ztyH69YC/0L5MiY400AtutKJLFyGrRrRZ1aJs0z5o7M=" = "1"
[HKLM\SOFTWARE\Wow6432Node\SensePlus\kOh3UM0sElMiqev3yfmeSQG kIDfQMrDtUUKdBeZQFYRDn 4vqALxCRhdjVUQuH02yH41TJV1E8pqvbhPOggZ5Ln6qV98SgznqY9yJY5JtWQyQOBj2KP1Oo6KStyL37EiRvGTGPJMEDJGk0 f2wuncrPpvLrepeO3UC8nxb/hJI=]
"EjBZWTgzCSYnv0us2GklJd9kak/HonX7GcA9biIxImj2lk6xB/XpnoQzpEobQ4Di8Cm5mO7lN2MCHfl3qtk13f Lwvu9/2Bbl/41z66wiep4fCgs4UOAaD1Gu1t4uL/m lEmLwy3igXug1J0xltFV0VByOF7d2Q6l5XweQi9vIs=" = "1"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The process QQBrowser.exe:604 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Mozilla\Extends]
"AppID" = "quick_searchff@gmail.com"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E\@""%windir%\System32]
"ie4uinit.exe"",-738" = "Start Internet Explorer without ActiveX controls or browser extensions."
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Search Page" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"Publisher" = "istartsurfᄀ盛t"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Search_URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
"(Default)" = "%Program Files% (x86)\Mozilla Firefox\firefox.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "istartsurf"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKLM\SOFTWARE\Wow6432Node\istartsurfSoftware\istartsurfhp]
"oem" = "smt"
"Time" = "Type: REG_QWORD, Length: 8"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E\@""%systemroot%\system32\windowspowershell\v1.0]
"powershell.exe"",-111" = "Performs object-based (command-line) functions"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Clients\StartMenuInternet\VMWAREHOSTOPEN.EXE\shell\open\command]
"(Default)" = "%Program Files%\VMware\VMware Tools\VMwareHostOpen.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
"(Default)" = "%Program Files% (x86)\Google\Chrome\Application\chrome.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
"(Default)" = "%Program Files%\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe"
[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "1"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
"Search Page" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKCU\Software\Mozilla\Extends]
"UID" = "535559167_198339_B48A115F"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
"DisplayName" = "istartsurf"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKCU\Software\Mozilla\Extends]
"ptid" = "smt"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"DisplayName" = "istartsurf uninstall"
[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"quick_searchff@gmail.com" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\quick_searchff@gmail.com"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe -ptid=smt"
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "istartsurf"
The process QQBrowser.exe:3556 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process DesktopMessenger.exe:3944 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "67 4F A4 61 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5B 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process testlsp.exe:4468 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "14 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "3B 5A C5 2D FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"
"TimeLimit" = "1"
"TracerDoBackup" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 57 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TimeStamp" = "1429596761"
"TimeLimit" = "1"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process powershell.exe:2340 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:3496 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:4512 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:1684 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:2388 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process powershell.exe:2708 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The process setup.exe:3664 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll,"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro]
"UninstallString" = "%Program Files% (x86)\ShopperPro\SPremove.exe"
"DisplayName" = "Shopper-Pro"
"DisplayIcon" = "%Program Files% (x86)\ShopperPro\ShopperPro.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro.exe]
"(Default)" = "%Program Files% (x86)\ShopperPro\ShopperPro.exe"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process setup.exe:1756 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DesktopMessenger]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
"DesktopMessenger.exe" = "11000"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DesktopMessenger]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe /S"
"DisplayName" = "DesktopMessenger"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DesktopMessenger" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe"
The process cmdshell.exe:4028 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "8C ED 90 F5 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4A 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process ShopperPro.exe:4088 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"UserId" = "dcdf22cc-90c9-4f0a-9d09-8ebad4636366"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "47 38 DC 29 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"NoExplore" = "1"
[HKLM\SOFTWARE\ShopperPro]
"CONFIGLOCATION" = "C:\ProgramData\ShopperPro"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"Aff" = "smtyc"
[HKLM\SOFTWARE\ShopperPro]
"DBLocation" = "C:\ProgramData\ShopperPro"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "CF DC F1 27 FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ExeLocation" = "%Program Files% (x86)\ShopperPro"
"Version" = "3.1.9318.1773"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"DBLocation" = "C:\ProgramData\ShopperPro"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4F 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"CONFIGLOCATION" = "C:\ProgramData\ShopperPro"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ChromeExtFile" = "ShopperPro.crx"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ChromeExtID" = "ojhagnahfpegocdhlopgljpaafeogmcc"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"DriverVersion" = "1.42.0.1773"
[HKLM\SOFTWARE\Wow6432Node\ShopperPro\ExtraInfo]
"DBVersion" = "1.0.1.4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process Ussgbdqdxxc.exe:4744 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"DisplayName" = "iWebar"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"CrAppId" = "70121"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"Publisher" = "Webby"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"
[HKLM\SOFTWARE\Wow6432Node\iWebar\Installer]
"BundledFirefox" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "69 41 55 2F FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21836]
"70121" = "iWebar"
[HKCU\Software\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"UninstallString" = "%Program Files% (x86)\iWebar\Uninstall.exe /fcp=1"
"DisplayIcon" = "%Program Files% (x86)\iWebar\utils.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
"WpadDecisionTime" = "31 FB 2C 32 FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"
[HKLM\SOFTWARE\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"DisplayVersion" = "1.36.01.22"
"CrPublisherId" = "21836"
[HKCU\Software\InstalledBrowserExtensions\21836]
"70121" = "iWebar"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 58 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKLM\SOFTWARE\InstalledBrowserExtensions\21836]
"70121" = "iWebar"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\InstalledBrowserExtensions\Webby]
"70121" = "iWebar"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process 125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"
[HKLM\SOFTWARE\Wow6432Node\iWebar\kOh3UM0sElMiqev3yfmeSQG kIDfQMrDtUUKdBeZQFYRDn 4vqALxCRhdjVUQuH02yH41TJV1E8pqvbhPOggZ5Ln6qV98SgznqY9yJY5JtWQyQOBj2KP1Oo6KStyL37EiRvGTGPJMEDJGk0 f2wuncrPpvLrepeO3UC8nxb/hJI=]
"EjBZWTgzCSYnv0us2GklJd9kak/HonX7GcA9biIxImj2lk6xB/XpnoQzpEobQ4Di8Cm5mO7lN2MCHfl3qtk13f Lwvu9/2Bbl/41z66wiep4fCgs4UOAaD1Gu1t4uL/m lEmLwy3igXug1J0xltFV0VByOF7d2Q6l5XweQi9vIs=" = "1"
[HKLM\SOFTWARE\Wow6432Node\iWebar\BdC8v2inq6DW0g 17Itij/Ao6qs7VY2UO/GLLUG vwECX0QzvPokNprJa 54LBUUswWEm5FuqOnu5tFjnTqkaee0MtijumFPn5RIL3h694Qb26mrJ47q4ZppeNcqx5gSlSy5rqRSjxMv SwJaW0v4syWcWjxlduFPAWXIrOGxo8=]
"Ep6RiGazZALFlmrTnWf1Z5S23oPOb5Bdil0Tu6jOzEGh4I/ pY/mBVxLTMDLxoAWZLmghf/uhnKXU2ew/DoyBxlJZSV EJNyM3nX5DIcxGhQnPmv0Vh3JNSqHfUZQcT8ztyH69YC/0L5MiY400AtutKJLFyGrRrRZ1aJs0z5o7M=" = "1"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Tempo]
The process smt_istartsurf.exe:1836 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "AD D1 5A E2 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json,"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process %original file name%.exe:2636 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe,"
The process regsvr32.exe:2428 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\ShopperPro.ShopperProBHO]
"(Default)" = "Shopper Pro"
[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\VersionIndependentProgID]
"(Default)" = "ShopperPro.ShopperProBHO"
[HKCR\ShopperPro.ShopperProBHO.1\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "ShopperPro 1.0 Type Library"
[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro64.dll"
"ThreadingModel" = "Apartment"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro64.dll"
[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ProgID]
"(Default)" = "ShopperPro.ShopperProBHO.1"
[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "Shopper Pro"
[HKCR\ShopperPro.ShopperProBHO\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"
[HKCR\ShopperPro.ShopperProBHO\CurVer]
"(Default)" = "ShopperPro.ShopperProBHO.1"
[HKCR\AppID\ShopperPro.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"
[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "ShopperPro"
[HKCR\ShopperPro.ShopperProBHO.1]
"(Default)" = "Shopper Pro"
It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"
"NoExplorer" = "1"
The process regsvr32.exe:3248 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\YTAHelper.YTAHelperBHO.1]
"(Default)" = "YTAHelper"
[HKCR\YTAHelper.YTAHelperBHO.1\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"
[HKCR\YTAHelper.YTAHelperBHO]
"(Default)" = "YTAHelper"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\ProgID]
"(Default)" = "YTAHelper.YTAHelperBHO.1"
[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "YTAHelper"
[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"Version" = "1.0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"
[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"Version" = "1.0"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "YTAHelper 1.0 Type Library"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper.dll"
[HKCR\AppID\YTAHelper.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"
[HKCR\YTAHelper.YTAHelperBHO\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"
[HKCR\YTAHelper.YTAHelperBHO\CurVer]
"(Default)" = "YTAHelper.YTAHelperBHO.1"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelper"
[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"NoExplorer" = "1"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper.dll"
[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}]
"(Default)" = "IYTAHelperBHO"
[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\VersionIndependentProgID]
"(Default)" = "YTAHelper.YTAHelperBHO"
[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}]
"(Default)" = "IYTAHelperBHO"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
The process regsvr32.exe:3604 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\YTAHelper.YTAHelperBHO.1]
"(Default)" = "YTAHelper"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "YTAHelper 1.0 Type Library"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper64.dll"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper64.dll"
[HKCR\YTAHelper.YTAHelperBHO.1\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"
[HKCR\AppID\YTAHelper.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\ProgID]
"(Default)" = "YTAHelper.YTAHelperBHO.1"
[HKCR\YTAHelper.YTAHelperBHO\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"
[HKCR\YTAHelper.YTAHelperBHO\CurVer]
"(Default)" = "YTAHelper.YTAHelperBHO.1"
[HKCR\YTAHelper.YTAHelperBHO]
"(Default)" = "YTAHelper"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelper"
[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "YTAHelper"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\VersionIndependentProgID]
"(Default)" = "YTAHelper.YTAHelperBHO"
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"
"NoExplorer" = "1"
The process regsvr32.exe:1868 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "Shopper Pro"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro.dll"
[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\VersionIndependentProgID]
"(Default)" = "ShopperPro.ShopperProBHO"
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro.dll"
[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\ShopperPro.ShopperProBHO\CurVer]
"(Default)" = "ShopperPro.ShopperProBHO.1"
[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "ShopperPro"
[HKCR\AppID\ShopperPro.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"
[HKCR\ShopperPro.ShopperProBHO]
"(Default)" = "Shopper Pro"
[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"Version" = "1.0"
[HKCR\ShopperPro.ShopperProBHO.1\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"Version" = "1.0"
[HKCR\ShopperPro.ShopperProBHO\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"
[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
"(Default)" = "IShopperProBHO"
[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\ShopperPro.ShopperProBHO.1]
"(Default)" = "Shopper Pro"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\HELPDIR]
"(Default)" = "C:\ProgramData\ShopperPro"
[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "ShopperPro 1.0 Type Library"
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"
[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
"(Default)" = "IShopperProBHO"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"
[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ProgID]
"(Default)" = "ShopperPro.ShopperProBHO.1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"NoExplorer" = "1"
[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
The Application deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
The process lspinst.exe:4328 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ`DvisWwj@pPX["
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60101"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-100"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "11 00 00 00"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-101"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Next_Catalog_Entry_ID" = "1022"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-103"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
"ProtocolName" = "YTALSP"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60101"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Num_Catalog_Entries" = "13"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
"PackedCatalogItem" = "25 77 69 6E 64 69 72 25 5C 73 79 73 74 65 6D 33"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60100"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-102"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|acP_w}Yu`fRISI`@Ntl"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [TCP/IPv6]]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [UDP/IP]]"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\FdUXjkIpvn]
"(Default)" = "R[vJIqJXaKp}DD^P"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
"PackedCatalogItem" = "25 77 69 6E 64 69 72 25 5C 73 79 73 74 65 6D 33"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
"ProtocolName" = "VMCI sockets STREAM"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [TCP/IP]]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
"ProtocolName" = "YTALSP over [RSVP UDPv6 Service Provider]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
"ProtocolName" = "YTALSP over [RSVP TCP Service Provider]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
"ProtocolName" = "YTALSP over [RSVP TCPv6 Service Provider]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Serial_Access_Num" = "19"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"LspCategories" = "1"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60102"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"ProtocolName" = "YTALSP over [RSVP UDP Service Provider]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [UDP/IPv6]]"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
"ProtocolName" = "VMCI sockets DGRAM"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60100"
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60102"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "F}FdcTzbnLZBznXQtn["
The Application deletes the following registry key(s):
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000018]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000019]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000012]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000013]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000016]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000017]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000014]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000015]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001B]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001C]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001A]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
The Application deletes the following value(s) in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"FdUXjkIpvn"
"jugyvwoEcjGw"
"Uojvoqeov"
"rffapxdttSchh"
"yxQHXfdfitoe"
"qPacydvhduuR"
"qvorsEtjxw"
"qvbbRNdMg"
"yEsrDTepOCs"
"cgcdxuSksc"
"MNEMOyZJWG"
"LdsE"
"fSXewhkfv"
"omdjT"
"hFLwn"
"DxOl"
"uqmpybcjdI"
"pseKcc"
"pxylOXnGwpXkz"
The process lspinst.exe:3788 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ`DvisWwj@pPX["
[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|ac`_w}Yu`fbISI`@Ntl"
[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "0E 00 00 00"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\FdUXjkIpvn]
"(Default)" = "R[vJVqJXaK{RyQ\p"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "F}FdcTzbnLZBznXQtn["
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"
The Application deletes the following value(s) in system registry:
[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"FdUXjkIpvn"
"jugyvwoEcjGw"
"Uojvoqeov"
"rffapxdttSchh"
"yxQHXfdfitoe"
"qPacydvhduuR"
"qvorsEtjxw"
"qvbbRNdMg"
"yEsrDTepOCs"
"cgcdxuSksc"
"MNEMOyZJWG"
"LdsE"
"fSXewhkfv"
"omdjT"
"hFLwn"
"DxOl"
"uqmpybcjdI"
"pseKcc"
"pxylOXnGwpXkz"
The process YTAHEL~1.EXE:796 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll,"
The process DCytaiesmt_smtyc_setup.exe:3580 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "2E 37 95 20 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4C 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process DCytaiesmt_smtyc_setup.exe:4188 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "44 07 28 2F FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 55 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process DCytaiesmt_smtyc_setup.exe:3856 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Success]
"InstallStr" = "ok"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "3E 84 1A 21 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Success]
"Install" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4D 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer" = "2"
"MaxConnectionsPer1_0Server" = "2"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process DCytaiesmt_smtyc_setup.exe:3976 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "2D B6 24 2B FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 53 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process DCytaiesmt_smtyc_setup.exe:3084 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "2D B6 24 2B FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "BC FE B6 2C FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 52 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process DCytaiesmt_smtyc_setup.exe:4260 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TraceLevel" = "3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "27 F9 46 2F FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 56 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process spbiu.exe:3144 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Gcf" = "D9 91 CF EC EE 40 F4 7E 74 E4 CF FB 2F 99 75 C3"
[HKLM\SOFTWARE\ShopperPro\SPBIUpd\Users\Default]
"Ucf" = "AF 19 06 18 24 A7 78 A7 83 2B E1 77 84 81 A9 3B"
[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Scf" = "B7 D9 57 AC 22 CD 0F FA 23 62 C0 8C 21 AB 1C 1F"
The process spbiu.exe:2612 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Ult" = "Type: REG_QWORD, Length: 8"
The process wscript.exe:2072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process 6650.tmp:3864 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "99 5B C5 37 FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5A 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Application deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process taskeng.exe:1420 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{8B1CB6DE-FFAC-4723-BC59-32D8149549E7}]
"data" = "4D 45 4F 57 01 00 00 00 E4 B7 BD 92 8B F2 A0 46"
The process ytaiesmt_smtyc_setup.exe:3588 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe,"
Dropped PE files
MD5 | File path |
---|---|
88856f63e45c974b19a323e07a01b0a7 | c:\Program Files (x86)\SensePlus\Uninstall.exe |
19c952082b23910ad46f25db7a10b9bc | c:\Program Files (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe |
ec82f7731f3bc5b84d3faa10569b78c9 | c:\Program Files (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe |
26ccd2418100ccc2886fdc94d0a8ca2e | c:\Program Files (x86)\SensePlus\utils.exe |
262285531c6570177301e8e27145470c | c:\Program Files (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe |
bd7d9c5152704a1e11d32d0a0b729cb3 | c:\Program Files (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys |
262285531c6570177301e8e27145470c | c:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe |
bd7d9c5152704a1e11d32d0a0b729cb3 | c:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys |
7d8f239f995a9387dbca08b11c523cab | c:\Program Files (x86)\ShopperPro\SPRemove.exe |
5471f0ae1b92c014ea32f0ec5c11f923 | c:\Program Files (x86)\ShopperPro\ShopperPro.dll |
d6d6cc5817bd22d993545804fb250903 | c:\Program Files (x86)\ShopperPro\ShopperPro.exe |
f6884feeba4191fb3e8fbb09e6d54b74 | c:\Program Files (x86)\ShopperPro\ShopperPro64.dll |
82cbb6a522abe82d144c6593a026a3a5 | c:\Program Files (x86)\ShopperPro\Updater.exe |
33a33e52e9c7db9063cbac82fa9e28d4 | c:\Program Files (x86)\XTab\BrowerWatchCH.dll |
9def3a62487338e892ce4fffa8efa5d2 | c:\Program Files (x86)\XTab\BrowerWatchFF.dll |
5785680870eff9ba7b4f58c726552013 | c:\Program Files (x86)\XTab\BrowserAction.dll |
7e4e734d5adbbc4026a5db2e63c29d40 | c:\Program Files (x86)\XTab\CmdShell.exe |
8c15f35314eadbe08375dd47ad62439a | c:\Program Files (x86)\XTab\HPNotify.exe |
e6aac50b9fc19546c5e524c47be5d66d | c:\Program Files (x86)\XTab\IeWatchDog.dll |
e98c5cfa4051bfa3e2cb0afb10ff4cab | c:\Program Files (x86)\XTab\ProtectService.exe |
fc60e0ceb67207edd48ed4acbea5de98 | c:\Program Files (x86)\XTab\SupTab.dll |
3e29914113ec4b968ba5eb1f6d194a0a | c:\Program Files (x86)\XTab\msvcp110.dll |
4ba25d2cbe1587a841dcfb8c8c4a6ea6 | c:\Program Files (x86)\XTab\msvcr110.dll |
ff73e8efe2b7f0f134dda89694299ff5 | c:\Program Files (x86)\XTab\uninstall.exe |
99762975ae78b591fa6699cc460bb5f7 | c:\Program Files (x86)\YTAHelper\JSDriver\jsdrv.exe |
43901c75bcf54be31a8f15bae77a3865 | c:\Program Files (x86)\YTAHelper\JSDriver\jsdrv.sys |
e0e06dca0f07ebaba0545450d0f69ade | c:\Program Files (x86)\YTAHelper\YTAHelper.dll |
c254e02e1b6fe3b7f33426bebb9e6af2 | c:\Program Files (x86)\YTAHelper\YTAHelper.exe |
a3b46b4c5d373c51e6e489bb603dba9f | c:\Program Files (x86)\YTAHelper\YTAHelper64.dll |
76f41068f2fa82523736c58c6a6a27db | c:\Program Files (x86)\YouTube Accelerator\Res.dll |
973567b98cdfc147df4e60471d9df072 | c:\Program Files (x86)\YouTube Accelerator\UNWISE.EXE |
850e72f521667f04a1fa06bc92311b37 | c:\Program Files (x86)\YouTube Accelerator\Updater.exe |
29605c3fee628f62dea028a354425e3f | c:\Program Files (x86)\YouTube Accelerator\YTAHUninstall.exe |
4a53830f2e9fa95a7873dcebd0249e80 | c:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe |
46e2c40e8adae15d5e3a164e7b65fe40 | c:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe |
a77332904ccef3efc9dbb27bfc8dfd31 | c:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe |
3f4049d8bf040812a96680c5a6b377fd | c:\Program Files (x86)\YouTube Accelerator\cabex.dll |
f756379f1f0fbad6bcf53170aa804918 | c:\Program Files (x86)\YouTube Accelerator\engine.dll |
81baf300ca0dc9a3d557d0e84567b1a2 | c:\Program Files (x86)\YouTube Accelerator\helper.dll |
c014a1dddb4677f54f88efaaa492ddce | c:\Program Files (x86)\YouTube Accelerator\ipc.dll |
f6ac21939884df5c0201cdf1ead06b90 | c:\Program Files (x86)\YouTube Accelerator\lspinst.exe |
2c3a467735e2d937ce44034869b43231 | c:\Program Files (x86)\YouTube Accelerator\lspinst2.exe |
a082e5473b2a9a4d846ed7ddf637ac76 | c:\Program Files (x86)\YouTube Accelerator\sporder.dll |
5e2c0de2f0f15923154293dea89d196b | c:\Program Files (x86)\YouTube Accelerator\testlsp.exe |
39d9593e5c43d81fe9724fb0f7b16cc0 | c:\Program Files (x86)\YouTube Accelerator\unelevate.exe |
e0024c585767d4851de5e7331ac91ee5 | c:\Program Files (x86)\YouTube Accelerator\xmldb.dll |
c84cbb44c3aca460522eba9bd033cd62 | c:\Program Files (x86)\YouTube Accelerator\ytalsp.dll |
b4f8404b51e99487e56d8fa84a1e9470 | c:\Program Files (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe |
4078d3e9f16bd51b05b5b02c7ca96ad9 | c:\Program Files (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe |
88856f63e45c974b19a323e07a01b0a7 | c:\Program Files (x86)\iWebar\Uninstall.exe |
668eebc218927987ba2a477283807c6f | c:\Program Files (x86)\iWebar\utils.exe |
e3d3a05e0f184054036de52a1a67fd29 | c:\Program Files\Common Files\ShopperPro\spbia.exe |
cbb3b002a2aee773dd68372eb4608c2a | c:\Program Files\Common Files\ShopperPro\spbici32.dll |
2cad1194367243b4846957c0284c60e1 | c:\Program Files\Common Files\ShopperPro\spbici64.dll |
98e5ae670756522d1720d8ce5e9b2ed2 | c:\Program Files\Common Files\ShopperPro\spbii32.exe |
cb2a46d93fb166d882658145017a73ab | c:\Program Files\Common Files\ShopperPro\spbii64.exe |
25c8ef9478f078b849b63d0d199291d9 | c:\Program Files\Common Files\ShopperPro\spbiu.exe |
94cea41b991986be61facf8741db2a0a | c:\Program Files\Common Files\ShopperPro\spbiw.sys |
5471f0ae1b92c014ea32f0ec5c11f923 | c:\ProgramData\ShopperPro\ShopperPro.dll |
f6884feeba4191fb3e8fbb09e6d54b74 | c:\ProgramData\ShopperPro\ShopperPro64.dll |
f94557f8fd41731a3d180383a516fbe3 | c:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe |
e0e06dca0f07ebaba0545450d0f69ade | c:\ProgramData\YTAHelper\YTAHelper.dll |
a3b46b4c5d373c51e6e489bb603dba9f | c:\ProgramData\YTAHelper\YTAHelper64.dll |
5471f0ae1b92c014ea32f0ec5c11f923 | c:\Users\All Users\ShopperPro\ShopperPro.dll |
f6884feeba4191fb3e8fbb09e6d54b74 | c:\Users\All Users\ShopperPro\ShopperPro64.dll |
f94557f8fd41731a3d180383a516fbe3 | c:\Users\All Users\WindowsMangerProtect\ProtectWindowsManager.exe |
e0e06dca0f07ebaba0545450d0f69ade | c:\Users\All Users\YTAHelper\YTAHelper.dll |
a3b46b4c5d373c51e6e489bb603dba9f | c:\Users\All Users\YTAHelper\YTAHelper64.dll |
0f1a901cfbd8fc3f17ac2cdbd4875ae3 | c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe |
7fcbd6dc217380f995c83d1a7cc7f4c2 | c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe |
cb63b3e387caf96c3322aaa51ca36fce | c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe |
46539173b56ba94ccd9e702d4a2d8e30 | c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll |
ea0ca98847dc1a403ffec3be116e8b2f | c:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe |
ea0ca98847dc1a403ffec3be116e8b2f | c:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe |
f58984ad99ca43a9506569e447f64737 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp |
f58984ad99ca43a9506569e447f64737 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp |
f58984ad99ca43a9506569e447f64737 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp |
f58984ad99ca43a9506569e447f64737 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp |
d65611fbc4da8cea4e886076bec82d1e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe |
77cb93857d577104595f4671d9ede81d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe |
f6f9963a698423d4e2cd03e118e4a037 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe |
f2ee77e64e6d8944c1a440ab24d0dadb | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe |
f8076da03b6b36fa1ec0bd5a082d8d95 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe |
45960b40c1ecb75ed5549a80049879e1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx |
76f41068f2fa82523736c58c6a6a27db | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll |
29605c3fee628f62dea028a354425e3f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe |
6f4f8c2cb7e07436aa59a72c89fbaa4a | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe |
46e2c40e8adae15d5e3a164e7b65fe40 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe |
a77332904ccef3efc9dbb27bfc8dfd31 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe |
f756379f1f0fbad6bcf53170aa804918 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll |
81baf300ca0dc9a3d557d0e84567b1a2 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll |
c014a1dddb4677f54f88efaaa492ddce | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll |
f6ac21939884df5c0201cdf1ead06b90 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe |
2c3a467735e2d937ce44034869b43231 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe |
a082e5473b2a9a4d846ed7ddf637ac76 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll |
5e2c0de2f0f15923154293dea89d196b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe |
39d9593e5c43d81fe9724fb0f7b16cc0 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe |
850e72f521667f04a1fa06bc92311b37 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe |
e0024c585767d4851de5e7331ac91ee5 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll |
c84cbb44c3aca460522eba9bd033cd62 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll |
4a53830f2e9fa95a7873dcebd0249e80 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe |
ef7d1863f4980ab0c8bda142fee67f92 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe |
518879abe3170dabd172dfffcd165598 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe |
1bdf5e5015efcaa68b05cec0a79be484 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe |
3f4049d8bf040812a96680c5a6b377fd | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll |
6f7d9e111a17fab195efe0bbd3a0442d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll |
faa7f034b38e729a983965c04cc70fc1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll |
3a9ce8edf728d00a44376a75fe7b2aca | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll |
f0438a894f3a7e01a4aae8d1b5dd0289 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll |
ea0ca98847dc1a403ffec3be116e8b2f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe |
a08f4ec3efa60141725cf723b0b5e773 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe |
62d52491695400e8d14b30876f476933 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe |
39d9593e5c43d81fe9724fb0f7b16cc0 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\unelevate.exe |
69d2894206516657b7a06eeea5b917e5 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe |
3663b55452d8e814f62d6fae8eb32d65 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe |
f94557f8fd41731a3d180383a516fbe3 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe |
acf2f3ad315964ec2ed1ec4e61bd1f96 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe |
a5bfd6a87161d5dfa81cb5c2c6d29488 | c:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe |
45960b40c1ecb75ed5549a80049879e1 | c:\Windows\SysWOW64\AniGIF.ocx |
45960b40c1ecb75ed5549a80049879e1 | c:\Windows\System32\AniGIF.ocx |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
WerFault.exe:3548
WerFault.exe:2924
WerFault.exe:2488
Npjwb.exe:4764
YTAHelper.exe:2072
GLB4191.tmp:2908
ProtectWindowsManager.exe:3696
ProtectWindowsManager.exe:3648
GLJ41D1.tmp:3252
YouTubeAcceleratorService.exe:1348
YouTubeAcceleratorService.exe:1664
YouTubeAcceleratorService.exe:3648
ctmpua.exe:2288
ctmpua.exe:3432
ctmpua.exe:4816
ProtectService.exe:3944
ProtectService.exe:3960
XTab_Setup2121.exe:3784
jsdrv.exe:200
1F52.tmp:3644
wpm_v20.0.0.1953_0302.exe:3616
biclient.exe:2936
biclient.exe:1760
biclient.exe:3896
b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108
ins_yta.exe:1244
QQBrowser.exe:604
QQBrowser.exe:3556
DesktopMessenger.exe:3944
testlsp.exe:4468
powershell.exe:2340
powershell.exe:3496
powershell.exe:4512
powershell.exe:1684
powershell.exe:2388
powershell.exe:2708
setup.exe:3664
setup.exe:1756
HPNotify.exe:2060
cmdshell.exe:4028
ShopperPro.exe:4088
Ussgbdqdxxc.exe:4744
125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092
smt_istartsurf.exe:1836
ins_shopperpro.exe:3416
%original file name%.exe:2636
regsvr32.exe:2428
regsvr32.exe:3248
regsvr32.exe:3604
regsvr32.exe:3144
regsvr32.exe:1116
regsvr32.exe:1868
lspinst.exe:4328
lspinst.exe:3788
YTAHEL~1.EXE:796
DCytaiesmt_smtyc_setup.exe:3580
DCytaiesmt_smtyc_setup.exe:4188
DCytaiesmt_smtyc_setup.exe:3856
DCytaiesmt_smtyc_setup.exe:3976
DCytaiesmt_smtyc_setup.exe:3084
DCytaiesmt_smtyc_setup.exe:4260
spbiu.exe:3144
spbiu.exe:2612
wscript.exe:2072
6650.tmp:3864
INS_SENSE.EXE:4724
taskeng.exe:1420
ytaiesmt_smtyc_setup.exe:3588
INS_IWEBAR.EXE:4644 - Delete the original Application file.
- Delete or disinfect the following files created/modified by the Application:
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0dd4f150\Report.wer (239494 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0b6b27ab\Report.wer (239478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_09b1efab\Report.wer (241156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\5774 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\hmwmphigb.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA795.tmp (595233 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\b31cdfed-0f00-400c-94a9-14f605306e7a-4.dll (38103 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe (9147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\installer.js (5 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\365718 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\emfom.dll (23 bytes)
%Program Files% (x86)\SensePlus\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\wuogor.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\lutouoko.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\System.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\SensePlus\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\bakxdyd.dll (31241 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5_user.job (74 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\ipgeoapi_com[1].json (40 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5.job (74 bytes)
C:\ProgramData\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.xul (203 bytes)
C:\ProgramData\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
%Program Files% (x86)\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\install.rdf (884 bytes)
C:\ProgramData\YTAHelper\YTAHelper.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\chrome.manifest (111 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\yta_database1_0_0.json (2 bytes)
C:\ProgramData\YTAHelper\YTAHelper64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\YTAHelper_64.png (4 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000e.TMP (11493 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001a.TMP (13284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\blank.html (75 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000d.TMP (7861 bytes)
C:\Users\"%CurrentUserName%"\Desktop\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0006.TMP (115350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe (14357 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAuninstall.mht (9 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0011.TMP (34 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001f.TMP (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAIDN.LNG (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0001.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe (19739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe (27818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0004.TMP (16 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0009.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll (3048 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0016.TMP (6341 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0003.TMP (119 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0010.TMP (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\OK.gif (329 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
%Program Files% (x86)\YouTube Accelerator\cabex.dll (98 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000c.TMP (941 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLG49E0.tmp (93076 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0002.TMP (2104 bytes)
%Program Files% (x86)\YouTube Accelerator\temp.000 (51331 bytes)
%Program Files% (x86)\YouTube Accelerator\res\~GLH0014.TMP (75 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe (30222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll (3271 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000a.TMP (18940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll (6691 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000f.TMP (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0007.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe (20746 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll (34861 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll (7687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLC41C0.tmp (3791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLK43D5.tmp (1604 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe (3528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe (20848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLF49E1.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0005.TMP (65 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VADEU.LNG (18 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0012.TMP (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll (4155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page2.mht (1961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0015.TMP (4061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0000.TMP (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx (3175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page1.mht (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Cancel.gif (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe (2082 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAITA.LNG (1660 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe (146 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLJ41D1.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLM45D8.tmp (12 bytes)
C:\Windows\SysWOW64\temp.000 (3624 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000b.TMP (11493 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\~GLH0021.TMP (65 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\comtest.gif (1817 bytes)
%Program Files% (x86)\YouTube Accelerator\INSTALL.LOG (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\progbar.gif (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0020.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe (10592 bytes)
C:\ProgramData\WindowsMangerProtect\update\conf (5 bytes)
C:\Windows\SysWOW64\AniGIF.ocx (172 bytes)
%Program Files% (x86)\YouTube Accelerator\engine.dll (146 bytes)
%Program Files% (x86)\YouTube Accelerator\ipc.dll (286 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (60 bytes)
%Program Files% (x86)\YouTube Accelerator\xmldb.dll (192 bytes)
C:\Windows\Temp\SBCC0F0.tmp (98 bytes)
C:\Windows\Temp\SBCE919.tmp (44 bytes)
C:\Windows\Temp\SBCFD94.tmp (51193 bytes)
C:\Windows\Temp\SBC72CE.tmp (98 bytes)
%Program Files% (x86)\YouTube Accelerator\helper.dll (200 bytes)
C:\Windows\Temp\SBC14AD.tmp (547 bytes)
C:\Windows\Temp\SBCBBC1.tmp (44 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log (591 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log (261752 bytes)
C:\ProgramData\TEMP:56E2E879 (240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[4].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[3].gif (35 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (536 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (876 bytes)
C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (49 bytes)
%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (17941 bytes)
%Program Files% (x86)\XTab\conf (1594 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1794 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\ver.txt (47 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (4 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5468 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1028.xpi (15 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn143C.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (15946 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.bak_tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\SMALLTEST[1].htm (70 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9171.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log_tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9148.tmp (682 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log_tmp (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90D6.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk901F.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log_tmp (300 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90A0.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916D.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90C5.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log_tmp (3 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (408785 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9136.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B1.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log_tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk907E.tmp (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B3.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log_tmp (758 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log_tmp (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9159.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log_tmp (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk915B.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916F.tmp (1 bytes)
C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\inetc.dll (44 bytes)
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (3568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IZSMH2G7.txt (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\vlc_48[1].png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A0GU0ZSM.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\C7DICHCP.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0BISIEEE.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ga[1].js (25835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9GM47V2A.txt (116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[1].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[1].htm (4339 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-istartsurf[1].htm (1054 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\247cff67b7ccf545bc359dea5d4fdcca[1].htm (35176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XBFPV72L.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe (43024 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VWCSVYJT.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Z4XAPYNG.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CAECMN2Q.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VSU9UM32.txt (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9WGP90AI.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L7G4BE9A.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[1].htm (1059 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Y2YQ0ZN9.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.7 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.4 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.5 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.2 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.3 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.0 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.1 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BFIYZCSM.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\40da6fd4d86af64fa44c08b317ad86e7[1].htm (36028 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.6 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8IZK4DIW.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XRSM1SYU.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[5].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyoLightGrayStripesBG[1].jpg (439 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0ZXSMBUT.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\G4EMRU6A.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2YAKCMQE.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\11H1CVWK.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F8VDJPMY.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MCEUOC87.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ARAVBC6Q.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XT3O6SY5.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\5ee27ba0e055bb4684b8648858d31d9a[1].htm (34716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FFA3HBHT.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BDVF95Q7.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3KR1O1W4.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\N3J3D9ZZ.txt (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[2].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IWHOVB19.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[2].png (1277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\8b685dcf684f214ea8b00dc2c916e842[1].htm (34823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TE7T15RC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FNHOZK1G.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UEDY9YTQ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\32X7O7GH.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Q8XWSLCR.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\YK3867F1.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\eula[1].htm (1058 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0982L053.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8SWC09PC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[2].htm (1061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TZJ60FG3.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[2].htm (4391 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\1K9S4IKF.txt (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2I762JJ4.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LEX2PBNZ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L4B69UQE.txt (129 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\334.js (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\dd664ae6f5b9fff9189830efc4277c1f.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\e8bf7602a41c0cdd14ad3540f08069cf.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\d0ac5e3ab61d9c9d036ca53d47b29da9.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\cf410972f8f7d9ce4b77ee942f1466ad.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\e0aa67c698a956adcab1a009989465d9.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\a212c1cc5036af14d61114d057025057.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d7a9ef674b92bd799ec4bb2c4ad621ef.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\9c5116558c43d87c3a32571c768872c8.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\be649c4e3a3e93d8a40243a4b8fc8344.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\b7b54f267e564c72cde2760d1dbd8ba2.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\e5f493e4f10da2ac3e336eaebbe86097.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\b4bb02edd36de53e69ba6b93fbbaf546.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d3f76309e3ba67b37724cd13c2a877ab.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\0177f7adb3a7120281e3dc4ad27672bd.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\192.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\7bded2a2506031aee5561ee8095bfcda.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\cd42e843c315396a255ec90674730514.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\337.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\281.js (461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\f533812f59e22810ff3bc56548ce46a5.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\527d5f3becaec0408e1ef15ac8f13bb8.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\491bb26de8d74c88f4ef82985489e2a7.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\f15d508ac04f84271fdf78b6cd665aeb.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\390.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\162678864fe0dce10da8913dbd7ae511.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome.manifest (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\ef5f49cce70bb46b02b28579a3bd464b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\3d33016b291b0f7bcfe763a02760e8c7.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\skin.css (949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\a4216ae64b11870b51e4b6ddf906205d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\fc95591e3359f30c3025d78dffef3f08.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\23ee7c2ff74dde91e4fef185b27fc94c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\1d8df16ea3f4be636f5817d37d006df5.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\userCode\extension.js (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\193.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\defaults\preferences\prefs.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\57897893dc3d4deec228a28f1d8f10b2.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\e38361e1c88892cbd641c1625e826699.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\0d3c7da494fcbab7f37c0e38eed8654c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\d599fcb25ec9c785d2c1d66a72962be4.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\83bbdd4a0fff63d909d0a0d0e0e6bd38.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\0f728b47f95c6ce7ef2de6868fd3ac67.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\3c15b1a00edb4ad7a7b6ea0c2f029e60.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\356.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\b23a8e0fe71c1dea24c69cf3bfa392b4.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\c0f52d7d6baeb5125934e7f4ae3aaaff.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\7fb62ef1207bd6500db94456a32fafff.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\34b8f82350c85955993d9f02d0941792.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\api\b33ac672edd3e152a7f18f3bbccca9ef.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\a6bfe546fc476bf6efa27bce866a3a5f.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\core\a3dd82821479da5accbcad4543805ae5.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com\chrome\content\447b6d228c0833ca1c3560e0acb7ff93.js (659 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLB4191.tmp (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\scrollbar.bmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code6.jpg (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5D5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\remoterequest.js (2 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe (14022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml (553 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5C5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\vi\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (148 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1GTL8DZTBO258N0GHLR0.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7O3W63F2E3I22BLN6TOW.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D34R02L3N7OKWC8P2R3J.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XZNWAHWP4KMSA08GUC3P.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZG7QQZ7AW1JD8CDIB6CZ.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L0DHHN7AY5J5O0FAV13K.temp (196 bytes)
%Program Files%\Common Files\ShopperPro\spbii64.exe (17848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\MoreInfo.dll (15 bytes)
%Program Files%\Common Files\ShopperPro\spbia.exe (11344 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.exe (33633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll (11659 bytes)
%Program Files%\Common Files\ShopperPro\spbiw.sys (1552 bytes)
%Program Files%\Common Files\ShopperPro\spbii32.exe (13368 bytes)
%Program Files% (x86)\ShopperPro\Updater.exe (25112 bytes)
%Program Files%\Common Files\ShopperPro\spbiu.exe (69777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\jsdrv.exe (100669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn697C.tmp (360871 bytes)
%Program Files% (x86)\ShopperPro\FireFox\chrome.manifest (113 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\System.dll (23 bytes)
%Program Files%\Common Files\ShopperPro\spbici32.dll (37025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (100378 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.dll (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\ShopperPro\FireFox\install.rdf (828 bytes)
%Program Files%\Common Files\ShopperPro\spbici64.dll (48241 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.json (11 bytes)
%Program Files% (x86)\ShopperPro\SPRemove.exe (20416 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro64.dll (18424 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.ej (14 bytes)
%Program Files% (x86)\ShopperPro\manifest.json (595 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_60.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_65.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c5.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a5.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f349.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2935.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f648.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f429.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f637.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-active.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f682.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a3.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_72.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_62.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23eb.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f699.png (691 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute.png (445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f453.png (867 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68e.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f1.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f472.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f645.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2601.png (626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23e9.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44c.png (812 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f518.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f237.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40d.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23-20e3.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b9.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f476.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f501.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f608.png (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f511.png (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a3.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2139.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f301.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe (21399 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40b.png (910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f521.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus-active.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68b.png (681 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a7.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f308.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f406.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ac.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ec.png (773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cb.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50a.png (708 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264d.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\30-20e3.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25c0.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE-GRAPHICS (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_02.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a0.png (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a9.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_20.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f506.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_49.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7.png (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4af.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f196.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f564.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f631.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_78.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f485.png (602 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fc.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53b.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ba.png (517 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none-blue.png (755 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f602.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f539.png (308 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f380.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f558.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31b.png (826 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55b.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f416.png (569 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21a9.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2734.png (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\send_message.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_44.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264b.png (701 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_56.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fe.png (472 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f6.png (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f335.png (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274e.png (442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2665.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21aa.png (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f364.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_55.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fb.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2648.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f400.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f561.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f303.png (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f425.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f694.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d3.png (590 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2716.png (443 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f459.png (978 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f508.png (293 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2615.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60f.png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fb.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f467.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f427.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f487.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52e.png (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44e.png (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f305.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40a.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f341.png (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f615.png (623 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2194.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f373.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31d.png (878 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f5.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f194.png (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f629.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a8.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f497.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f310.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f626.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2049.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f408.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f343.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\260e.png (963 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b4.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c1.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f451.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b50.png (552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61b.png (848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f523.png (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f647.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f517.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_57.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3f0.png (511 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4be.png (359 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb-1f1f7.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f236.png (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_11.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f316.png (981 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_73.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a9.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\35-20e3.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f352.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\libs.js (4316 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c5.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49c.png (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69f.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f525.png (991 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f414.png (935 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f613.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f515.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c9.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64d.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-active.png (410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c9.png (699 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_71.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f693.png (743 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2796.png (184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2753.png (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63c.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f442.png (928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69d.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f371.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f620.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e4.png (495 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f004.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f498.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f376.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62f.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f684.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f493.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_38.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2693.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\default_photo.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a4.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a2.png (767 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68f.png (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49d.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit-active.png (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f457.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31f.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_59.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f407.png (908 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ab.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f624.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45c.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f423.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f509.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a6.png (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f354.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f384.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f567.png (629 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7-1f1fa.png (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b1.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f649.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fc.png (659 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ac.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45e.png (639 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ed.png (420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60a.png (839 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f379.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f606.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4de.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b6.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f535.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25aa.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5ff.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\24c2.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f402.png (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52b.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a2.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f553.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f234.png (526 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_25.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2795.png (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3eb.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f504.png (643 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_37.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e6.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48d.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f5.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_47.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36b.png (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a9.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c4.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f696.png (986 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50c.png (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f2.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f340.png (739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_26.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f500.png (542 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f21a.png (596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fd.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f455.png (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34f.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f348.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2195.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f519.png (730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f304.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25b6.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f356.png (916 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_28.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f2.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c3.png (449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27bf.png (725 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\263a.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\36-20e3.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f412.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61f.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f639.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f690.png (774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ba.png (789 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f681.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f198.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f382.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_14.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2708.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ea.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62a.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52f.png (820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55a.png (889 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f446.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33b.png (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e9.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll (8406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e0.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f410.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_77.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f495.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f435.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47b.png (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b8.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\261d.png (585 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\settings.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_69.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b4.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55c.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2714.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f502.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c7.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61d.png (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f622.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ae.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51b.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2649.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ea.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a1.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f390.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c5.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42a.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f625.png (957 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\main.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_30.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f560.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53a.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ca.png (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e8.png (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_41.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6aa.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\203c.png (210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_13.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51d.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31a.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-out.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea-1f1f8.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42c.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f4.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec-1f1e7.png (747 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f195.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60b.png (931 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f300.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2705.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb.png (362 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f470.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f358.png (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\33-20e3.png (554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35e.png (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-close.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ac.png (556 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f342.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_53.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f503.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f437.png (958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f202.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b05.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ed.png (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49f.png (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f338.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\index.html (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f566.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2733.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53c.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2728.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f418.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f491.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f344.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4db.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_16.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fd.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2652.png (430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49b.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_32.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_22.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c7.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f636.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e7.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34b.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2663.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50e.png (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f232.png (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f484.png (574 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f555.png (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d2.png (901 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_43.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50b.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f346.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f551.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f529.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ab.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51f.png (619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231b.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f452.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fc.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_67.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_35.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64e.png (772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\ae.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2755.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f623.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_19.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f557.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f431.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d5.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_76.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f482.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f357.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f4.png (603 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31c.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17e.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f632.png (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b0.png (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f0cf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e6.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ab.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e2.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f685.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_54.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f355.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_34.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_63.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f351.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f251.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c4.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f462.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_03.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f687.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f426.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f627.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37c.png (621 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f413.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ee.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2712.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\34-20e3.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b06.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f605.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48b.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f319.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ef.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f403.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47d.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\32-20e3.png (518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f448.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_08.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f640.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f530.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f363.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f454.png (992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fe.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ba.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50f.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f680.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f314.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61e.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\37-20e3.png (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270b.png (496 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f450.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f527.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3299.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a6.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a0.png (833 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f309.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e2.png (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27b0.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ee.png (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bb.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f538.png (307 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f393.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bf.png (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f374.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e7.png (656 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f405.png (926 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60e.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f460.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f638.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4aa.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47f.png (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_80.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f633.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2744.png (698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f8.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit.png (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f479.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_66.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f520.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2122.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f365.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2934.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e3.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f171.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36a.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa.png (451 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f683.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f490.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f522.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f0.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41c.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c0.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1b.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264f.png (462 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f439.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f510.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38f.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2754.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264c.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ff.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f607.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f528.png (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f18e.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b8.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_79.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b0.png (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25ab.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f466.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38d.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3aa.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f603.png (850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26be.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d9.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61a.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f440.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69b.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fa.png (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2660.png (500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4eb.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f562.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f192.png (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main_test.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\hatter.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f19a.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2600.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4df.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a7.png (337 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f616.png (885 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f359.png (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f367.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f197.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f239.png (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f514.png (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f312.png (956 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_64.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f692.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f3.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48e.png (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f475.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b7.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f532.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_33.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c3.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c6.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37a.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f191.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f494.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f315.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f618.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_15.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f334.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c2.png (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f444.png (766 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30e.png (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fc.png (539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270c.png (685 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f604.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63d.png (968 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f370.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f695.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fd.png (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a7.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea.png (378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26d4.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\message.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f306.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f507.png (882 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b0.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f609.png (788 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f307.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a2.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1c.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f619.png (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8.png (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44d.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef-1f1f5.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ea.png (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f391.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f458.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267f.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bd.png (616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2651.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f443.png (857 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f688.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f534.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f461.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ae.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2197.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e3.png (389 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45a.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f409.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bb.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3297.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f332.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52a.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264e.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f23a.png (549 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68c.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43e.png (573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48c.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c1.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f438.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f3.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f415.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_50.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_45.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45f.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ce.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f1.png (251 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\303d.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f353.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ef.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus-active.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f6.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_17.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0-1f1f7.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_04.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f464.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f302.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52c.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f317.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f697.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f449.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a5.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f7.png (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2797.png (284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f250.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b6.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55e.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2198.png (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d4.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e5.png (315 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f377.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c0.png (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f401.png (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f488.png (492 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68d.png (514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f492.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f516.png (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f383.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b9.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f526.png (589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f536.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f193.png (528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f411.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f233.png (533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f3.png (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f422.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51a.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f330.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f478.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_75.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f385.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f360.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f477.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_31.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2614.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f691.png (791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2199.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f433.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f480.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f235.png (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_12.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_24.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f378.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69a.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3030.png (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31e.png (902 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b2.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f22f.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9-1f1ea.png (267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fb.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c6.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f552.png (702 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45d.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267b.png (951 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ec.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49e.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42b.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f524.png (608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fa.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f686.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f468.png (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bb.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2747.png (473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f612.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f559.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_58.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_18.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b5.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f471.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e4.png (494 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62b.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d8.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\jquery.min.js (4267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fb.png (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47e.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cc.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f420.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c8.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f698.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ce.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f387.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b5.png (437 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f617.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f366.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f238.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f614.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f550.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cd.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f9.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa-1f1f8.png (310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6af.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f611.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f362.png (780 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f456.png (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a4.png (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c0.png (781 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fe.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f428.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50d.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\Data\Config.xml (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f434.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f199.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f419.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f347.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a0.png (655 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoDB13.tmp\nsisFirewall.dll (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_68.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c2.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f646.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\a9.png (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\e50a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d6.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2653.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ec.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ea.png (551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27a1.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f339.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f445.png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f473.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d1.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c1.png (223 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34e.png (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f489.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f311.png (712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f170.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f486.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e9.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ae.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f531.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2650.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f512.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ad.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_42.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-icon.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2196.png (356 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_46.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f556.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264a.png (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_52.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f481.png (972 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bc.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f331.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f350.png (595 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a8.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55f.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_21.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49a.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35d.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f635.png (770 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bd.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_10.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cf.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f333.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274c.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f345.png (881 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f337.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee.png (302 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270f.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8-1f1f3.png (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43d.png (466 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f447.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4da.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e8.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e1.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26aa.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_05.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_51.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f313.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f424.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_40.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_27.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f381.png (477 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_29.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17f.png (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2757.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270a.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2611.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f465.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_09.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a5.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b8.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62e.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f3.png (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b7.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2764.png (513 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f537.png (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d0.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d7.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f634.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f392.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f386.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2668.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f5.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_61.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f533.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f389.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c4.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f372.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log.png (670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_23.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f496.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bf.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ab.png (735 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e0.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f483.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_39.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ca.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f554.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b07.png (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef.png (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b7.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f621.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f388.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2666.png (407 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f369.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f463.png (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f565.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2709.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c8.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2702.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37b.png (875 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f436.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e5.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f201.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30a.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f689.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a1.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f375.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_74.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b3.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b1.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\31-20e3.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f318.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ed.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3be.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f432.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f368.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_70.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231a.png (754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f601.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f474.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64b.png (945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f600.png (815 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69e.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62c.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f513.png (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f417.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f630.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_01.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f499.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f430.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53d.png (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f421.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bc.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\38-20e3.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55d.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a6.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b55.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48a.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\39-20e3.png (527 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a1.png (738 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f563.png (787 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f469.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main.html (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f610.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_36.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f9.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a8.png (555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f505.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_06.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b1.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f404.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_07.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e7.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f628.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f361.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6be.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee-1f1f9.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f320.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3af.png (1 bytes)
C:\ProgramData\ShopperPro\config.json (487 bytes)
C:\ProgramData\ShopperPro\ShopperPro.dll (2321 bytes)
%Program Files% (x86)\ShopperPro\config.json (1254 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\database1_0_0.ej (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\config.json (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\database1_0_0.json (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\install.rdf (828 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (22786 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\chrome.manifest (113 bytes)
C:\ProgramData\ShopperPro\database1_0_0.ej (14 bytes)
C:\ProgramData\ShopperPro\ShopperPro64.dll (3361 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\config.json (767 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\installer.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\System.dll (808 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\125b6778-a7b3-42de-b39a-7082dbd6c683-4.dll (38103 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\lutouoko.dll (13 bytes)
%Program Files% (x86)\iWebar\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\wuogor.dll (8 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\133 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\340584 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA60F.tmp (601872 bytes)
%Program Files% (x86)\iWebar\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\hmwmphigb.dll (14 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\bakxdyd.dll (31241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe (9147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\08698225a6048f6e460097f16e02e704.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\71d4611ff095ba11d5170e66cbcb1f99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\e495468dafb76cfdaf72e5fa8d28a349.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\64e8d4e87627d5c1948a0bcef5d8bddf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\27cf8aa127aac261d305fe9089529830.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins.json (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\3d80de7fb266005117ceaafcc80fdce9.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\cd81bdfb69d0d25218ce67718be563af.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\385.js (805 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\1780bb19c407d25583ce46e040481d99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\85ea74e5af2c1af63fce579c5ab50f9f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome.manifest (622 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\b25ebd4eb2e834fb9cccdc10bb148863.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\fbbdb0f74062a849bda57f6fe11fcf32.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\f769131cae2813ce580e9e94c4e96f9c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\e7c458df68b2cf4608fc221688ae08ca.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\ebf33cc6f061080861c3e83c583756dc.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\290.js (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\fd27a2fb33b55a5f18ab50f4ba936cd4.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\0bec9e6b7afcc4c4516f35378da8e8f9.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\af5a57f759bd1cf2e294bcfccaf931fb.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\686b2fd98f5ea3e56eaaef1af8491492.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\3e381797919b94e2bb615148f7e47028.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\56d8099de7f917a05ebc946e4ff23a90.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\ffb8884740ec4a25e7613eb834ca1913.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\79f3c8aab387a44396d3dacdadf581ca.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\0034b573374c522556781d729432c887.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\525208f03fe2d8bef8b7bb6b8ef4fce1.js (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\287fabae0a36fcfbc8d77dcdaaaad216.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\8c01eaa93fd0bc0662848c840cae8041.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\b790483a12fb1b0b6cd3863184729b25.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\633a77e2ae00bb6d6d2e3abbbbe03912.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\269585125e1cb71c5dfc6f15d18aba48.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\userCode\extension.js (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\01b19a2e32d1a93bc2187a399e31eb51.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\edc254d662db048aede80d03ff95a848.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\5647e30e6af0add68690b1d263429c43.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\eca39140ee956f1f06527fb9ad62e501.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\b7c3eebfc78cf0199ff6ad83ec7241bf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\e83df05e1cf9ce178c9205b266814e5e.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\69a7dc8ac94d415bb9c821991dc88c28.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\skin.css (899 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\29d9a644a93fb36aff415aeea5c35684.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\api\8c47021875b6fd49edb959b301d1c49a.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\437c9512ae40f6cf2212e22d83fc0762.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\6aacfc15412fb43d4bcd12a55d84a7ac.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\core\1358a6937d07734cf85a79aaec52d489.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\14fef81ee28d4335a493c2d@6383fd42ff9b4872bccb5b.com\chrome\content\a48b2e165ded142e4fd41c767365d414.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowser.exe (5199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\sweetsearch!1.0.0.1031.xpi (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg2.zip (259958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\conf (79 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\quick_searchff#5.4.10.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\UninstallManager.exe (60186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg1.zip (172558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup1.exe (144456 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61CF.tmp (155198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup.exe (1606835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\D1958.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe (8409 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nshCF02.tmp (7098 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\config.ini (113 bytes)
%Program Files% (x86)\YouTube Accelerator\instlsp.log (295 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\YTAHelper_64.png (4 bytes)
%Program Files% (x86)\YTAHelper\FireFox\chrome.manifest (111 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.exe (32784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\YTAHelper\FireFox\install.rdf (884 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\jsdrv.exe (100669 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.exe (100378 bytes)
C:\Users\Public\Documents\YTAHelper\JsDriver\Config.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B02.tmp (118586 bytes)
%Program Files% (x86)\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.dll (13584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll (11667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\System.dll (23 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper64.dll (16424 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\MoreInfo.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe (7726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe (48375 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe (31105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe (18619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe (7726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe (50552 bytes)
C:\ProgramData\ShopperPro\spbihe.js (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Sgfzhi.tmp (390774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Npjwb.exe (1335155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\pvgykk.dll (2121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\4D90EAE405E9E2FF (34773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\D1989.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe (379403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3247.tmp (35697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\pvgykk.dll (2121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Ussgbdqdxxc.exe (1340508 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Rtmrbzobbxy.tmp (392398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\gzxaaspvo.dll (30 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DesktopMessenger" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 2.0.0.0
File Description: Powered by BetterInstaller
Comments:
Language: English (United States)
Company Name: Product Name: Product Version: Legal Copyright: Legal Trademarks: Original Filename: Internal Name: File Version: 2.0.0.0File Description: Powered by BetterInstallerComments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 28860 | 29184 | 4.36907 | 33e8227bf6edbf3997e3d0895494668e |
.data | 36864 | 140 | 512 | 0.818223 | 1b0351714f371c0ba066871d4e504b00 |
.rdata | 40960 | 3196 | 3584 | 3.54441 | 88a268b1fac88e9fad865c68cf3abce2 |
.bss | 45056 | 110088 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 155648 | 4932 | 5120 | 3.53424 | 11c816edc4ef9cc4aa5511f8a707232b |
.ndata | 163840 | 32768 | 1024 | 0 | 0f343b0931126a20f133d67c2b018a3b |
.rsrc | 196608 | 17800 | 17920 | 3.94947 | 910d365c8572b40bfb8141bb8ae1ba88 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 3664
7f6d030a23f210ff0f767468fe3edd48
9fe8b39c75f8ed0d56094fe69fbf2c3f
0f8cfe6c36d70739199896a29a9ab59e
9c25ad5c86c1bf46d4564075b019e71c
9c129a294d7cc0fe9ed53d890dbde85f
b9569d981dd7f0516c10295bcb118f65
f3a31b785aef97068400d0987e8505fa
bbef8102d6345f6e5aea4567f3493da7
5423049c0be0b64dd47e76f4552912c0
e994aa2020aa429e7ed46bde26100014
90351671e65f1bb12916d1e9ec86ed49
13df569a80b0b685ba250ad7617fe738
a16c30b5aa236dc78beea2d35406b2b7
b3fa5976434ce1e51a1bd370e2aefd3c
7f9d59c48734f851495f71f0c539537b
22754d84b6a8863fdb8bcc5c56c849cb
58fe62f415a645bea095e193a1676101
2a2a5c35d16c851fbe31471dc439b39c
92c551fd1abfe685fd18911e9ab08526
0d213295b19e20e1fecc37345c3e009b
e7b769fcb3292ae349d046038146b08d
a6fc7dda6bdd315dfd5980ac76fb22d0
ba8a944ac777b66e2f8831e41c48a17e
52f55df57abbba5785a9fc223655676d
43e6206ab7ba8f798441f29b86ac7746
Network Activity
URLs
URL | IP |
---|---|
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/247cff67b7ccf545bc359dea5d4fdcca?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4 | |
hxxp://d110jf50ovcr9h.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/images/Tokyo/tokyo_sprite_full.png | |
hxxp://installer.betterinstaller.com/installer/ajax | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/istartsurf/eula-istartsurf.html | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/speedbit/eula-youtubeaccelerator.html | |
hxxp://www-google-analytics.l.google.com/ga.js | |
hxxp://www.girlliuxiaowei.com/home/smt_istartsurf.exe | |
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=891678463&utmhn=bi.bisrv.com&utmhid=446800634&utmr=-&utmp=Installer_Init&utmht=1429596636339&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1909607576&utmredir=1&utmu=qhCAAAAAAAABAAAAAAAAAAAE~ | |
hxxp://d2z5psu5fxw71b.cloudfront.net/sponsored/swiftrecord/eula-swiftrecord.html | |
hxxp://d2z5psu5fxw71b.cloudfront.net/affiliates/filesfrog/eula.html | |
hxxp://mirror.frogdownload.com/software_files/vlc/vlc_48.png | |
hxxp://a1726.d.akamai.net/sd?is=sm | |
hxxp://d2otsfra4otprh.cloudfront.net/mag/ytaiesmt_smtyc_setup.exe | |
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/pc_messenger_for_android/default/setup.exe | |
hxxp://mirror.frogdownload.com/software_files/vlc/2_0_2/vlc-2.0.2-win32.exe | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&display_height=50&0.9153985493271659 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&0.8522578642015259 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=2&index_in_screen=1&index_in_session=2&display_height=170&0.9592077379969404 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=2&index_in_screen=1&index_in_session=2&0.8782558746692214 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=3&index_in_screen=1&index_in_session=3&display_height=80&0.1334864874963183 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=3&index_in_screen=1&index_in_session=3&0.8799863343719936 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=4&index_in_screen=1&index_in_session=4&display_height=195&0.7944516260210912 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=4&index_in_screen=1&index_in_session=4&0.5368077775084833 | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action1=xa.geoip&action2=visit&action3=smt.visit.istartsurf&update1=ref,smt&update2=identifier,installer&update3=version,6.6.86.1606&update4=nation,us&update5=language,en | |
hxxp://dqoup4b5zs0bi.cloudfront.net/infv5/index/3428/bnd | |
hxxp://dlrkbt247pbk6.cloudfront.net/3428_3b67a5ef5d450c1556c543c6323981d9/1.pak | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&0.8875708268396014 | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=2&utmn=1803266286&utmhn=bi.bisrv.com&utmhid=446800634&utmr=-&utmp=Offer_Accepted&utmht=1429596646250&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.regok | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.ds | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.hp | |
hxxp://log.very911.com/install.gif?bundle=istartsurf&ptid=smt&uid=535559167_198339_B48A115F | |
hxxp://download.dynect.mozilla.net/?product=firefox-34.0.5-complete&os=win&lang=en-US | |
hxxp://a1284.g.akamai.net/pub/firefox/releases/34.0.5/update/win32/en-US/firefox-34.0.5.complete.mar | |
hxxp://www.google.com/ | |
hxxp://www.google.com.ua/?gfe_rd=cr&ei=6-k1VfOpLYOu8we8uoDwBA | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.nt.ff.tab | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.finish | |
hxxp://dqoup4b5zs0bi.cloudfront.net/infv5/index/3428/3rd | |
hxxp://dqoup4b5zs0bi.cloudfront.net/3428_92a5d683c188790231b1aa2af09de41e/2.pak | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.wpm | |
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action=visit.heartbeat.wpmvt&update3=version,20.0.0.1953 | |
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action=visit.heartbeat.wpmvt | |
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.ient | |
hxxp://xa.xingcloud.com/v4/sof-ient/535559167_198339_B48A115F?action0=xa.geoip&action2=visit&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,2.8.8.2102&update4=chptid,smt | |
hxxp://xa.xingcloud.com/v4/sof-ient/535559167_198339_B48A115F?action1=install.smt | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=3&utmn=692550647&utmhn=bi.bisrv.com&utme=8(sp_slug)9(istartsurf)&utmhid=446800634&utmr=-&utmp=Install_Complete&utmht=1429596666051&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qxCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/8b685dcf684f214ea8b00dc2c916e842?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4 | |
hxxp://up.soft365.com/Fan/rebirth?uid=535559167_198339_B48A115F&ptid=smt&ver=4.0.1.1716&dname=istartsurf | |
hxxp://xa.xingcloud.com/v4/searchprotect/535559167_198339_B48A115F?action=visit.heartbeat.smt&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,4.0.1.2105 | |
hxxp://xa.xingcloud.com/v4/searchprotect/535559167_198339_B48A115F?action0=xa.geoip&action1=visit&action2=install | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg | |
hxxp://d110jf50ovcr9h.cloudfront.net/images/Tokyo/tokyo_sprite_full.png | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/swiftrecord/eula-swiftrecord.html | |
hxxp://d110jf50ovcr9h.cloudfront.net/affiliates/filesfrog/eula.html | |
hxxp://d1h8rlkib3jo2q.cloudfront.net/affiliates/filesfrog/eula.html | |
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=1665638849&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Installer_Init&utmht=1429596667810&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1063059989&utmredir=1&utmu=qhCAAAAAAAABAAAAAAAAAAAE~ | |
hxxp://d2z5psu5fxw71b.cloudfront.net/sponsored/speedbit/eula-youtubeaccelerator.html | |
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action0=xa.geoip&action1=visit&action2=install&update0=ref,wpmvt&update1=nation,us&update2=language,en | |
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/nerocrossrider/appshat_generic.exe | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&display_height=170&0.43209955227997554 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.8902343800499003 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&display_height=80&0.5999672903135584 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&0.3944050553270405 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=3&index_in_screen=1&index_in_session=3&display_height=195&0.7397356789101737 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=3&index_in_screen=1&index_in_session=3&0.6216911406062087 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=4&index_in_screen=1&index_in_session=4&display_height=90&0.9088924169240506 | |
hxxp://www.theviilage.com/windowspm/up?ptid=wpmvt&sid=WindowsMangerProtect&ln=en_us&ver=20.0.0.1953&uid=&upv= | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=4&index_in_screen=1&index_in_session=4&0.09920990337743929 | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.6710044187465542 | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=2&utmn=387526838&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Offer_Accepted&utmht=1429596733521&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://theswiftrecord.com/mg?alpha=dEExCndCCQVYMzd5HiB4dQViB3d0BzN7f3EqRzxidWNwFHYjPix4bwMFMH0gXF8pXQ4CQld+RmszYCcXZ0kLBwUMFi1FfCRlQzZrVi9y | |
hxxp://theswiftrecord.com/fp?alpha=fTYJCFZWOBozTQkRJiJZfHJaBVZ9ah95F1o3SBcKeiIECBB/RwENPQsAHAl0PCgIXylgRBF/EnxBXiBIZWFwflUbQjgXJCwbaRtAWGJyBUk+NwpECGouXnxTA1gJSkN4YkgcUi1MAHc6enEVEwQnJQRcKXxIZw4JYDBYVlYqICsFRm5zGlYFMW8ZHQdVJndmRG4qH15be2JUZFMKSA0fVypuRR1XOEsJbj52ZEcMF3InHA9+bRRlHEY8PTgMHy09LEAwd2EYTA5zNkBaWlR1bxowSzxdG15mMVx1VwteC0hcKiQJEzRxFF0hfzxkYVtRdH5YCGgTDGQDF2U3Wm5WPSYsXC1iNEMUVFhvGRByCTEOe1JKLw5Ee2IwWGlXC14COEgIYCdqJypmBHNqVFpP | |
hxxp://theswiftrecord.com/ii?alpha=ATNRByFYY01YMmRBfi0uAHcCCiEBb10vLDQARRZkU28bQGQUQjI2FlU1XWMlDnoWBktYA2pHGkk4Als2AXgtA0ltMA0bI1VvRAJiJHAqKHIsbAoWfFJnEjh2elUgQElzawpiOVxLU3JSBwc4B20sIyBaQANASXBra0YDLzd1EDtaEWI1BV0qUm9GB2p9NzlrIl0vU1N9FDYSL3QhLxEaMF43RVF4Cw0EZxtWJz9DLzsoVVJDAVs2B2MdKwFdMgZnO1ACME1MSCo1DFFdNzl6ZzwuJHYJAiJQdRhrJ3NAARx5ET1OV3EWQiwoHEEuDl4mGTUzCwNVGnhGcxolYBloUjNuRA4wb0JHNy5/V0QhP3B+Nn1TJUdQYxYoA30hdk0QEH9BO15ENBQeAipfCWFMH3BLehcODF8SMnA9SmlZGG8UfkhZDitkRwtEFD4DVzdkJXkvLkc5CVQ9Gn8SKmd6VFNZPAdgG0x1WU9Re0oDe0gHel8kXlJcC0I7EyNCYQ0tZlgleBEDMGxNFlMuADlzYilsejouN1w4KAwBYkB2RwoaAgdoG3JrbGMFDQRhKVozCUQhATU3Qj5yJkYVF0R2W0tDUSB0VAJ5cUgWMQUxFA91a3kqaFYhNWoCVyY= | |
hxxp://theswiftrecord.com/if?alpha=ATNRByERDF14DT1Kfi0uAHcCCiEBb10vLDQARRZkU28bQGQUQjI2FlU1XWMlDnoWBktYA2pHGkk4Als2AXgtA0ltMA0bI1VvRAJiJHAqKHIsbAoWfFJnEjh2elUgQElzawpiOVxLU3JSBwc4B20sIyBaQANASXBra0YDLzd1EDtSBGJSS057DBYZWzAGans1QAR2EwUlAWtCdiVhG15HPQZnExEgSk1Qb08HdE0CcEtxAQQvQxoyXDZVdVwEdVFweVIBHXNMfSpRb1kCanQxJ2k9QilSVHwBYVEkXSgOXiBeET1OVW0UGlwWFl0lEkYzQTVSVkBTHHsTPF5zVRk6eT9+RQgsbkVfNzc2GVYrOnA3bjMjbQgAKFR1XSR/JgFDOy0XJFhTZw0QD2FFE3dTAG5aI1RTTUIQfUM6TmAQG2ZXPT0NR24vEw14EzMWXCNwRnk+fxpsD0ZlcmhdP3QjTTABbEM3TggyCglcdVldcw0MOUt0El9UAVk+BWELaFFWNwRsKAddajcZGSZab0YIc3klZzZ3TlkGCj5CIFAkfClQJztSeRMbRXsJHFwFPGwPPBckGSgyLxpQB2oZc3tIRwp1UXZLXhUrdEJHNzN/JHEXBCNTMGAYPyMDO05lUUNmKg1kGgE= | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.7190371375746383 | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/install.ashx?e=HfxXOGS/z9OZB5OpWDIhcI98vG 5fsxoWca3XTKXJfYriJQgYTNdKsv4S/K6mfkWhIAbznvPq9KP4omGccpXw4yox39H7ctICby7qJ3JU/SrJhv0HKSN7fI2lN9tDRbVkdht9YBbn9NoW7mKnZ2EeHpRzM4tyPZ3W7FDeAWA9Q/G654koUNxkMghSR4V61YBKj3opCu/EfMW3Pvdol3JD1RxnOeX4PrAM1cCPzZPV1Ir4SzzVigRZY8bmcjLPajJTihKLG4th75spw/7f00hPFp9lYCrTzudqPNcAS1l461ySja6I2xEDkC5Utp4ACue1aHGmPAFInybwpTFcYOvmsbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXvnPdWmxNjVj021585MfhSlKeRKeVWAD5 | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=F94QJJu2atmfZNC1TqAoBPMVqHgy q6Y1VMaOJFqXYpxTYwWxYG9WJlbztiqtoL/oUDW29 K3KYjf9BDcIeJg3f1ws7XaD2yRYhZSGl8ahHJscN vLrCozg0PJKmtjhbnF8rmHTkMqGy2eGRx58JVeIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSa9/CpuCTIAF0= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/t.ashx?e=eFCD8T/coiezrE/yDXLQyaBYTa7YJ/ddFibV1lgn9kL8ln8Iap23//2TEkHeJNDUga zuhV9q9GgigC dQ2qERB/SoLmDeveGxrTqW15vZAdYLC6Fwg82dCUHeR8YCF3BQ8MIYMfS0viLuGcd2F1x25D993ilxFQ7nJDKdFRkjljTyNjjzEEmvfwqbgkyABd | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=F94QJJu2atmfZNC1TqAoBPMVqHgy q6Y1VMaOJFqXYpxTYwWxYG9WJlbztiqtoL/oUDW29 K3KYjf9BDcIeJg3f1ws7XaD2yIg0p1vUMLr4E8SFHLIEPsGJTlYCQaOf7GuVxeoIbRG3Yz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW Q== | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=3&utmn=1730329326&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Offer_Accepted&utmht=1429596739155&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&0.5906745765326631 | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=KC52kqqAunDZ0iLC9WK4WFxXO2/ZuraujA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/iAIKZZuIG7pa1yMTX l/6fI6tVPrdYEHziRovMIdqiLY4G r 3F6T71bPtYaZyj1jXJFnq8uZ2OtcEDHjhn1UqBPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/install.ashx?e=s5Ydxb c7o1WuN7nJmKQv/x82bD1CPIVfvVXty/UsTroUht0DV8eHWD3h9gcT/r2iwEbfeVtNep9AGHLpPN9dvm9MH d93Mvga zuhV9q9Hxu1y 6Ac0RKhN6psLdnSsdosECI4dMRD6OfU8/FMPXH6dYg1rlTgUy/ecrRsbq5tpfYOBgM/eiVGOPVXIjHvBQBWGehDOL40qPeikK78R8xbc 92iXckPWyDeCB2 tfyPfcw3xSS2sC8A9/jgya9LlYcK O052ZC0GDTXqk98YFU/GQ/6lQnvZ9NUWB1HEgAqPeikK78R8xbc 92iXckPVHGc55fg sAzVwI/Nk9XUivhLPNWKBFljxuZyMs9qMlOKEosbi2HvmynD/t/TSE8Wn2VgKtPO52o81wBLWXjrXJKNrojbEQOQLlS2ngAK57VocaY8AUifAZ5Zhb6cYHbZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmBdCfoOhw1AmusrAPq35vVlc7I2zAtpd BrFRBRwOvfmpZiAUeJqQd3w7C/8Waki4UTdhHKpI8R4g== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/t.ashx?e=XJYuqQQo69eJxiP7f9a/G5kHk6lYMiFw8F7JKJBcHiFAXdQqxJ1va3sc7hbJtTJHVR5AawbKoxrmEFSc9UZ7HoLfo4buCUHLYCpHZc9ZUaGLbhvor/ikhRQC drCF7eFysWDrahxHN1nWpr61EGbEgSa6Z efd4uyZD6A1psf2ya3UsgcT0aYMiISMf8I5JK | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=obiBp3WOda80dGo5FFu/Rfx82bD1CPIVMg4/1 uL4Rx4E7mrr1h80riKIFo3W8f23Wq7IsWCDz6QG2IGXsglf9aoPZj94HyT6LOwEGQvh2zV2TxY7/sL 44G r 3F6T7xRE3XrPaz9SlN4/jP vfgHFG19d2lv/HJ3iKHvUBVBgUcVzVK9Vv1mcf8BCmUGG46EQb8iyo3pFzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhcOJRGQPMpOEZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmDIiEjH/COSSg== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=obiBp3WOda80dGo5FFu/Rfx82bD1CPIVMg4/1 uL4Rx4E7mrr1h80riKIFo3W8f23Wq7IsWCDz6QG2IGXsglf9aoPZj94HyTzprDiolRFccz/yeZN BbCCmF904v4t2DaVtcL0PMGkj3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22OWbU/CGmJ5Yn | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtSOm5eZ4cw1FBPrMwLm 2sRKYX3Ti/i3YOiW0 omKwO0XPGGaK58CUdKIVyy9nVE95oyD6CU7dt4Wn8ksZ3j7x1iB5kmKu6piWQOuYQ194zIMgZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/ S e3Qk oWjiLuGcd2F1x25D993ilxFQ7nJDKdFRkjljTyNjjzEEmn/Mv081ozH 6ysA rfm9WVzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhRN2EcqkjxHi | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRAkqBmtM5btymF904v4t2DqIs V7Ds6CRuZZIi5/tojmg8l4itKbh/HiBn688lkcr8toCm18jzwzsvB25MJtnS1urDxSq54gttr9SYvZpGaZcc7RKjUBXhxuC523JvYYdSkkpIJMyTNdApcSbF ajtWckiMiVYfJeK7a1soWlgbXd/rihenux9ySc2qnm2W09Gzz7wQc0vaHURkj7Q ftYGzj3tdSkW4Zmvpo8LqZZFg== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/yta33_full.exe | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=4mC0vXGWFtrPpyTTOfle7KBYTa7YJ/ddzVEHgY7Nvtv8ln8Iap23/wrmOSgIBLqiUA7dl9owwhJzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhUUzEuqmKn8FFjCwIjKziMWX1FtTkCv6XNG/q7d0kZqG4nJwzEzT2yGx2KlVs8m8LqSlVGmgAnwDgZiB55ZFi610O2zSRBrcbfeJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5tMM9FOiO9IIcxXLgDRmHLIooHpf zDreu25mDZEkSyn7iqNbFXibXo4EEUq2YBBrBKqBh/IhxWU= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtSSe6wB6uwHTPUd/QfilrMBAltiGSLIu3jTI/BdPpi2K8DfJqMJzaCLHcPH8e2aI0 M8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj247L51k5jm4zsBCEmBDvTUsTZINeK/JOSL 3WfbvnIvNzoFM0vxjvvSqcviFu3/GkUyaD6UnFJmg | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtQ3HFDGhcCtcymF904v4t2DkuWOvdnHdKumYTzO WELM7Ot/W9fkCR9BPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTTuh9zxLe96tCUHeR8YCF3eUieKUOy0CNssIFedkeDcwU A6kiYcjN5jgwqhpV 3QaM eJWkTw6uIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRohYWVSD9bxhD4NsK07Wi5s IILilpWF2KgswbSwpeyhmehRlAIZWixXuPFOdxmQSrMrg41l/Ly7CST5Ycto3cE6nMAQ0x67lxVrNxtz1yEZXZrelYJPLUp3totELV0vAUMpiXMw4KN81q3cIZb5NgZjB6lpXcvb8ETDauskRD13csfOMEkERp | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTF/nvWLek4mQTxIUcsgQ wziIw8Q49/dgttmOVSqw04CNiCF4FJfQXuVsw3gS4GmHhRrrlB59yRveJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5tMM9FOiO9IIcxXLgDRmHLIooHpf zDreu25mDZEkSyn7iqNbFXibXo4EEUq2YBBrBKqBh/IhxWU= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtQQuxFFygAloQTxIUcsgQ wWDLNdKr8lljanAVHlmf vATxchauHrQ9hdXWs9gHCsWrLZx3iqhAOXSh4 HSf3c17G8X1negC9ViA7TIcAcS/PSaXpttQq9u6mIlOXI595 bsMJhchpB dLHn2izZkEYSae6pFGeTxOSDd4/R9r/g== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRaYa2XOOQuZBQC drCF7eF7LQ fMG3nUOoTeqbC3Z0rIzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTvsEASNc/caY4G r 3F6T7M 2x4nq/V4db8yl/lmEDu8bgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=F94QJJu2atmfZNC1TqAoBBIAXT6v72bD1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglf K9V0GRRES3IlxQB6eB5S9R7UpgWEByNCUHeR8YCF3MktO1JB6jbL3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22ObTDPRTojvSCHMVy4A0ZhyyKKB6X/sw63rtuZg2RJEsp 4qjWxV4m16OBBFKtmAQawSqgYfyIcVl | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=QgW8pN5r26bof2QYjF1uPw 1b2jb81yhAZx7JfD/ZiMQyol6Hp9RdsFeXk7XK CmZc1aUYNgRmYUMpiXMw4KN81q3cIZb5NgZjB6lpXcvb8ETDauskRD18KD4bIu5UqAjKjHf0fty0jJarzC68jV81FHLC9J469/1QHs3X92ilHJn1GegIILyOsrHZsRsIfMRhg0WUsz0Xly/L51iHZ9rxr2JHwunefehyr8tn/scJASvby4dPZrV Iu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=4OQPU60dJ1qZB5OpWDIhcAe6sha6wrcYQF3UKsSdb2sRoGJKEMpEhX5dMiu8MPG0ffYljA3T0gt1hsGb8yo/2TkjhBdHIT10cuvvLWnJm1UnwfzR3S4hQtSSaUQFDqWEnmP3t8anGDckr4PJ1IiKN1 JfVwpv1Wv4yV9gTVq WZsJKoGkBMBgLPiCC4paVhdOS 6WDi3NsuM8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj247L51k5jm4zsBCEmBDvTUsTZINeK/JOSL 3WfbvnIvNzoFM0vxjvvSqcviFu3/GkUyaD6UnFJmg | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=DNkDj dFVmCfZNC1TqAoBLWRhHmxIJa51VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfzMncK1Qz/SNyETj4nts NPl9AOtqZ1I9ymF904v4t2DIdOulZ3X5yT2e6nYO18M sRH TBIllJr94khRQjb0om5r9iFtppC1uEsoMnuAcfjiugW2mv9tjm0wz0U6I70ghzFcuANGYcsiigel/7MOt67bmYNkSRLKfuKo1sVeJtejgQRSrZgEGsEqoGH8iHFZQ== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6sAcx93N9gOwKrHgy/oM8tnisgFVrwdvYUha2hWnuyChQC drCF7eFK1fB54AeplfjV/OYuilSzqVKY5y Qu9A4i7hnHdhdcduQ/fd4pcRUO5yQynRUZI5Y08jY48xBJp/zL9PNaMx/usrAPq35vVlc7I2zAtpd BrFRBRwOvfmpZiAUeJqQd3w7C/8Waki4UTdhHKpI8R4g== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6sAcx93N9gOwKrHgy/oM8tnisgFVrwdvYUha2hWnuyChQC drCF7eFhyLMFTfLfGniVx6hrLaV8djP1QedMB/cy/B6ujnJrtI0fJ30mPWB3MJ9BqBjylb5Pk55LBQN29oKKSszP/5sI8gZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/CgTTFbRks1o= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qayD5Sh2iPx4Tl/DvTHZIAKtATxIUcsgQ wusjSmD/os8shJkdH5jOhAHvojBYZTAl2SDGL01oIa7jD3Psqw12eBUNQkrQodbn4W0C6B oLg2/kIgqoM4zGjB6RUS1Mgh81BPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qayyETj4nts NO517CUeh0QiwTxIUcsgQ wusjSmD/os8uUYk8/b2 6EUeCMSNo5dvN0DAe2B9i5kJssIFedkeDcwU A6kiYcjN5jgwqhpV 3RVAAKZHGiEvoUuxfjpmZqkclTumrkXWbdv qR/r3k14sbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY= | |
hxxp://cds.c5z6s5a3.hwcdn.net/spd/shopp/iweb.exe | |
hxxp://cds.c5z6s5a3.hwcdn.net/spd/shopp/sense9.exe | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/ShopperProJSINJFull.exe | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qay3IlxQB6eB5S9R7UpgWEByNCUHeR8YCF3TCM72XKEiy8qCttwK9rPhasyuDjWX8vLsJJPlhy2jdwTqcwBDTHruXFWs3G3PXIRldmt6Vgk8tSne2i0QtXS8BQymJczDgo3zWrdwhlvk2BmMHqWldy9vwRMNq6yREPXdyx84wSQRGk= | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=5&utmn=1464879343&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Installer_Init&utmht=1429596751514&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAAAAAAABAAAAAAAAAAAE~ | |
hxxp://54.197.238.106/app/ping.ashx?e=LCnUzM5l8JJPNjxRBLtb4/zZkW6G79bUt8f6YpiR28K/M iZRiJnRnHdTB6jkze/avGlMWAqZVGhQNbb34rcpnjQavldL2jCXHOzMoXfreuzIeRzata1huhetAXEFso2Hd5atJBamYqM8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj23LymH6HWKlXaBQc7HR56MWNJxXQawroNmbktPzt6FdqtvzSMXg z9WmrvcVl0Mf/w== | |
hxxp://54.197.238.106/app/ping.ashx?e=QgW8pN5r26byj2QAAnEFBPx82bD1CPIVl505lEjGRHKRoZJTpqsyZxASc9FSZWyoGYsEX4kIHlu/0mFZouDnPtaRJ3Kmqu0qPF/e8UuaTHBgKkdlz1lRoYUad3QpOh3uU8/inQ0dV1y6KJfGT/oeAyr6Se9TnnMMjPDFOy mdVxc7JTfzqJuQ2xNoUmVdbK77K3bmITDI9ty8ph h1ipV6k2NKjmbE4rFDKYlzMOCjfNat3CGW TYGYwepaV3L2/BEw2rrJEQ9cb WUhAeb4M8AeXrDcfXn1 | |
hxxp://54.197.238.106/app/ping.ashx?e=b1dRW7RxYKfwl4DCqEaRhC8ev2TZOcii62ls PLHCLAq gheK7Gg4DZ3oi5EKsF2X3dll9ySpyXBi830LV6OHeQDoeGvwbJQMRM hXxEXcCcOCzurm ZeawY6pZsyp29dVn5miu3RfPczYZ7/4oF2Mbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXoDAbDf1f5I9gDcoAJAtAYWupXyB/g5yjGYsEX4kIHlvi5n nh6YVLffopz0y2Q7Y | |
hxxp://54.197.238.106/app/ping.ashx?e=lOCrbsNL2zWYW6sXTpZ7/KBYTa7YJ/ddDe4S81RKSSsyIvs8NVvu9kXFDxkTgufFt5aWEmvF1lmyibNNhHQuhqoPWDE/bHCMqUVvKp9Lg9WpU9MRQHad4Zw4LO6ub5l59bC43VoLO9EMGHDQVw/vzGhU19XqFTVuS55OePfOVKxbaMNHmg 4ouIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSa8OW8dQbOsF zv/F4nWpfy1LqqCcUKB 1ai329YoT/oQo3Gv nP8wmYBlKlGJcuDg | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=Ka qOJkckoXHjWHokC5IQCi9f0a46N9/eq10/GADmDBu89fJv3K/CWQ14on7GBy1f82ojUnVmk1jg4jhBREgIvCV4d3G7GmUuX P2xaLa6cCbsn9VEgrCJGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfwe6XX8Ler0VWuHFN9lRYXm3sb/Jc9bi4CY6tkU PjWGlHVWy8T0I6XgvyObhcmYFVDq65iJ/PSima3r97HUBE6rMrg41l/Ly7CST5Ycto3cE6nMAQ0x67lxVrNxtz1yEZ3jd05TL7uA7e7JlmIOJU/BXl5O1yvgpmXNWlGDYEZmFDKYlzMOCjfNat3CGW TYGYwepaV3L2/BEw2rrJEQ9ceEUGZ7qw47sqwZwxAX4ff | |
hxxp://173.239.4.56/online/Register.aspx?CV=2.0.0.0&ProductID=12000&UserID=&Password=&OS=10&EMail=&Newsletter=&V=3.3.9.5&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList= | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=PcwT4QFtuPDEA05CBT6a0fx82bD1CPIVuKcNdKpB42 RoZJTpqsyZxASc9FSZWyoGYsEX4kIHlu/0mFZouDnPtaRJ3Kmqu0qPF/e8UuaTHBgKkdlz1lRofUDr3 uV4Ko6jA0ovCT514E8XIWrh60PYXV1rPYBwrFqy2cd4qoQDl0oePvh0n93F2fKohH1AHQrJh3xkjGF5PIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZf3BUb3WcrzZ7HySmeDQikgk= | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=FwW11b 20b6fZNC1TqAoBA2dE/SZourWTEgCpOx0T0GQL2F0hg1RicLJlw9FGc64W40V8RHoWcfADsKdK4BIvJzI6WjgFlNrd6j7/wRBDsRoqvWX6JwkevDehHIxlAXyb98NyY 3Jv/oKdNf4wHzMP/l0k1T1nn7b588fAguahpqadCmmmNJTNNeVrTC3wKjwfrj lvkwi3PeAWvHdcyb2damvrUQZsSBJrpn5593i7JkPoDWmx/bJrdSyBxPRpgkex5UpBoxTMMW2oEbpyuz9p5gsvoA3US | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=KC46TpkJIZznGREG7sgAN5kHk6lYMiFwka70kbUmYHH7RH4w/5EvdUqAWhGQi7pGk2HxL2Lh3QfhrDqaDSP7qD7whcneFjZtnMjpaOAWU2t3qPv/BEEOxGiq9ZfonCR68N6EcjGUBfJv3w3Jj7cm/ gp01/jAfMw/ XSTVPWeftvnzx8CC5qGmpp0KaaY0lM015WtMLfAqPB uP6W TCLfid DGu7L2IfOGA aYz3qB2EfZmulEUHKsyuDjWX8vLsJJPlhy2jdwTqcwBDTHruXFWs3G3PXIR40rkbBe1jq 6d7D/p//KBBNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaC5k/79Gow98g== | |
hxxp://s3-1-w.amazonaws.com/partner/gim394750002/release/live/InstallGenieo.exe | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=wlkQ3WKgYpSE2rQtmh2LBMH64/pb5MItlzMqADZ2OvYSZTerw9Y85XkjLFx9TDtKeHo6FOnjNt3Tp8VZQ/4p3GivYS/d2rWv9A8dpvtBeO2hc3DbjNrW8PQYnQ1xoKSBiZYn8TH3Pe3MlW9RFqOniiR/VPwArHZ1QMCg3fniKLWzp3t4zCe899YNvMh53GZd/HzZsPUI8hXft0AGFKL6V8UWbVgwixNWt9kbY6X6G3rYz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW aNKDh4dmbgaJe7HkSXGWaA0BPmlVlU0prupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8MNAWquLWplE= | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=984e31dVhw3Z0iLC9WK4WOZsZFYgTv0v2YTeaOaZJPFysSIQM/WMqtGQDVZU32tJRZ4jWEvEgl1Ieo6/gOuIoWivYS/d2rWv9A8dpvtBeO2hc3DbjNrW8PQYnQ1xoKSBiZYn8TH3Pe3MlW9RFqOniiR/VPwArHZ1QMCg3fniKLWzp3t4zCe899YNvMh53GZd/HzZsPUI8hXft0AGFKL6V8UWbVgwixNWt9kbY6X6G3rYz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW aNKDh4dmbgaJe7HkSXGWaA0BPmlVlU0prupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8MNAWquLWplE= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=j7YMo/n29XMqqDJt46TNcdnSIsL1YrhY5mxkViBO/S MDmRWpWBZ0PxJo1EJGyYRjOluN4MfK82Ul/CEn08 CUbPPvBBzS9odRGSPtD5 1gbOPe11KRbhmNS7NBdn5Y UeZLRmueCpr 7rPtSKe/ JqfQ7l07EVJDzWhC2rNQ6ya2dF0VKZsa4Q2/MQzLTqMBPEhRyyBD7A7Ux5MSUiBG6zbMzc4pOx2GGp9MstS3cDTDTdslR3ozsRaU2At1Xqvl0LTeIZ6yJ92wY9krKeIwcv4S/K6mfkWhIAbznvPq9LAXh4LPUO ueIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/25296.ashx?e=043Mckb8Lnj5nRk39lR6RcH64/pb5MItBBvtTcvyOOgDt2EUeZbtRVHmS0Zrngqa/u6z7Uinv/jJ625QtO7cCECN9h bV19VoPPb/i9FtJTgL4xsffnkQbPiCC4paVhdAGW4B5KF0X3G4Lnbcm9hh1KSSkgkzJM10ClxJsX5qO1ZySIyJVh8lz8lbkb0am4Y | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/25296.ashx?e=043Mckb8Lnj5nRk39lR6RcH64/pb5MItBBvtTcvyOOgDt2EUeZbtRVHmS0Zrngqa/u6z7Uinv/jJ625QtO7cCECN9h bV19VdXQO8eCkzNk9LWPkwGrB/imF904v4t2DTTuHrYVulo109x0h yMmOq3 e5cYLWVDvEq1XCmEIT/KGwMMc0gnpNgExseWQzn2f6OZPQtzuZxpdD3k9Bz56StbFykGQeFJDeQKlJvveiYBN5p9ENNd42Jy LrysKIChDb8xDMtOox69ZimTX2csKzbMzc4pOx2GGp9MstS3cDTDTdslR3ozqAqUZoVYaYqOh7dSyef3K/a9dSBDkVKEEn/27iYAIjK5pdl3V4yoSZtC3ZUXmNv4hOEZ9fC9NN7s9C7tmmeIQ4UJj9eY3tRmk7I4yfJnN09f40hcgVNJWNmhoIRlNpk1mikCyRdzxo8v7Oo1qwnkCjjbJDwZzUwO IENZVDItwmaAzdvG4/9NloJg2UA3GeKNsBE3goakaNuPR5NfrntvDVo4ooxmVMPwjkjucBSk1dZJXwSvkB4LUW2SuoR83S f89O44axxrpFmpWsqJza8G jCJhwZ2krd1LISTKeN3CckdTtpt CJF3lUqbxpVPs/eJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5ZtT8IaYnlic= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=uWabAt9SLcwd5zMhdw4gNpkHk6lYMiFwapPLbuJFxiVAXdQqxJ1vaxGgYkoQykSFfl0yK7ww8bR99iWMDdPSC3WGwZvzKj/ZOSOEF0chPXRy6 8tacmbVSfB/NHdLiFC1JJpRAUOpYSeY/e3xqcYNySvg8nUiIo3aTN6JbPRttbb8zyMlAjNJ94BVzIM sbWFAL52sIXt4UeH8s8AG8ECxxc81u2rgCm44UuTa3qd5D7MusukiOxFQ/nGwVmCS6yE4/IIoWPFRUEB1KJjJJfUAE70KA8ZXhbA8YCZx49749T/rv 3Ugl9NjP1QedMB/cy/B6ujnJrtI0fJ30mPWB3MJ9BqBjylb5Pk55LBQN29oKKSszP/5sI8gZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/CgTTFbRks1o= | |
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=/kyMh6fFcsSfZNC1TqAoBOrinWEtHMrXiUSU3wY9EyZgKkdlz1lRoe viA2bCzBJ8S85LP28b9XoIGt9tn96dHczOeuk4NHAZlWzJoJS0vpeeVUornuiCLupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8cyhMDFV3OWTM2kLK0Eh6GOhAyMRSteYLfy2nd2OoBNWZcVk3bWa3iMJb UIfjrRxmoi0CE64JPPM/9VP4YRizveJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5x 9v0hi6ojl/pUrWo8oa7dY GMQdF3uJi4Hm9PT1ORmf0Es2LXheJLtuZg2RJEsp 4qjWxV4m16OBBFKtmAQa wAawvpuok/gc3cbc64uvo= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/1638.ashx?e=o4wkB1bL2nKZB5OpWDIhcGqTy27iRcYlQF3UKsSdb2t7HO4WybUyR1UeQGsGyqMaUBoq0tYrWJQaFTly08TKaZ9eFhsT1abeQqykZerlmJWOBvq/txek 4iYlmtiSGZOjPDFOy mdVxc7JTfzqJuQ2xNoUmVdbK77K3bmITDI9tzfMa2zgJTnw== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=j7YMo/n29XMVCZIctrluXvx82bD1CPIVELGhIJQe0HZ4E7mrr1h80riKIFo3W8f23Wq7IsWCDz7LtnwqBBAAaNaoPZj94HyTzprDiolRFccz/yeZN BbCCmF904v4t2DaVtcL0PMGkj3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22OWbU/CGmJ5Yn | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=j7YMo/n29XMVCZIctrluXvx82bD1CPIVELGhIJQe0HZ4E7mrr1h80riKIFo3W8f23Wq7IsWCDz7LtnwqBBAAaNaoPZj94HyT6LOwEGQvh2zV2TxY7/sL 44G r 3F6T7U6q7EvjWjEUpXTEKkNwLoQKR8BH1AzvaPPinFkosvv9rREKBtez 7WKW/rKS vRXCAOOMT3NqqKes3TcA28cXQBEHhrcWo7yWUQOfMPJmmh0ybeGoyy0n/LTq3A5G0uD18dH0Dqne6k4zRLhdZdA1ySsz132oq8QdKhmr1s1SeLNSxMOktmsJuXkffI7Bc/8CjIrR103eiScpBTrnNl8 QzgS38rypWTnpREYU9txHgvkahbKtRxSuTlLpRpGef1HRWCGgD35NKpP/58BClMEV0zgN2QlL7bUZOTrxLzAqz5PbKQnR2ahvRSgOOuFwqPUe/lNjkrreVLV GIYMVmKXpVpzwoowpDIzgoMNgVSZqtuKkFbJdih3 4IimkuEAS4i7hnHdhdcduQ/fd4pcRUO5yQynRUZI5Y08jY48xBJr38Km4JMgAXQ== | |
hxxp://test.youtubeaccelerator.com/video_accelerator/wizardtest/SMALLTEST.HTM?random=561931&mode=nolsp | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=EYAmqppYZO/Z0iLC9WK4WDbtqEH pn2ijA5kVqVgWdAgLxC0aXqYrYyox39H7ctIe8oePBO1o3KmcJNx5UwP Vi2s6XsF8NYPpbX8eNZzIIUAvnawhe3hU72ISjKawWsoSwUHtq20zGrMrg41l/Ly7CST5Ycto3cE6nMAQ0x67kcucdFKeANzw== | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=EYAmqppYZO/Z0iLC9WK4WDbtqEH pn2ijA5kVqVgWdAgLxC0aXqYrYyox39H7ctIe8oePBO1o3KmcJNx5UwP Vi2s6XsF8NY0jd2Ua9SYWgE8SFHLIEPsNuIAbgWXib3hDb8xDMtOox69ZimTX2csKzbMzc4pOx2GGp9MstS3cDTDTdslR3ozqAqUZoVYaYqOh7dSyef3K80qxoLIs2wicAgCBrynT3T/Dw8o2fbvVqcMM7jAoddqLdDuCot28iq0o3 yQeiL1SuvBinayp0tcns/kzQV2BeVzGXirEinUjygIx XkkBquLrC93K5FW5l208O4rRao0E6NcS/ao7oObdRP0O2TtGfu0Hoi4IoRaoc6SnqWp/oWNRnHx8enwk/aK7d1sV3iVS6qgnFCgftRA3YsNRBZWc6/aMBz7Ly9o89e8YHMKynf1HMm1Ts0Hqd5LUq7 5Y6PN25QukZWk/lWZ9Aknq7ogvFXyQpt50unG4Lnbcm9hh1KSSkgkzJM10ClxJsX5qO1ZySIyJVh8lz8lbkb0am4Y | |
hxxp://test.youtubeaccelerator.com/youtube_accelerator/wizardtest/SMALLTEST.HTM?random=564177&mode=nolsp | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=hXeqmv1IpelezyBKiN6u EaSrJjHbiRO7OXLse4BafQHqUQ0J3/4E9SSaUQFDqWEnmP3t8anGDd5NQIjO3Pvbce7kS6GRZSsCy5U1DKQBR/1HrjuYPfZlNCUHeR8YCF3eUieKUOy0CNssIFedkeDcwU A6kiYcjN5jgwqhpV 3RVAAKZHGiEvoUuxfjpmZqk49BuL0n8vhTQE6ga EGy2YzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbc3zGts4CU58= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=b1dRW7RxYKceWuDhZt9/CZkHk6lYMiFwsTnO2KqeLVhAXdQqxJ1va3sc7hbJtTJHVR5AawbKoxrV3H17CkcJAVCJBxBnzZq4YCpHZc9ZUaFgmm5xjmBlpCI3FLqKedV9QoAE/or KqogGeUpHHIWiSSfRcuIfR0fUu0KI1IApgUwqc65TUDdvwHwk6fyNraudfO3QRiGoOfMI41K2f6iZFP u/7dSCX02M/VB50wH9zL8Hq6Ocmu0jR8nfSY9YHcwn0GoGPKVvk= | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=100&n=init_start_funnel_step_name&rnd=1429596767 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=100&n=init_start_funnel_step_name&rnd=1429596768 | |
hxxp://ipgeoapi.com/ | |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=70121&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_32&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&mdat=&procstarttime=1429596767&procruntime=3&rnd=1429596770 | |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=70299&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_36&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&mdat=&procstarttime=1429596768&procruntime=2&rnd=1429596770 | |
hxxp://s3-website-us-east-1.amazonaws.com/installer-error.gif?action=sesamy&app=70121&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&error=0&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596767&procruntime=3&rnd=1429596770 | |
hxxp://s3-website-us-east-1.amazonaws.com/installer-error.gif?action=sesamy&app=70299&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&error=0&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596768&procruntime=2&rnd=1429596770 | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000171&country=ua&app=70121&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596767&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596767 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=200&n=init_end_funnel_step_name&rnd=1429596770 | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000805&country=ua&app=70299&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596768&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596768 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=200&n=init_end_funnel_step_name&rnd=1429596771 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=300&n=deploy_start_funnel_step_name&rnd=1429596771 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=300&n=deploy_start_funnel_step_name&rnd=1429596771 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=500&n=deploy_notification_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=500&n=deploy_notification_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1429596772 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=700&n=deploy_ch_start_funnel_step_name&rnd=1429596773 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=700&n=deploy_ch_start_funnel_step_name&rnd=1429596773 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=800&n=deploy_nova_start_funnel_step_name&rnd=1429596773 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=800&n=deploy_nova_start_funnel_step_name&rnd=1429596773 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=900&n=deploy_ff_start_funnel_step_name&rnd=1429596773 | |
hxxp://173.239.4.56/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596773&SBPIDS=1&KA=1 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=900&n=deploy_ff_start_funnel_step_name&rnd=1429596773 | |
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596773&SBPIDS=1&KA=1 | |
hxxp://online.speedbit.com/online/RegisterAnon.aspx?ProductID=12000&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList= | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1429596774 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1429596775 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1429596775 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1429596776 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=10000&n=deploy_end_funnel_step_name&rnd=1429596776 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1429596777 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1429596777 | |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&LFMR=_ffDll_0&app=70121&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_32&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596767&procruntime=12&rnd=1429596779 | |
hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=70121&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1429596767&lifetime=0&silent=1&crtnm=na&procstarttime=1429596767&procruntime=12&rnd=1429596779 | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000171&country=ua&app=70121&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596767&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596767 | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1429596779 | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2QI8HtM9wp5Tx0cXu7AB1uimF904v4t2DIApimWCrqanh60kwO3gtxYzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2yETj4nts NO517CUeh0QiwTxIUcsgQ wfJnh8VDEgRSlTNRWMyvAk6UqjDuAivmJ4m/vJXDvF2G8SrVcKYQhP8obAwxzSCek2ATGx5ZDOfYQeWksviRUhRe13wRG2Zyfh8h5o3YrXrZv qR/r3k14sbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY= | |
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=10000&n=deploy_end_funnel_step_name&rnd=1429596779 | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2yETj4nts NO517CUeh0QiwTxIUcsgQ wWs /9f4We1ocVdO68mAhaoKbHXQ3LZlHwdE4jBu2OwY8 KcWSiy /2tEQoG17P7tYpb spL69FcIA44xPc2qop6zdNwDbxxdAEQeGtxajvJ8DVynAnBV8ozwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA= | |
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBE3dSGLo0YSs1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglf6yVpsz5btdlnKfUFSSn msc10t7BHb3gMjKRY6Iofb7CNjw3TJVaaftecqRQrG/Wx7XFrkvV19SZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmAQ VwoE0aIX/TbXnzkx FKpYXnBYRIAoJ1hsGb8yo/2TkjhBdHIT10cuvvLWnJm1UiAOXU9hSaAQ== | |
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&LFMR=_ffDll_0&app=70299&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_36&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596768&procruntime=13&rnd=1429596781 | |
hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=70299&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1429596768&lifetime=0&silent=1&crtnm=na&procstarttime=1429596768&procruntime=14&rnd=1429596782 | |
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000805&country=ua&app=70299&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596768&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596768 | |
hxxp://online.speedbit.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=7f18dd1b-ec41-4752-9468-5f9624612952&Password=mm7DBqQs&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596785&SBPIDS=1&KA=1 | |
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=7f18dd1b-ec41-4752-9468-5f9624612952&Password=mm7DBqQs&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596785&SBPIDS=1&KA=1 | |
hxxp://www.theviilage.com/searchprotect/up?ptid=smt&sid=IHProtectPlugin&ln=en_us&ver=4.0.1.2105&uid=535559167_198339_B48A115F&dp=0 | |
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596790&SBPIDS=0 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=2&index_in_screen=1&index_in_session=2&display_height=195&0.8906559107847234 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.5528722536780852 | |
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=1&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=20131113143800&XMLUpdateFailed=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596796&SBPIDS=0 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=2&index_in_screen=1&index_in_session=2&0.4142904310700625 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.9104375687078131 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=3&index_in_screen=1&index_in_session=3&0.4049143552587808 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.9583576309473749 | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?95e2710ce7116392 | |
hxxp://a1621.g.akamai.net/pki/crl/products/WinPCA.crl | |
hxxp://a1621.g.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=4&index_in_screen=1&index_in_session=4&0.2014881967661576 | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.49850194038478096 | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=6&utmn=933000356&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Offer_Accepted&utmht=1429596840246&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://theswiftrecord.com/mg?alpha=UUFbQCJjAx9tEGh1dGotUAUITSJRB1kxK1JZLwU8VRUaI1UFT0YyTVsKWjd2DyVDFCpQNTczZDxCeGozQklhTVApFkcPKQFAQzZrVi9y | |
hxxp://theswiftrecord.com/fp?alpha=XjJ8Pkx/TBBzLSYRUxRDX3YvM0xebmpPDXkzPSEQWSZxPgpcQ3U9VCp3YjoYH1ELakJDQBM0B19FKGAoRmZ0PzgyQTpTT30YbS1ae2YHM1MdM39yEkkqK0pJIFx8fFlbZj0qSA5IdUEgWXVgJR4EIXFqM19MEjgTQzQtYEwJJF4zXE13b2AfEmtsKx12IgJQXk0uamhBWGYhUkkpTHgpTQlqMCtNG098WCRVYDI6DVEjaTlkThAQKlwfOU06BQ45WXYqVGVtehRQMjVsQHdxGiwqaDgoLURFNSlDTShafn5GCSB8JS5SECgXZR9gFG1LV3otPnIwCBE1DUYzL1hMHiJZajdBMDYiTntrbCZoKjV7TUhpK3tyYUE0LV9NKFp3DlIrZFJcPQkqFRx/Sgx9 | |
hxxp://theswiftrecord.com/ii?alpha=XjJ8Pkx4FBptWzEwUxRDX3YvM0xebnAWQWsBaC8JDG42eQlLQx8Pewo0cFpIUXs7PyYHAkd+dxY5L2JbXnkAOiQyMSAiTgpuaTsPe3EHER9zbScvEQ1mPwEbJVULCiZfYSItVH48fTo/WHFoMQBzIXsZLV8wEz4MMzBcZygtYBZjfD00KGRHDW5rPgciNhRSTwIufmoQSzc/Fhl+LjwjXQE2aGgVVAwpXnYJJhJ6QmQpeGsuXlobPg5CKixkX1lmFmlvb0xhcUdqDXxkWmZ7SgVDe3ckO08PdDVSSixBLCUUTjxjbhxJQwERcR4vI2dLRjQeMm4KG1V/HkUkTSAFDTJDfWNvbm9+WnF+en1MYHFTDxAMJGppDkkpLkRMKUw9KRIeOnN9WUsfLxMyVmBhJh0Uezo3YQATH0lQFWh0IQJLf2VgY3RlajIpSz8ublo7JFQWQxg4JG1QRX4/EwolVX5gUVhhNnUYBk58QidcemU+FwAlc2sxVEMWKk4dYCAUCwckVShub21gLz5xARRKD3ZtVwNDaF0VEWFeY21PKlUbLz4FRHNGVQ5aDClYRAUyJH1MXjQae1MtJ2sseht3dnIuDiFZbW8mcGUvXFowOTYYNHgHUQM+UitJAjk= | |
hxxp://theswiftrecord.com/if?alpha=YS9EPRcOZjJOP1cmaxcYYGsXMBdhc0gVGlQcUCxSM3MOelJ0XicMIDUpSFkTbmYDPH04H399LCkkF2EAYWQ4OX8NLBghFTVzUThURGw/EkRMcB8sSjJ7BwJAGkgzCX1gfBouD0EhRTlkZ2xQMltMPEMadmAtKz1XDC1kZHMSfS5oMgJOXnRNbAoMYQZmdm4PdmRqBj8TYXdXTBMBB0t9C2Z7BisWKlFFVXlnaFg4RittFD4ZIwYnZgA1aUk+QzFsbGg3fW9ZRxwxc0w4XBQtMlMLIjVHbkphfUQea0gSSxpocSFbb1t0BkksID05B3wFISlHbHYzAG4pCj5vQCMMGSNrfz5MclBlAVcqDGwdWmwiVAVDcR06HjRpSB5JRh1WARt3OE1pUW0MGltzc2tGOlg6P0FpeyIMaHkMLnwFIVA3ISg3cQ4zBjdOcy8DZhUQWmwESXpwGnxTEnRIBUJDUSU7WiMrWzIEahVJT289bxg2DytoB2ViYUUrP1drdERsAWRwPT1rCisMIxA6c1MyRRk5cgxBLkUTMAgiPEUeSklMMgFkGQ8Of01pAEk/CgwTKS0SeTQnFSwwG38jRRtUUjBDMWpeZCNLaFd9AVNjMUshZD9GClZ4IzY5DS55RHlQcCcRPCI= | |
hxxp://installer.betterinstaller.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.9208263061749289 | |
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=7&utmn=1472907400&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Offer_Accepted&utmht=1429596847128&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~ | |
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=73055282&utms=9&utmt=event&utme=5(Messenger*install-desktop-client-new*1.2.23)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/DesktopMessenger.exe/11111&utmp=stats&utmac=UA-53163344-3&utmcc=__utma=37894201.75610525.1429574400000.1429574400000.1429574400000.2;+__utmb=37894201;+__utmc=37894201;+__utmz=37894201.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/DesktopMessenger.exe|utmcct=/11111|utmcmd=referral;+__utmv=37894201.-; | |
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/40da6fd4d86af64fa44c08b317ad86e7?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4 | |
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=69679079&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=54986866.62946922.1429574400000.1429574400000.1429574400000.2;+__utmb=54986866;+__utmc=54986866;+__utmz=54986866.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=54986866.-; | |
hxxp://d2z5psu5fxw71b.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg | |
hxxp://d2z5psu5fxw71b.cloudfront.net/images/Tokyo/tokyo_sprite_full.png | |
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=82030882&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=59077916.52149898.1429574400000.1429574400000.1429574400000.2;+__utmb=59077916;+__utmc=59077916;+__utmz=59077916.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=59077916.-; | |
hxxp://plus.l.google.com/__utm.gif?utmwv=5.6.4&utms=9&utmn=1727154030&utmhn=installer.filebulldog.com&utmhid=1748701739&utmr=-&utmp=Installer_Init&utmht=1429596849188&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAAAAAAABAAAAAAAAAAAE~ | |
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=27137216&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=31941152.92397420.1429574400000.1429574400000.1429574400000.2;+__utmb=31941152;+__utmc=31941152;+__utmz=31941152.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=31941152.-; | |
hxxp://d1z9ocnzqrnjt0.cloudfront.net/mirror/nerocrossrider/appshat_generic.exe | |
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/filesfrog/UpdateCheckerSetup.exe | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5f7079ad37977473 | |
hxxp://a1621.g.akamai.net/pki/crl/products/microsoftrootcert.crl | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt?a7806eeaf8fe6574 | |
hxxp://crl.globalsign.net/root-r3.crl | |
hxxp://crl.globalsign.net/gscodesignsha2g2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQpEOCqbmTiQA9OjY//t2aa8NSkuwQUGUq4WuRNMaUU5V7sL6Mc+oCMMmsCEhEhZyg35kUM7JUe4UHDT5+Nwg== | |
hxxp://crl.globalsign.net/root.crl | |
hxxp://crl.globalsign.net/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhZ1N/ArcYWNWqP8XWy7QmXA== | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBILJd3le4hjatTZfSO5nIg= | |
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s= | |
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs= | |
hxxp://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQDmFsbNcBDBl+cij2b1soa7 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=1&index_in_screen=1&index_in_session=1&display_height=170&0.6079360980039414 | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= | |
hxxp://a1621.g.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=1&index_in_screen=1&index_in_session=1&0.4441371446485662 | |
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=2&index_in_screen=1&index_in_session=2&display_height=90&0.45001640321370245 | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Application connects to the servers at the folowing location(s):
Strings from Dumps
ProtectWindowsManager.exe_3696:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
j.Yf;
j.Yf;
_tcPVj@
_tcPVj@
.PjRW
.PjRW
SHELL32.dll
SHELL32.dll
function not supported
function not supported
operation canceled
operation canceled
address_family_not_supported
address_family_not_supported
operation_in_progress
operation_in_progress
operation_not_supported
operation_not_supported
protocol_not_supported
protocol_not_supported
operation_would_block
operation_would_block
address family not supported
address family not supported
broken pipe
broken pipe
inappropriate io control operation
inappropriate io control operation
not supported
not supported
operation in progress
operation in progress
operation not permitted
operation not permitted
operation not supported
operation not supported
operation would block
operation would block
protocol not supported
protocol not supported
GetProcessWindowStation
GetProcessWindowStation
operator
operator
MaxPolicyElementKey
MaxPolicyElementKey
pExecutionResource
pExecutionResource
SHLWAPI.dll
SHLWAPI.dll
USERENV.dll
USERENV.dll
%dYeArdMoNthdDaY
%dYeArdMoNthdDaY
file_url
file_url
GET %s%s%s HTTP/1.1
GET %s%s%s HTTP/1.1
Host: %s
Host: %s
%sUser-Agent: Mozilla/4.0 %s
%sUser-Agent: Mozilla/4.0 %s
POST %s HTTP/1.1
POST %s HTTP/1.1
%sContent-Type: %s
%sContent-Type: %s
User-Agent: Mozilla/4.0
User-Agent: Mozilla/4.0
Content-Length: %u
Content-Length: %u
%*s %d %*s
%*s %d %*s
%*[ ]%[^
%*[ ]%[^
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
ShellExecuteExW
ShellExecuteExW
SHDeleteKeyW
SHDeleteKeyW
GetWindowsDirectoryA
GetWindowsDirectoryA
GetProcessHeap
GetProcessHeap
GetSystemWindowsDirectoryW
GetSystemWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyW
RegCreateKeyW
ReportEventW
ReportEventW
RegOpenKeyW
RegOpenKeyW
ADVAPI32.dll
ADVAPI32.dll
PSAPI.DLL
PSAPI.DLL
InternetCrackUrlW
InternetCrackUrlW
WININET.dll
WININET.dll
WS2_32.dll
WS2_32.dll
WinHttpReceiveResponse
WinHttpReceiveResponse
WinHttpSetTimeouts
WinHttpSetTimeouts
WinHttpSetOption
WinHttpSetOption
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WinHttpSendRequest
WinHttpSendRequest
WinHttpWriteData
WinHttpWriteData
WinHttpConnect
WinHttpConnect
WinHttpCloseHandle
WinHttpCloseHandle
WinHttpQueryHeaders
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpQueryDataAvailable
WinHttpOpen
WinHttpOpen
WinHttpOpenRequest
WinHttpOpenRequest
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpCrackUrl
WinHttpCrackUrl
WinHttpReadData
WinHttpReadData
WinHttpAddRequestHeaders
WinHttpAddRequestHeaders
WINHTTP.dll
WINHTTP.dll
SensApi.dll
SensApi.dll
VERSION.dll
VERSION.dll
GetCPInfo
GetCPInfo
.?AVunsupported_os@Concurrency@@
.?AVunsupported_os@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AUIExecutionContext@Concurrency@@
.?AUIExecutionContext@Concurrency@@
zcÃ
zcÃ
.?AVCHttpClient@@
.?AVCHttpClient@@
.?AVCTcpipSocket@@
.?AVCTcpipSocket@@
6!676$717
6!676$717
,050'101
,050'101
7"7&7*7.72767:7
7"7&7*7.72767:7
1!1%1)1-11151
1!1%1)1-11151
00S0d0
00S0d0
5 5$5(5,505
5 5$5(5,505
? ?@?`?
? ?@?`?
3 3@3`3|3
3 3@3`3|3
combase.dll
combase.dll
kernel32.dll
kernel32.dll
mscoree.dll
mscoree.dll
- CRT not initialized
- CRT not initialized
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- floating point support not loaded
- floating point support not loaded
USER32.DLL
USER32.DLL
portuguese-brazilian
portuguese-brazilian
advapi32.dll
advapi32.dll
WindowsMangerProtect
WindowsMangerProtect
SOFTWARE\supWindowsMangerProtect
SOFTWARE\supWindowsMangerProtect
xa.geoip
xa.geoip
visit.heartbeat
visit.heartbeat
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action0=%s&action1=visit&action2=%s&update0=ref,%s&update1=nation,%s&update2=language,%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action0=%s&action1=visit&action2=%s&update0=ref,%s&update1=nation,%s&update2=language,%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s&update3=version,%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s&update3=version,%s
Report Start.
Report Start.
C:\DoStartTEST.DAT
C:\DoStartTEST.DAT
Report Heart beat.
Report Heart beat.
ProtectWindowsManager.exe
ProtectWindowsManager.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
TypesSupported
TypesSupported
%s is already installed
%s is already installed
%s installed
%s installed
%s failed to install. Error %d
%s failed to install. Error %d
%s is not installed
%s is not installed
Could not remove %s. Error %d
Could not remove %s. Error %d
WindowsProtectManger
WindowsProtectManger
Advapi32.dll
Advapi32.dll
/c ping 127.0.0.1 -n 2 > nul && del
/c ping 127.0.0.1 -n 2 > nul && del
"%s" %s
"%s" %s
psapi.dll
psapi.dll
Explorer.exe
Explorer.exe
update.exe
update.exe
%s_%s
%s_%s
\\.\Phys
\\.\Phys
hXXp://
hXXp://
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion\Internet Settings
http=
http=
..\Src\json\src\json_value.cpp
..\Src\json\src\json_value.cpp
..\Src\json\src\json_reader.cpp
..\Src\json\src\json_reader.cpp
xxxx
xxxx
WinHttpClient
WinHttpClient
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
hXXp://xa.xingcloud.com
hXXp://xa.xingcloud.com
..\Src\json\src\json_writer.cpp
..\Src\json\src\json_writer.cpp
Assertion failed: %s, file %s, line %d
Assertion failed: %s, file %s, line %d
WindowsMangerProtect Service
WindowsMangerProtect Service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
WindowsMangerProtect service
WindowsMangerProtect service
SysTool PasSame LIMITED
SysTool PasSame LIMITED
Windows SysTool Service
Windows SysTool Service
20.0.0.1953
20.0.0.1953
Windows SysTool.exe
Windows SysTool.exe
ProtectService.exe_3960:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
GET %s%s%s HTTP/1.1
GET %s%s%s HTTP/1.1
Host: %s
Host: %s
%sUser-Agent: Mozilla/4.0
%sUser-Agent: Mozilla/4.0
POST %s HTTP/1.1
POST %s HTTP/1.1
%sContent-Type: %s
%sContent-Type: %s
User-Agent: Mozilla/4.0
User-Agent: Mozilla/4.0
Content-Length: %u
Content-Length: %u
%*s %d %*s
%*s %d %*s
%*[ ]%[^
%*[ ]%[^
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
file_url
file_url
E:\supsoft\SupSearchProtectV4\SearchProtect\Bin\Release\ProtectService.pdb
E:\supsoft\SupSearchProtectV4\SearchProtect\Bin\Release\ProtectService.pdb
GetProcessHeap
GetProcessHeap
GetSystemWindowsDirectoryW
GetSystemWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
RegOpenKeyW
RegOpenKeyW
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
SHELL32.dll
SHELL32.dll
MSVCP110.dll
MSVCP110.dll
InternetCrackUrlW
InternetCrackUrlW
WININET.dll
WININET.dll
WS2_32.dll
WS2_32.dll
SHLWAPI.dll
SHLWAPI.dll
MSVCR110.dll
MSVCR110.dll
_crt_debugger_hook
_crt_debugger_hook
__crtUnhandledException
__crtUnhandledException
__crtTerminateProcess
__crtTerminateProcess
_calloc_crt
_calloc_crt
__crtGetShowWindowMode
__crtGetShowWindowMode
_amsg_exit
_amsg_exit
_wcmdln
_wcmdln
__crtSetUnhandledExceptionFilter
__crtSetUnhandledExceptionFilter
WinHttpCloseHandle
WinHttpCloseHandle
WinHttpOpen
WinHttpOpen
WinHttpSetTimeouts
WinHttpSetTimeouts
WinHttpCrackUrl
WinHttpCrackUrl
WinHttpConnect
WinHttpConnect
WinHttpOpenRequest
WinHttpOpenRequest
WinHttpSetOption
WinHttpSetOption
WinHttpAddRequestHeaders
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpWriteData
WinHttpWriteData
WinHttpReceiveResponse
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReadData
WINHTTP.dll
WINHTTP.dll
SensApi.dll
SensApi.dll
VERSION.dll
VERSION.dll
PSAPI.DLL
PSAPI.DLL
USERENV.dll
USERENV.dll
.?AVCHttpClient@@
.?AVCHttpClient@@
.?AVCTcpipSocket@@
.?AVCTcpipSocket@@
2-2v2
2-2v2
hXXp://
hXXp://
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion\Internet Settings
http=
http=
WinHttpClient
WinHttpClient
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
hXXp://xa.xingcloud.com
hXXp://xa.xingcloud.com
xxxx
xxxx
%u_%u
%u_%u
%s_%s
%s_%s
%s_X
%s_X
\\.\PhysicalDrive%d
\\.\PhysicalDrive%d
UpDateProcess.exe
UpDateProcess.exe
hXXp://VVV.theviilage.com/searchprotect/up?ptid=%s&sid=%s&ln=%s_%s&ver=%s&uid=%s&dp=%s
hXXp://VVV.theviilage.com/searchprotect/up?ptid=%s&sid=%s&ln=%s_%s&ver=%s&uid=%s&dp=%s
g{2EFFE99D-743D-44D0-BBF2-F9DDDEA2F92D}
g{2EFFE99D-743D-44D0-BBF2-F9DDDEA2F92D}
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
Report HeartBeat
Report HeartBeat
cmdshell.exe
cmdshell.exe
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=visit.heartbeat.%s&update0=ref,%s&update1=nation,%s&update2=language,%s&update3=version,%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=visit.heartbeat.%s&update0=ref,%s&update1=nation,%s&update2=language,%s&update3=version,%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action0=xa.geoip&action1=visit&action2=install
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action0=xa.geoip&action1=visit&action2=install
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=uninstall
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=uninstall
explorer.exe
explorer.exe
Advapi32.dll
Advapi32.dll
"%s" %s
"%s" %s
psapi.dll
psapi.dll
Explorer.exe
Explorer.exe
json_value.cpp
json_value.cpp
ljson_reader.cpp
ljson_reader.cpp
ProtectSvc.exe
ProtectSvc.exe
4.0.1.2105
4.0.1.2105
HPNotify.exe_2060:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
wszUrl
wszUrl
strUrlTemp
strUrlTemp
hKEY
hKEY
strSelUrl
strSelUrl
strUrl
strUrl
strConfUrlTemp
strConfUrlTemp
strDsUrl
strDsUrl
strHpUrl
strHpUrl
strCmdLine
strCmdLine
tCPW
tCPW
%UUUU
%UUUU
e_GetBrowserCurrentHpUrl
e_GetBrowserCurrentHpUrl
e_GetBrowserCurrentDsUrl
e_GetBrowserCurrentDsUrl
URLDownloadToFileW
URLDownloadToFileW
URLDownloadToFileW ret:0XX
URLDownloadToFileW ret:0XX
Error : %d
Error : %d
inflate 1.1.3 Copyright 1995-1998 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
1.1.3
1.1.3
monochrome
monochrome
unsupported bit depth
unsupported bit depth
`'\%D,3
`'\%D,3
Run-Time Check Failure #%d - %s
Run-Time Check Failure #%d - %s
%s%s%p%s%ld%s%d%s
%s%s%p%s%ld%s%d%s
%s%s%s%s
%s%s%s%s
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
del /s/q %1\*.*
del /s/q %1\*.*
%suninstall.bat
%suninstall.bat
E:\supsoft\SupSearchProtectV4\SearchProtect\bin\Release\HPNotify.pdb
E:\supsoft\SupSearchProtectV4\SearchProtect\bin\Release\HPNotify.pdb
KERNEL32.dll
KERNEL32.dll
GetKeyState
GetKeyState
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
ShellExecuteA
ShellExecuteA
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
SHDeleteKeyW
SHDeleteKeyW
SHLWAPI.dll
SHLWAPI.dll
MSVCP110.dll
MSVCP110.dll
MSVCR110.dll
MSVCR110.dll
_calloc_crt
_calloc_crt
_CRT_RTC_INITW
_CRT_RTC_INITW
__crtGetShowWindowMode
__crtGetShowWindowMode
_amsg_exit
_amsg_exit
_wcmdln
_wcmdln
_crt_debugger_hook
_crt_debugger_hook
__crtUnhandledException
__crtUnhandledException
__crtTerminateProcess
__crtTerminateProcess
__crtSetUnhandledExceptionFilter
__crtSetUnhandledExceptionFilter
GdiplusShutdown
GdiplusShutdown
gdiplus.dll
gdiplus.dll
IMM32.dll
IMM32.dll
DeleteUrlCacheEntryW
DeleteUrlCacheEntryW
WININET.dll
WININET.dll
COMCTL32.dll
COMCTL32.dll
GetProcessHeap
GetProcessHeap
#*1892 $
#*1892 $
%,3:;4-&
%,3:;4-&
.?AVCActiveXEnum@DuiLib@@
.?AVCActiveXEnum@DuiLib@@
.?AVCWebBrowserUI@DuiLib@@
.?AVCWebBrowserUI@DuiLib@@
3?3
3?3
1-2}2
1-2}2
77t7
77t7
9":,:6:@:
9":,:6:@:
12u2
12u2
: :$:(:,:0:
: :$:(:,:0:
4 4$4(4,404
4 4$4(4,404
>$?(?,?0?
>$?(?,?0?
2 2$2(2,20242
2 2$2(2,20242
0 1@1\1|1
0 1@1\1|1
hXXp://VVV.bing.com/
hXXp://VVV.bing.com/
hXXp://VVV.yahoo.com/
hXXp://VVV.yahoo.com/
hXXp://VVV.google.com/
hXXp://VVV.google.com/
%sconf
%sconf
web/?type=dspp&
web/?type=dspp&
web/?type=dspp
web/?type=dspp
hXXp://VVV.v9.com/
hXXp://VVV.v9.com/
Itemd
Itemd
BrowserAction.dll
BrowserAction.dll
%u_%u
%u_%u
%s_%s
%s_%s
%s_X
%s_X
\\.\PhysicalDrive%d
\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
UrlEdit
UrlEdit
conf.xml
conf.xml
hXXp://v9.com/license_agreement.html
hXXp://v9.com/license_agreement.html
hXXp://v9.com/privacy_policy.html
hXXp://v9.com/privacy_policy.html
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.show.%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.show.%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.other.%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.other.%s
%stmp%d.tmp
%stmp%d.tmp
urlmon.dll
urlmon.dll
main.xml
main.xml
explorer.exe
explorer.exe
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
IeWatchDog.dll
IeWatchDog.dll
BrowerWatchFF.dll
BrowerWatchFF.dll
BrowerWatchCH.dll
BrowerWatchCH.dll
Global\GUID(6D05BFEC-4307-4649-8963-962A24345DF4)
Global\GUID(6D05BFEC-4307-4649-8963-962A24345DF4)
msimg32.dll
msimg32.dll
User32.dll
User32.dll
WM_KEYDOWN
WM_KEYDOWN
WM_KEYUP
WM_KEYUP
WM_SYSKEYDOWN
WM_SYSKEYDOWN
WM_SYSKEYUP
WM_SYSKEYUP
0xX
0xX
keyboard
keyboard
msftedit.dll
msftedit.dll
password
password
%s%s%s
%s%s%s
Correct password required
Correct password required
%s\%s
%s\%s
WebBrowser
WebBrowser
transshadow
transshadow
transshadow1
transshadow1
dest='%d,%d,%d,%d'
dest='%d,%d,%d,%d'
dest='%d,%d,%d,%d' source='%d,%d,%d,%d'
dest='%d,%d,%d,%d' source='%d,%d,%d,%d'
source='%d,%d,%d,%d' dest='%d,%d,%d,%d'
source='%d,%d,%d,%d' dest='%d,%d,%d,%d'
M-d-d
M-d-d
WebBrowserUI
WebBrowserUI
errorUrl
errorUrl
{D27CDB6E-AE6D-11CF-96B8-444553540000}
{D27CDB6E-AE6D-11CF-96B8-444553540000}
user32.dll
user32.dll
MSPDB110.DLL
MSPDB110.DLL
ADVAPI32.DLL
ADVAPI32.DLL
/c ping 127.0.0.1 -n 2 > nul && del /s/q
/c ping 127.0.0.1 -n 2 > nul && del /s/q
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
%Program Files% (x86)\XTab\skin\
%Program Files% (x86)\XTab\skin\
SupHPNot.exe
SupHPNot.exe
4,0,1,1716
4,0,1,1716
SupHPNty.exe
SupHPNty.exe
YouTubeAcceleratorService.exe_2932:
.text
.text
`.rdata
`.rdata
@.data
@.data
.text1
.text1
.adata
.adata
.data1
.data1
.pdata
.pdata
.rsrc
.rsrc
uh9.tZ
uh9.tZ
otuh9.tZ
otuh9.tZ
tZ9.tB
tZ9.tB
tV9.tB
tV9.tB
l$$9.tZ
l$$9.tZ
t9.tZ
t9.tZ
uB9.tF
uB9.tF
Windows CE
Windows CE
Windows 7
Windows 7
Windows Vista
Windows Vista
Windows 2003 Server
Windows 2003 Server
Windows XP
Windows XP
Windows 2000
Windows 2000
Windows NT
Windows NT
Windows Me
Windows Me
Windows 98
Windows 98
Windows 95
Windows 95
[CAcceleratorService::ExecuteServerAsWD] Exit
[CAcceleratorService::ExecuteServerAsWD] Exit
[CAcceleratorService::ExecuteServerAsWD] Impersonate Wakeup
[CAcceleratorService::ExecuteServerAsWD] Impersonate Wakeup
\\.\pipe\GOOBZO_VAPIPESERVERENG
\\.\pipe\GOOBZO_VAPIPESERVERENG
[CAcceleratorService::ExecuteServerAsWD] Enter
[CAcceleratorService::ExecuteServerAsWD] Enter
[CAcceleratorService::CreateEngineThread] Create thread result %d
[CAcceleratorService::CreateEngineThread] Create thread result %d
[CAcceleratorService::CreateEngineThread] ___Error Creating the Engine Keep Alive event. error: %d
[CAcceleratorService::CreateEngineThread] ___Error Creating the Engine Keep Alive event. error: %d
[CAcceleratorService::StopServiceExitMode] Name: %s
[CAcceleratorService::StopServiceExitMode] Name: %s
[CAcceleratorService::ProcessTimeoutEvent] ___Error wait for thread termination result %d
[CAcceleratorService::ProcessTimeoutEvent] ___Error wait for thread termination result %d
[CAcceleratorService::ProcessTimeoutEvent] ___Error StopThread result %d
[CAcceleratorService::ProcessTimeoutEvent] ___Error StopThread result %d
[CAcceleratorService::ExecuteServer] Leave
[CAcceleratorService::ExecuteServer] Leave
[CAcceleratorService::ExecuteServer] Calling to ExecuteServerAsWD
[CAcceleratorService::ExecuteServer] Calling to ExecuteServerAsWD
[CAcceleratorService::ExecuteServer] ___Error creating the service named event. LE: %d
[CAcceleratorService::ExecuteServer] ___Error creating the service named event. LE: %d
[CAcceleratorService::ExecuteServer] Enter
[CAcceleratorService::ExecuteServer] Enter
%d.%d.%d.%d
%d.%d.%d.%d
Name: %s
Name: %s
Path: %s
Path: %s
Version: %s
Version: %s
%s_%d.log
%s_%d.log
[CAcceleratorService::InstallDriver] Driver name: %s, Driver path: %s
[CAcceleratorService::InstallDriver] Driver name: %s, Driver path: %s
[CAcceleratorService::UninstallDriver] Driver name: %s
[CAcceleratorService::UninstallDriver] Driver name: %s
[CAcceleratorService::InstallLsp] Module not found - LE: %d
[CAcceleratorService::InstallLsp] Module not found - LE: %d
[CAcceleratorService::InstallLsp] Function Install not found - LE: %d
[CAcceleratorService::InstallLsp] Function Install not found - LE: %d
[CAcceleratorService::InstallLsp] Module path: %s
[CAcceleratorService::InstallLsp] Module path: %s
[CAcceleratorService::UninstallLsp] Module not found - LE: %d
[CAcceleratorService::UninstallLsp] Module not found - LE: %d
[CAcceleratorService::UninstallLsp] Function Remove not found - LE: %d
[CAcceleratorService::UninstallLsp] Function Remove not found - LE: %d
[CAcceleratorService::UninstallLsp] Module path: %s
[CAcceleratorService::UninstallLsp] Module path: %s
[CAcceleratorService::RunCommand] Command: %d
[CAcceleratorService::RunCommand] Command: %d
[CLSPKeepAlive::GetLastLSPTestStatus] return %d
[CLSPKeepAlive::GetLastLSPTestStatus] return %d
[CLSPKeepAlive::CheckOurLSPStatus]
[CLSPKeepAlive::CheckOurLSPStatus]
[CLSPKeepAlive::Work] CheckOurLSPStatus - our LSP is installed!
[CLSPKeepAlive::Work] CheckOurLSPStatus - our LSP is installed!
[CLSPKeepAlive::Work] ___Error CheckOurLSPStatus - *** SBLSP NOT Installed ***
[CLSPKeepAlive::Work] ___Error CheckOurLSPStatus - *** SBLSP NOT Installed ***
[CLSPKeepAlive::Work] ___Error creating the service named event. LE: %d
[CLSPKeepAlive::Work] ___Error creating the service named event. LE: %d
%sLow\%s\
%sLow\%s\
%C:\Users\Public\Documents\%s\%s\
%C:\Users\Public\Documents\%s\%s\
%s\%s\%s\
%s\%s\%s\
%s\Application Data\%s\%s\
%s\Application Data\%s\%s\
[CDriverManager::CreateDriver] CreateService failed: %d
[CDriverManager::CreateDriver] CreateService failed: %d
Tcpip
Tcpip
[CDriverManager::CreateDriver] Name: %s, Path: %s
[CDriverManager::CreateDriver] Name: %s, Path: %s
[CDriverManager::Install] OpenSCManager failed: %d
[CDriverManager::Install] OpenSCManager failed: %d
[CDriverManager::Install] Name: %s, Path: %s
[CDriverManager::Install] Name: %s, Path: %s
[CDriverManager::DeleteDriver] DeleteService failed: %d
[CDriverManager::DeleteDriver] DeleteService failed: %d
[CDriverManager::DeleteDriver] OpenService failed: %d
[CDriverManager::DeleteDriver] OpenService failed: %d
[CDriverManager::DeleteDriver] Name: %s
[CDriverManager::DeleteDriver] Name: %s
[CDriverManager::UnInstall] OpenSCManager failed: %d
[CDriverManager::UnInstall] OpenSCManager failed: %d
[CDriverManager::UnInstall] Name: %s
[CDriverManager::UnInstall] Name: %s
[CDriverManager::StartDriver] OpenService failed: %d
[CDriverManager::StartDriver] OpenService failed: %d
[CDriverManager::StartDriver] Name: %s
[CDriverManager::StartDriver] Name: %s
[CDriverManager::Load] OpenSCManager failed: %d
[CDriverManager::Load] OpenSCManager failed: %d
[CDriverManager::Load] Name: %s
[CDriverManager::Load] Name: %s
[CDriverManager::StopDriver] OpenService failed: %d
[CDriverManager::StopDriver] OpenService failed: %d
[CDriverManager::StopDriver] Name: %s
[CDriverManager::StopDriver] Name: %s
[CDriverManager::UnLoad] OpenSCManager failed: %d
[CDriverManager::UnLoad] OpenSCManager failed: %d
[CDriverManager::UnLoad] Name: %s
[CDriverManager::UnLoad] Name: %s
[CEventsThread::SetTimeoutResolution] From: %d -> To: %d
[CEventsThread::SetTimeoutResolution] From: %d -> To: %d
[CEventsThread::WaitForMultipleEvents] Released on Signaled: %d ms
[CEventsThread::WaitForMultipleEvents] Released on Signaled: %d ms
[CEventsThread::WaitForMultipleEvents] Released on Timeout: %d ms
[CEventsThread::WaitForMultipleEvents] Released on Timeout: %d ms
[CEventsThread::WaitForMultipleEvents] ___Error MsgWaitForMultipleObjectsEx. LE: %d
[CEventsThread::WaitForMultipleEvents] ___Error MsgWaitForMultipleObjectsEx. LE: %d
[CEventsThread::WaitForMultipleEvents] TID=%X
[CEventsThread::WaitForMultipleEvents] TID=%X
[CEventsThread::CreateNamedEvent] OpenEvent. LE: %d
[CEventsThread::CreateNamedEvent] OpenEvent. LE: %d
[CEventsThread::CreateNamedEvent] ___Error OpenEvent: LE: %d
[CEventsThread::CreateNamedEvent] ___Error OpenEvent: LE: %d
[CEventsThread::CreateNamedEvent] ___Error CreateEvent. LE: %d. Try OpenEvent...
[CEventsThread::CreateNamedEvent] ___Error CreateEvent. LE: %d. Try OpenEvent...
[CEventsThread::Start - Leave] TID=%X
[CEventsThread::Start - Leave] TID=%X
[CEventsThread::Start] ___Error - Failed to create thread: %X
[CEventsThread::Start] ___Error - Failed to create thread: %X
[CEventsThread::Stop - Leave] TID=%X
[CEventsThread::Stop - Leave] TID=%X
[CEventsThread::Stop - Enter] TID=%X
[CEventsThread::Stop - Enter] TID=%X
[CEventsThread::CallProcessTimeoutRoutines] ___Error Invalid Event Entry: %d, Timeout: %d
[CEventsThread::CallProcessTimeoutRoutines] ___Error Invalid Event Entry: %d, Timeout: %d
[CEventsThread::AlertEvent] ___Error SetEvent failed: %d
[CEventsThread::AlertEvent] ___Error SetEvent failed: %d
[CEventsThread::AlertEvent] ___Error Invalid Event Entry: %d
[CEventsThread::AlertEvent] ___Error Invalid Event Entry: %d
[CEventsThread::AlertEvent] ___Error Not found Event: %d
[CEventsThread::AlertEvent] ___Error Not found Event: %d
[CEventsThread::SetGlobalEvent] ___Error Invalid Event Entry: %d
[CEventsThread::SetGlobalEvent] ___Error Invalid Event Entry: %d
[CEventsThread::SetGlobalEvent] ___Error Not found Event: %d
[CEventsThread::SetGlobalEvent] ___Error Not found Event: %d
[CEventsThread::SetGlobalEvent] Event: %d
[CEventsThread::SetGlobalEvent] Event: %d
[CEventsThread::ResetEvent] ___Error ResetEvent failed: %d
[CEventsThread::ResetEvent] ___Error ResetEvent failed: %d
[CEventsThread::ResetEvent] ___Error Invalid Event Entry: %d
[CEventsThread::ResetEvent] ___Error Invalid Event Entry: %d
[CEventsThread::ResetEvent] ___Error Not found Event: %d
[CEventsThread::ResetEvent] ___Error Not found Event: %d
[CEventsThread::ResetEvent] Event: %d
[CEventsThread::ResetEvent] Event: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Entry: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Entry: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Index: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Index: %d
[CEventsThread::RemoveEvent] ___Error CloseHandle failed: %d
[CEventsThread::RemoveEvent] ___Error CloseHandle failed: %d
[CEventsThread::RemoveEvent] ___Error Invalid Event Entry: %d
[CEventsThread::RemoveEvent] ___Error Invalid Event Entry: %d
[CEventsThread::RemoveEvent] ___Error Not found Event: %d
[CEventsThread::RemoveEvent] ___Error Not found Event: %d
[CEventsThread::RemoveEvent] Event: %d
[CEventsThread::RemoveEvent] Event: %d
[CEventsThread::Cleanup] ___Error CloseHandle(0x%p) failed: %d
[CEventsThread::Cleanup] ___Error CloseHandle(0x%p) failed: %d
[CEventsThread::Cleanup] Closing Handle: %d
[CEventsThread::Cleanup] Closing Handle: %d
[CEventsThread::WaitEvent] TID=%X
[CEventsThread::WaitEvent] TID=%X
[CEventsThread::Work] TID=%X - Exit !!!
[CEventsThread::Work] TID=%X - Exit !!!
[CEventsThread::Work] WAIT_ABANDONED - %d
[CEventsThread::Work] WAIT_ABANDONED - %d
[CEventsThread::Work] TID=%X
[CEventsThread::Work] TID=%X
[CEventsThread::AddEvent] ___Warning event handle already exists %d
[CEventsThread::AddEvent] ___Warning event handle already exists %d
[CEventsThread::AddEvent] ___Error invalid event handle %d
[CEventsThread::AddEvent] ___Error invalid event handle %d
[CImpersonate::Impersonate] ImpersonateLoggedOnUser - Error: %d
[CImpersonate::Impersonate] ImpersonateLoggedOnUser - Error: %d
[CImpersonate::Impersonate] Impersonated: %d
[CImpersonate::Impersonate] Impersonated: %d
[CImpersonate::Revert] RevertToSelf - Error: %d
[CImpersonate::Revert] RevertToSelf - Error: %d
[CImpersonate::Revert] Impersonated: %d
[CImpersonate::Revert] Impersonated: %d
[CImpersonate::Cleanup] Impersonated: %d
[CImpersonate::Cleanup] Impersonated: %d
[CImpersonate::GetUserSID] LookupAccountNameW failed. GetLastError returned: %d
[CImpersonate::GetUserSID] LookupAccountNameW failed. GetLastError returned: %d
[CImpersonate::GetUserSID] The SID for %s is invalid.
[CImpersonate::GetUserSID] The SID for %s is invalid.
[CImpersonate::GetUserSID] Not Enough Memory: %d
[CImpersonate::GetUserSID] Not Enough Memory: %d
[CImpersonate::SetPrivilege] AdjustTokenPrivileges - Error: %d
[CImpersonate::SetPrivilege] AdjustTokenPrivileges - Error: %d
[CImpersonate::SetPrivilege] LookupPrivilegeValue - Error: %d
[CImpersonate::SetPrivilege] LookupPrivilegeValue - Error: %d
[CImpersonate::OpenCurrentUserDesktop] - The function does not support Windows Vista and Windows 98
[CImpersonate::OpenCurrentUserDesktop] - The function does not support Windows Vista and Windows 98
[CImpersonate::OpenCurrentUserDesktop] OpenDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenInputDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenInputDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] SetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] SetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] GetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] GetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] - The function does not support MAC
[CImpersonate::OpenCurrentUserDesktop] - The function does not support MAC
[CImpersonate::CreateProcessAsCurrentUser] CreateProcessAsUser - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] CreateProcessAsUser - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] CreateEnvironmentBlock - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] CreateEnvironmentBlock - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetLogonSID - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetLogonSID - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] DuplicateTokenEx - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] DuplicateTokenEx - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] SetProcessWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] SetProcessWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetProcessWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetProcessWindowStation - Error: %d
[CImpersonate::AddAceToWindowStation] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToWindowStation] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToWindowStation] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToWindowStation] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToWindowStation] CopySid - Error: %d
[CImpersonate::AddAceToWindowStation] CopySid - Error: %d
[CImpersonate::AddAceToWindowStation] AddAce - Error: %d
[CImpersonate::AddAceToWindowStation] AddAce - Error: %d
[CImpersonate::AddAceToWindowStation] GetAce - Error: %d
[CImpersonate::AddAceToWindowStation] GetAce - Error: %d
[CImpersonate::AddAceToWindowStation] GetAclInformation - Error: %d
[CImpersonate::AddAceToWindowStation] GetAclInformation - Error: %d
[CImpersonate::AddAceToWindowStation] GetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToWindowStation] GetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] AddAccessAllowedAce - Error: %d
[CImpersonate::AddAceToDesktop] AddAccessAllowedAce - Error: %d
[CImpersonate::AddAceToDesktop] AddAce - Error: %d
[CImpersonate::AddAceToDesktop] AddAce - Error: %d
[CImpersonate::AddAceToDesktop] GetAce - Error: %d
[CImpersonate::AddAceToDesktop] GetAce - Error: %d
[CImpersonate::AddAceToDesktop] GetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] GetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] GetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] GetUserObjectSecurity - Error: %d
[CImpersonate::OpenCurrentUserKey] LoadUserProfile - SUCCESS
[CImpersonate::OpenCurrentUserKey] LoadUserProfile - SUCCESS
[CImpersonate::OpenCurrentUserKey] LoadUserProfile failed - Error: %d
[CImpersonate::OpenCurrentUserKey] LoadUserProfile failed - Error: %d
[CImpersonate::GetLogonUserName] GetLogonUserName - Error: %d
[CImpersonate::GetLogonUserName] GetLogonUserName - Error: %d
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - Error: %d
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - Error: %d
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - SUCCESS
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - SUCCESS
[CImpersonate::OpenCurrentUserKey] Impersonated: %d
[CImpersonate::OpenCurrentUserKey] Impersonated: %d
[CImpersonate::FindLoggedOnUser] Process32First - Error: %d
[CImpersonate::FindLoggedOnUser] Process32First - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcess - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcess - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcessToken - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcessToken - Error: %d
[CImpersonate::FindLoggedOnUser] CreateToolhelp32Snapshot failed - Error: %d
[CImpersonate::FindLoggedOnUser] CreateToolhelp32Snapshot failed - Error: %d
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
explorer.exe
explorer.exe
[CImpersonate::FindLoggedOnUser] Impersonated: %d
[CImpersonate::FindLoggedOnUser] Impersonated: %d
[CImpersonate::GetLogonUserName] Name: %s
[CImpersonate::GetLogonUserName] Name: %s
[CImpersonate::GetLogonUserName] GetUserName - Error: %d
[CImpersonate::GetLogonUserName] GetUserName - Error: %d
[CImpersonateThread::NotifyImpersonateLogon] Time: %d
[CImpersonateThread::NotifyImpersonateLogon] Time: %d
[CImpersonateThread::NotifyImpersonateLogoff] Time: %d
[CImpersonateThread::NotifyImpersonateLogoff] Time: %d
[CImpersonateThread::ProcessEvent] CreateProcess - CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::ProcessEvent] CreateProcess - CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::CreateProcess] CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::CreateProcess] CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(TRUE), LE: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(TRUE), LE: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(FALSE) failed: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(FALSE) failed: %d
engine.dll
engine.dll
DestroyPipeEventThreadManager
DestroyPipeEventThreadManager
CreatePipeEventThreadManager
CreatePipeEventThreadManager
ipc.dll
ipc.dll
xmldb.dll
xmldb.dll
config.xml
config.xml
d/d/%d d:d:d::d 0x%X>
d/d/%d d:d:d::d 0x%X>
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegNotifyChangeKeyValue
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegNotifyChangeKeyValue
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegOpenKeyEx
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegOpenKeyEx
[SbTracer::RecursiveCreateDirectory] Directory: %s
[SbTracer::RecursiveCreateDirectory] Directory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - CreateDirectory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - CreateDirectory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - Directory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - Directory: %s
[SbTracer::ReadConfiguration] Trace Max Size: %d
[SbTracer::ReadConfiguration] Trace Max Size: %d
[SbTracer::ReadConfiguration] Trace Time Stamp: %d
[SbTracer::ReadConfiguration] Trace Time Stamp: %d
[SbTracer::ReadConfiguration] Trace Time Limit: %d
[SbTracer::ReadConfiguration] Trace Time Limit: %d
[SbTracer::ReadConfiguration] Trace Backup: %d
[SbTracer::ReadConfiguration] Trace Backup: %d
[SbTracer::ReadConfiguration] Trace Destination: %d
[SbTracer::ReadConfiguration] Trace Destination: %d
[SbTracer::ReadConfiguration] Trace Level: %d
[SbTracer::ReadConfiguration] Trace Level: %d
[SbTracer::FormatFilePath] Log Path: %s
[SbTracer::FormatFilePath] Log Path: %s
[SbTracer::FormatFilePath] ___Error - RecursiveCreateDirectory: %s
[SbTracer::FormatFilePath] ___Error - RecursiveCreateDirectory: %s
[SbTracer::FormatFilePath] ___Warning - No Log folder: %s
[SbTracer::FormatFilePath] ___Warning - No Log folder: %s
[SbTracer::FormatFilePath] ___Error - GetModuleFileName: %s
[SbTracer::FormatFilePath] ___Error - GetModuleFileName: %s
\StringFileInfo\x\%s
\StringFileInfo\x\%s
[SbTracer::BackupTraceFile] %s
[SbTracer::BackupTraceFile] %s
[SbTracer::OpenTraceFile] Done %s
[SbTracer::OpenTraceFile] Done %s
[SbTracer::OpenTraceFile] ___Error: %d, File: %s
[SbTracer::OpenTraceFile] ___Error: %d, File: %s
[SbTracer::WriteTraceLine] !!! OVERFLOW or FORMAT ERROR !!! - (%d) %s
[SbTracer::WriteTraceLine] !!! OVERFLOW or FORMAT ERROR !!! - (%d) %s
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] SetSecurityDescriptorDacl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] SetSecurityDescriptorDacl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeSecurityDescriptor failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeSecurityDescriptor failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the trusted owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the trusted owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the Everyone group. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the Everyone group. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the queue owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the queue owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeAcl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeAcl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetLogonSID failed. Error code: 0x%X
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetLogonSID failed. Error code: 0x%X
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AllocateAndInitializeSid failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AllocateAndInitializeSid failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetTokenInformation failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetTokenInformation failed. GetLastError returned: %d
[CServiceController::ChangeStartType] ___Error ChangeServiceConfig failed: %d
[CServiceController::ChangeStartType] ___Error ChangeServiceConfig failed: %d
[CServiceController::ChangeStartType] ___Error OpenService: %s, failed: %d
[CServiceController::ChangeStartType] ___Error OpenService: %s, failed: %d
[CServiceController::ChangeStartType] ___Error OpenSCManager failed: %d
[CServiceController::ChangeStartType] ___Error OpenSCManager failed: %d
[CServiceController::ChangeStartType] Name: %s
[CServiceController::ChangeStartType] Name: %s
[CServiceController::ExecuteServer] Exit
[CServiceController::ExecuteServer] Exit
[CServiceController::ExecuteServer] Enter
[CServiceController::ExecuteServer] Enter
[CServiceController::ServiceMain] ___Error SetServiceStatus Failed: %d
[CServiceController::ServiceMain] ___Error SetServiceStatus Failed: %d
[CServiceController::ServiceMain] ___Error RegisterServiceCtrlHandler Failed: %d
[CServiceController::ServiceMain] ___Error RegisterServiceCtrlHandler Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error Exception StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error Exception StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] Enter, %s
[CServiceController::UpdateServiceDespatchTable] Enter, %s
[CServiceController::Remove] ___Error OpenService Failed: %d
[CServiceController::Remove] ___Error OpenService Failed: %d
[CServiceController::Remove] ___Error OpenSCManager Failed: %d
[CServiceController::Remove] ___Error OpenSCManager Failed: %d
[CServiceController::GetStatus] ___Error QueryServiceStatus Failed: %d
[CServiceController::GetStatus] ___Error QueryServiceStatus Failed: %d
[CServiceController::GetStatus] ___Error OpenService Failed: %d
[CServiceController::GetStatus] ___Error OpenService Failed: %d
[CServiceController::GetStatus] ___Error OpenSCManager Failed: %d
[CServiceController::GetStatus] ___Error OpenSCManager Failed: %d
[CServiceController::Start] The service %s was started
[CServiceController::Start] The service %s was started
[CServiceController::Start] ___Error StartService Failed: %d
[CServiceController::Start] ___Error StartService Failed: %d
[CServiceController::Start] ___Error OpenService Failed: %d
[CServiceController::Start] ___Error OpenService Failed: %d
[CServiceController::Start] ___Error OpenSCManager Failed: %d
[CServiceController::Start] ___Error OpenSCManager Failed: %d
[CServiceController::Start] Going to start the service %s
[CServiceController::Start] Going to start the service %s
[CServiceController::Stop] The service %s was stopped
[CServiceController::Stop] The service %s was stopped
YoutubeAcceleratorService.exe
YoutubeAcceleratorService.exe
[CServiceController::Stop] ___Error ControlService Failed: %d
[CServiceController::Stop] ___Error ControlService Failed: %d
[CServiceController::Stop] ___Error OpenService Failed: %d
[CServiceController::Stop] ___Error OpenService Failed: %d
[CServiceController::Stop] Going to stop the service %s
[CServiceController::Stop] Going to stop the service %s
[CServiceController::Stop] ___Error SetServiceStatus Failed: %d
[CServiceController::Stop] ___Error SetServiceStatus Failed: %d
[CServiceController::Install] ___Error OpenService Failed: %d
[CServiceController::Install] ___Error OpenService Failed: %d
[CServiceController::Install] ___Error QueryServiceStatus Failed: %d
[CServiceController::Install] ___Error QueryServiceStatus Failed: %d
[CServiceController::Install] ___Error CreateService Failed: %d
[CServiceController::Install] ___Error CreateService Failed: %d
[CServiceController::Install] ___Error OpenSCManager Failed: %d
[CServiceController::Install] ___Error OpenSCManager Failed: %d
%s -%s -%s
%s -%s -%s
%s\%s
%s\%s
[CServiceController::Install] ___Error GetModuleFileName Failed: %d
[CServiceController::Install] ___Error GetModuleFileName Failed: %d
[CServiceController::GetArgsFromCmd] Exit
[CServiceController::GetArgsFromCmd] Exit
[CServiceController::GetArgsFromCmd] m_bSCMCmd = TRUE
[CServiceController::GetArgsFromCmd] m_bSCMCmd = TRUE
[CServiceController::GetArgsFromCmd] Enter
[CServiceController::GetArgsFromCmd] Enter
[CServiceController::RunCommand] Args: %s
[CServiceController::RunCommand] Args: %s
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
operator
operator
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
c:\BUILDS\Build_YTA\Client\VA_3_2\Bin\Release\YouTubeAcceleratorService.pdb
c:\BUILDS\Build_YTA\Client\VA_3_2\Bin\Release\YouTubeAcceleratorService.pdb
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
ADVAPI32.dll
ADVAPI32.dll
SHELL32.dll
SHELL32.dll
VERSION.dll
VERSION.dll
USERENV.dll
USERENV.dll
PSAPI.DLL
PSAPI.DLL
.?AVIPipeEventsThread@@
.?AVIPipeEventsThread@@
.?AVCPipeEventThread@@
.?AVCPipeEventThread@@
.?AV?$IMultiBaseInterface@VIPipeEventThreadManagerFactory@@@@
.?AV?$IMultiBaseInterface@VIPipeEventThreadManagerFactory@@@@
.?AVIPipeEventThreadManagerFactory@@
.?AVIPipeEventThreadManagerFactory@@
.?AV?$CMultiBaseInterface@VCPipeEventThreadManagerFactory@@VIPipeEventThreadManagerFactory@@@@
.?AV?$CMultiBaseInterface@VCPipeEventThreadManagerFactory@@VIPipeEventThreadManagerFactory@@@@
.?AVCPipeEventThreadManagerFactory@@
.?AVCPipeEventThreadManagerFactory@@
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe
aSSSh
aSSSh
FTPjK
FTPjK
FtPj;
FtPj;
C.PjRV
C.PjRV
]@ ]( ]8
]@ ]( ]8
tGHt.Ht&
tGHt.Ht&
FTPQ
FTPQ
.?AVunsupported_thread_option@boost@@
.?AVunsupported_thread_option@boost@@
zcÃ
zcÃ
SetProcessShutdownParameters
SetProcessShutdownParameters
kernel32.dll
kernel32.dll
COMCTL32.DLL
COMCTL32.DLL
boost::too_few_args: format-string referred to more arguments than were passed
boost::too_few_args: format-string referred to more arguments than were passed
boost::too_many_args: format-string referred to less arguments than were passed
boost::too_many_args: format-string referred to less arguments than were passed
Required USB Key not found
Required USB Key not found
Failed to execute target process
Failed to execute target process
Cannot find import; DLL may be missing, corrupt, or wrong version
Cannot find import; DLL may be missing, corrupt, or wrong version
File "%s", function "%s"
File "%s", function "%s"
File "%s", ordinal %d
File "%s", ordinal %d
File "%s", error %d
File "%s", error %d
(Error code %d)
(Error code %d)
%X:DAF
%X:DAF
(Location XEB, error code %d)
(Location XEB, error code %d)
_PAD%d
_PAD%d
RNX
RNX
%X::DAX
%X::DAX
KERNEL32.DLL
KERNEL32.DLL
.DbgLog
.DbgLog
GetWindowsDirectoryW
GetWindowsDirectoryW
CreateDialogIndirectParamW
CreateDialogIndirectParamW
Kernel32.dll
Kernel32.dll
User32.dll
User32.dll
ComDlg32.dll
ComDlg32.dll
1.2.3
1.2.3
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_DENORMAL_OPERAND
EXCEPTION_FLT_DENORMAL_OPERAND
boost::unsupported_thread_option
boost::unsupported_thread_option
mscoree.dll
mscoree.dll
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
.mixcrt
.mixcrt
ADVAPI32.DLL
ADVAPI32.DLL
portuguese-brazilian
portuguese-brazilian
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService-2.DbgLog
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService-2.DbgLog
GetWindowsDirectoryA
GetWindowsDirectoryA
EnumThreadWindows
EnumThreadWindows
EnumWindows
EnumWindows
CreateDialogIndirectParamA
CreateDialogIndirectParamA
GetAsyncKeyState
GetAsyncKeyState
GDI32.dll
GDI32.dll
comdlg32.dll
comdlg32.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
GetConsoleOutputCP
GetConsoleOutputCP
^.Ad/
^.Ad/
.Zvv[
.Zvv[
j%FwL
j%FwL
e.tu/
e.tu/
5%up/
5%up/
A.YNpN\n
A.YNpN\n
%Um-IF
%Um-IF
.BV$L|
.BV$L|
%X1:S
%X1:S
`?T%Sj
`?T%Sj
%x@k4
%x@k4
.iyDY
.iyDY
j.Wsf
j.Wsf
Cr.BxL
Cr.BxL
V.Fb7|
V.Fb7|
$"bM-Q}n
$"bM-Q}n
%x R\X
%x R\X
4%sPp
4%sPp
_%S3@
_%S3@
.LvHT
.LvHT
.owm;y,
.owm;y,
}R.zmA
}R.zmA
.bi@{
.bi@{
>I|.pt|d
>I|.pt|d
t_\A
t_\A
p}.GF
p}.GF
G){.mf
G){.mf
.xh$x
.xh$x
U.gs!
U.gs!
J|0.tL
J|0.tL
.iJp`
.iJp`
.zE:aG
.zE:aG
.7%Xs
.7%Xs
-DED%xFqz
-DED%xFqz
%cnzb
%cnzb
%UQzss
%UQzss
1%.Ey\=
1%.Ey\=
/\%Dg
/\%Dg
.FlC\5
.FlC\5
.cA~;
.cA~;
P?=I_.or\
P?=I_.or\
E.yb|4
E.yb|4
%SuSw
%SuSw
T.UHuR
T.UHuR
LZÃ
LZÃ
Q,-I}g_
Q,-I}g_
4.gtE
4.gtE
-;M.EZk
-;M.EZk
1:](P%X
1:](P%X
g.RUg
g.RUg
fH.XFH
fH.XFH
.cP;_
.cP;_
OUTUB~1\YouTubeAcceleratorService.exe
OUTUB~1\YouTubeAcceleratorService.exe
3.3.9.5
3.3.9.5
YouTubeAccelerator.exe_684:
.text
.text
`.rdata
`.rdata
@.data
@.data
.text1
.text1
.adata
.adata
.data1
.data1
.pdata
.pdata
.rsrc
.rsrc
uh9.tZ
uh9.tZ
otuh9.tZ
otuh9.tZ
tZ9.tB
tZ9.tB
tV9.tB
tV9.tB
l$$9.tZ
l$$9.tZ