Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC695699-4B86-6A64-2E83-2A518CAA6F77}]
- %TEMP%\507f7b5e\vqewa4hc.dat
- C:\users\administrator\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- %LOCALAPPDATA%\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %ALLUSERSPROFILE%\saveclicker\vqewa4hc.dat
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- %ALLUSERSPROFILE%\saveclicker\vqewa4hc.exe
- %LOCALAPPDATA%\packages\windows_ie_ac_001\ac\{fc695699-4b86-6a64-2e83-2a518caa6f77}\saveclicker.2.9.dat
- %ProgramFiles(x86)%\saveclicker\ytw_r5h.x64.dll
- %LOCALAPPDATA%low\{fc695699-4b86-6a64-2e83-2a518caa6f77}\saveclicker.2.9.dat
- %ProgramFiles(x86)%\saveclicker\ytw_r5h.dat
- %ProgramFiles(x86)%\saveclicker\ytw_r5h.tlb
- %ProgramFiles(x86)%\saveclicker\ytw_r5h.dll
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\dqpiheeey@wbeoar-.edu\install.rdf
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\dqpiheeey@wbeoar-.edu\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\dqpiheeey@wbeoar-.edu\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\dqpiheeey@wbeoar-.edu\bootstrap.js
- %LOCALAPPDATA%\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- %LOCALAPPDATA%\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- %LOCALAPPDATA%\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\fcpgnj0zj.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\background.html
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\manifest.json
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\content.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\lsdb.js
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\bootstrap.js
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\chrome.manifest
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\install.rdf
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\content\bg.js
- %TEMP%\507f7b5e\ytw_r5h.dll
- %TEMP%\507f7b5e\ytw_r5h.tlb
- %TEMP%\507f7b5e\ytw_r5h.x64.dll
- %TEMP%\507f7b5e\vqewa4hc.exe
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\fcpgnj0zj.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\nfaikhdcbalnmfgbcghkmocldfcnlnkb\2.1\content.js
- %ALLUSERSPROFILE%\9d57dfdabf8d3ffc\{e96338dc-1468-4918-8ec2-8454bffc5025}
- %TEMP%\507f7b5e\vqewa4hc.dat
- %TEMP%\507f7b5e\vqewa4hc.exe
- %TEMP%\507f7b5e\ytw_r5h.x64.dll
- %TEMP%\507f7b5e\ytw_r5h.tlb
- %TEMP%\507f7b5e\ytw_r5h.dll
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\content\bg.js
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\install.rdf
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\chrome.manifest
- %TEMP%\507f7b5e\dqpiheeey@wbeoar-.edu\bootstrap.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\lsdb.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\content.js
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\manifest.json
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\background.html
- %TEMP%\507f7b5e\nfaikhdcbalnmfgbcghkmocldfcnlnkb\fcpgnj0zj.js
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\507f7b5e\vqewa4hc.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveClicker\Ytw_r5h.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveClicker\Ytw_r5h.x64.dll"