Technical Information
- iexplore.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1bd7b34-b329-4f12-87d2-e9053e3db77b}]
- %TEMP%\47636ca4\3nwifzyd9oqhydh.dat
- C:\documents and settings\aspnet\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\guest\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\guest\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\guest\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\helpassistant\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\helpassistant\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\helpassistant\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\support_388945a0\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\support_388945a0\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\guest\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\aspnet\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\helpassistant\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\helpassistant\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\helpassistant\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- <LS_APPDATA>\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- <LS_APPDATA>\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- <LS_APPDATA>\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- <LS_APPDATA>\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\aspnet\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\torch\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\support_388945a0\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\support_388945a0\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- <SYSTEM32>\grouppolicy\machine\registry.pol
- %APPDATA%\mozilla\firefox\profiles\22ie2h77.default\extensions\staged\db6g@heqgvxn.com\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\22ie2h77.default\extensions\staged\db6g@heqgvxn.com\chrome.manifest
- C:\documents and settings\aspnet\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- %APPDATA%\mozilla\firefox\profiles\22ie2h77.default\extensions\staged\db6g@heqgvxn.com\content\bg.js
- %ProgramFiles%\priceless\oozxlbpgb0jpfl.dll
- %ProgramFiles%\priceless\oozxlbpgb0jpfl.tlb
- %ProgramFiles%\priceless\oozxlbpgb0jpfl.dat
- %ProgramFiles%\priceless\oozxlbpgb0jpfl.x64.dll
- %ALLUSERSPROFILE%\application data\priceless\3nwifzyd9oqhydh.exe
- %ALLUSERSPROFILE%\application data\priceless\3nwifzyd9oqhydh.dat
- C:\documents and settings\support_388945a0\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\support_388945a0\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- <LS_APPDATA>\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\aspnet\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\aspnet\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\aspnet\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\aspnet\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\guest\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\guest\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\guest\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\helpassistant\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- <LS_APPDATA>\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\helpassistant\local settings\application data\chromatic browser\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\guest\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\aspnet\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\guest\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\guest\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\guest\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\helpassistant\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\helpassistant\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\helpassistant\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\helpassistant\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\aspnet\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\aspnet\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- <LS_APPDATA>\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- %TEMP%\47636ca4\oozxlbpgb0jpfl.dll
- %TEMP%\47636ca4\oozxlbpgb0jpfl.tlb
- %TEMP%\47636ca4\oozxlbpgb0jpfl.x64.dll
- %TEMP%\47636ca4\db6g@heqgvxn.com\content\bg.js
- %TEMP%\47636ca4\db6g@heqgvxn.com\bootstrap.js
- %TEMP%\47636ca4\db6g@heqgvxn.com\chrome.manifest
- %TEMP%\47636ca4\db6g@heqgvxn.com\install.rdf
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\rwly2.js
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\background.html
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\manifest.json
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\content.js
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\lsdb.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- <LS_APPDATA>\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- <LS_APPDATA>\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\google\chrome\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\support_388945a0\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\support_388945a0\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\support_388945a0\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- <LS_APPDATA>\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\aspnet\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\aspnet\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\aspnet\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\aspnet\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\aspnet\local settings\application data\google\chrome sxs\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\support_388945a0\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\helpassistant\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\helpassistant\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\google\chrome\user data\default\preferences__.tmp
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\aspnet\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\aspnet\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- %ALLUSERSPROFILE%\application data\d8de867c1cff2d41\{75f9bf4a-af67-a478-a37b-31d73186d3f3}.20190720232221
- %APPDATA%\mozilla\firefox\profiles\22ie2h77.default\extensions\staged\db6g@heqgvxn.com\install.rdf
- C:\documents and settings\aspnet\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\guest\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\content.js
- C:\documents and settings\guest\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\lsdb.js
- C:\documents and settings\guest\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\manifest.json
- C:\documents and settings\guest\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- C:\documents and settings\helpassistant\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- <LS_APPDATA>\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\background.html
- C:\documents and settings\aspnet\local settings\application data\comodo\dragon\user data\default\extensions\nnddpmoajoahndjidabmolihjoplcfoe\5.2\rwly2.js
- %ALLUSERSPROFILE%\ntuser.pol
- %TEMP%\47636ca4\3nwifzyd9oqhydh.dat
- %TEMP%\47636ca4\oozxlbpgb0jpfl.dll
- %TEMP%\47636ca4\oozxlbpgb0jpfl.tlb
- %TEMP%\47636ca4\oozxlbpgb0jpfl.x64.dll
- %TEMP%\47636ca4\db6g@heqgvxn.com\content\bg.js
- %TEMP%\47636ca4\db6g@heqgvxn.com\bootstrap.js
- %TEMP%\47636ca4\db6g@heqgvxn.com\chrome.manifest
- %TEMP%\47636ca4\db6g@heqgvxn.com\install.rdf
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\rwly2.js
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\background.html
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\manifest.json
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\content.js
- %TEMP%\47636ca4\nnddpmoajoahndjidabmolihjoplcfoe\lsdb.js
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\PriceLess\oOZxLbPGb0jPfL.x64.dll"