Technical Information
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\YouutubeAdBLocKe\Hdcw9Bun7y3jpo.x64.dll"
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{477d1c22-3106-4eb6-9156-6aaf91fcd0ab}']
- %ProgramFiles%\YouutubeAdBLocKe\Hdcw9Bun7y3jpo.dll
- %ProgramFiles%\YouutubeAdBLocKe\Hdcw9Bun7y3jpo.tlb
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\zUQAOhzKey@s.net\content\bg.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\zUQAOhzKey@s.net\install.rdf
- %ProgramFiles%\YouutubeAdBLocKe\Hdcw9Bun7y3jpo.dat
- %ALLUSERSPROFILE%\Application Data\YouutubeAdBLocKe\OQo3qL1taEdQMZo.dat
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.20161209201420
- %ProgramFiles%\YouutubeAdBLocKe\Hdcw9Bun7y3jpo.x64.dll
- %ALLUSERSPROFILE%\Application Data\YouutubeAdBLocKe\OQo3qL1taEdQMZo.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\zUQAOhzKey@s.net\chrome.manifest
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.tlb
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.x64.dll
- %TEMP%\08a55b16\OQo3qL1taEdQMZo.dat
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.dll
- %TEMP%\08a55b16\zUQAOhzKey@s.net\content\bg.js
- %TEMP%\08a55b16\zUQAOhzKey@s.net\install.rdf
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\zUQAOhzKey@s.net\bootstrap.js
- %TEMP%\08a55b16\zUQAOhzKey@s.net\bootstrap.js
- %TEMP%\08a55b16\zUQAOhzKey@s.net\chrome.manifest
- %TEMP%\08a55b16\zUQAOhzKey@s.net\bootstrap.js
- %TEMP%\08a55b16\zUQAOhzKey@s.net\content\bg.js
- %TEMP%\08a55b16\zUQAOhzKey@s.net\install.rdf
- %TEMP%\08a55b16\zUQAOhzKey@s.net\chrome.manifest
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.dll
- %TEMP%\08a55b16\OQo3qL1taEdQMZo.dat
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.x64.dll
- %TEMP%\08a55b16\Hdcw9Bun7y3jpo.tlb