Application.Bundler.Somoto.A_52900543c1

by malwarelabrobot on April 22nd, 2015 in Malware Descriptions.

Application.Bundler.Somoto.A (AdAware), SearchProtectToolbar.YR (Lavasoft MAS)
Behaviour: Malware


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 52900543c17a5e7bf2dfca79aff4ed8e
SHA1: bde54935f39a7b826cbd04c655aa542a79100556
SHA256: 1967d352bba17da8da44a54fc2b72e380c0a8b66d565d5fcdbd9ed10d7921c17
SSDeep: 3072:b22ihA0m3BJP0vaUZf3dp5pJL7oCXEIolLb2wbdsIxa4s:0A0m3D0v3ZfN7HQEXolLxpsIa4s
Size: 162096 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-12-17 11:14:12
Analyzed on: Windows7Ada SP1 64-bit


Summary:

Malware. Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

Payload

No specific payload has been found.

Process activity

The Application creates the following process(es):

WerFault.exe:3548
WerFault.exe:2924
WerFault.exe:2488
Npjwb.exe:4764
YTAHelper.exe:2072
GLB4191.tmp:2908
ProtectWindowsManager.exe:3696
ProtectWindowsManager.exe:3648
GLJ41D1.tmp:3252
YouTubeAcceleratorService.exe:1348
YouTubeAcceleratorService.exe:1664
YouTubeAcceleratorService.exe:3648
ctmpua.exe:2288
ctmpua.exe:3432
ctmpua.exe:4816
ProtectService.exe:3944
ProtectService.exe:3960
XTab_Setup2121.exe:3784
jsdrv.exe:200
1F52.tmp:3644
wpm_v20.0.0.1953_0302.exe:3616
biclient.exe:2936
biclient.exe:1760
biclient.exe:3896
b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108
ins_yta.exe:1244
QQBrowser.exe:604
QQBrowser.exe:3556
DesktopMessenger.exe:3944
testlsp.exe:4468
powershell.exe:2340
powershell.exe:3496
powershell.exe:4512
powershell.exe:1684
powershell.exe:2388
powershell.exe:2708
setup.exe:3664
setup.exe:1756
HPNotify.exe:2060
cmdshell.exe:4028
ShopperPro.exe:4088
Ussgbdqdxxc.exe:4744
125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092
smt_istartsurf.exe:1836
ins_shopperpro.exe:3416
%original file name%.exe:2636
regsvr32.exe:2428
regsvr32.exe:3248
regsvr32.exe:3604
regsvr32.exe:3144
regsvr32.exe:1116
regsvr32.exe:1868
lspinst.exe:4328
lspinst.exe:3788
YTAHEL~1.EXE:796
DCytaiesmt_smtyc_setup.exe:3580
DCytaiesmt_smtyc_setup.exe:4188
DCytaiesmt_smtyc_setup.exe:3856
DCytaiesmt_smtyc_setup.exe:3976
DCytaiesmt_smtyc_setup.exe:3084
DCytaiesmt_smtyc_setup.exe:4260
spbiu.exe:3144
spbiu.exe:2612
wscript.exe:2072
6650.tmp:3864
INS_SENSE.EXE:4724
taskeng.exe:1420
ytaiesmt_smtyc_setup.exe:3588
INS_IWEBAR.EXE:4644

The Application injects its code into the following process(es):

YouTubeAcceleratorService.exe:2932
YouTubeAccelerator.exe:684
biclient.exe:4192

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process WerFault.exe:3548 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0dd4f150\Report.wer (239494 bytes)

The process WerFault.exe:2924 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0b6b27ab\Report.wer (239478 bytes)

The process WerFault.exe:2488 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_09b1efab\Report.wer (241156 bytes)

The process Npjwb.exe:4764 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\5774 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\hmwmphigb.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA795.tmp (595233 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\b31cdfed-0f00-400c-94a9-14f605306e7a-4.dll (38103 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe (9147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (5 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\365718 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\emfom.dll (23 bytes)
%Program Files% (x86)\SensePlus\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\wuogor.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\lutouoko.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\System.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\SensePlus\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\bakxdyd.dll (31241 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5_user.job (74 bytes)
%Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\ipgeoapi_com[1].json (40 bytes)
C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5.job (74 bytes)

The process YTAHelper.exe:2072 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.xul (203 bytes)
C:\ProgramData\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
%Program Files% (x86)\YTAHelper\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\install.rdf (884 bytes)
C:\ProgramData\YTAHelper\YTAHelper.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\config.json (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\chrome.manifest (111 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\yta_database1_0_0.json (2 bytes)
C:\ProgramData\YTAHelper\YTAHelper64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\YTAHelper_64.png (4 bytes)

The process GLB4191.tmp:2908 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\YouTube Accelerator\~GLH000e.TMP (11493 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001a.TMP (13284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\blank.html (75 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000d.TMP (7861 bytes)
C:\Users\"%CurrentUserName%"\Desktop\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0006.TMP (115350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe (14357 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAuninstall.mht (9 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0011.TMP (34 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH001f.TMP (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAIDN.LNG (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0001.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe (19739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe (27818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0004.TMP (16 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0009.TMP (2104 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll (3048 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0016.TMP (6341 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0003.TMP (119 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0010.TMP (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\OK.gif (329 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
%Program Files% (x86)\YouTube Accelerator\cabex.dll (98 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000c.TMP (941 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLG49E0.tmp (93076 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0002.TMP (2104 bytes)
%Program Files% (x86)\YouTube Accelerator\temp.000 (51331 bytes)
%Program Files% (x86)\YouTube Accelerator\res\~GLH0014.TMP (75 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe (30222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll (3271 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000a.TMP (18940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll (6691 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000f.TMP (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0007.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe (20746 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll (34861 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll (7687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLC41C0.tmp (3791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLK43D5.tmp (1604 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe (3528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe (20848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLF49E1.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0005.TMP (65 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VADEU.LNG (18 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0012.TMP (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll (4155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page2.mht (1961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH0015.TMP (4061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0000.TMP (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx (3175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page1.mht (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Cancel.gif (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe (2082 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAITA.LNG (1660 bytes)
%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe (146 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLJ41D1.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VATRK.LNG (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLM45D8.tmp (12 bytes)
C:\Windows\SysWOW64\temp.000 (3624 bytes)
%Program Files% (x86)\YouTube Accelerator\~GLH000b.TMP (11493 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\~GLH0021.TMP (65 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\comtest.gif (1817 bytes)
%Program Files% (x86)\YouTube Accelerator\INSTALL.LOG (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFAR.LNG (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\progbar.gif (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0020.TMP (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe (10592 bytes)

The process ProtectWindowsManager.exe:3696 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\WindowsMangerProtect\update\conf (5 bytes)

The process GLJ41D1.tmp:3252 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Windows\SysWOW64\AniGIF.ocx (172 bytes)

The process YouTubeAcceleratorService.exe:1664 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\YouTube Accelerator\engine.dll (146 bytes)
%Program Files% (x86)\YouTube Accelerator\ipc.dll (286 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (60 bytes)
%Program Files% (x86)\YouTube Accelerator\xmldb.dll (192 bytes)

The process YouTubeAcceleratorService.exe:2932 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Windows\Temp\SBCC0F0.tmp (98 bytes)
C:\Windows\Temp\SBCE919.tmp (44 bytes)
C:\Windows\Temp\SBCFD94.tmp (51193 bytes)
C:\Windows\Temp\SBC72CE.tmp (98 bytes)
%Program Files% (x86)\YouTube Accelerator\helper.dll (200 bytes)
C:\Windows\Temp\SBC14AD.tmp (547 bytes)
C:\Windows\Temp\SBCBBC1.tmp (44 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log (591 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (3076 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log (261752 bytes)
C:\ProgramData\TEMP:56E2E879 (240 bytes)

The process ctmpua.exe:2288 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[4].gif (35 bytes)

The process ctmpua.exe:3432 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[3].gif (35 bytes)

The process ctmpua.exe:4816 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[3].gif (35 bytes)

The process ProtectService.exe:3944 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\msvcp110.dll (536 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (876 bytes)

The process ProtectService.exe:3960 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (49 bytes)

The process XTab_Setup2121.exe:3784 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (17941 bytes)
%Program Files% (x86)\XTab\conf (1594 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1794 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\ver.txt (47 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (1685 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (4 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (21280 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5468 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1028.xpi (15 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn143C.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (15946 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (16990 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)

The process YouTubeAccelerator.exe:684 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.bak_tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\SMALLTEST[1].htm (70 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9171.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log_tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9148.tmp (682 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log_tmp (601 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (3671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90D6.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk901F.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log_tmp (300 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90A0.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916D.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90C5.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log_tmp (3 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (408785 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9136.tmp (242 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B1.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log_tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log (76089 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk907E.tmp (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B3.tmp (1 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log_tmp (758 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log_tmp (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9159.tmp (50 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log_tmp (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk915B.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916F.tmp (1 bytes)

The process jsdrv.exe:200 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (6 bytes)

The process 1F52.tmp:3644 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\inetc.dll (44 bytes)

The process wpm_v20.0.0.1953_0302.exe:3616 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (3568 bytes)

The process biclient.exe:2936 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IZSMH2G7.txt (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\vlc_48[1].png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A0GU0ZSM.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\C7DICHCP.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0BISIEEE.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ga[1].js (25835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9GM47V2A.txt (116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[1].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[1].htm (4339 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-istartsurf[1].htm (1054 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\247cff67b7ccf545bc359dea5d4fdcca[1].htm (35176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XBFPV72L.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe (43024 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VWCSVYJT.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Z4XAPYNG.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CAECMN2Q.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VSU9UM32.txt (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9WGP90AI.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L7G4BE9A.txt (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[1].htm (1059 bytes)

The process biclient.exe:4192 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Y2YQ0ZN9.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.7 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.4 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.5 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.2 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.3 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.0 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.1 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BFIYZCSM.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyo_sprite_full[1].png (1276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\40da6fd4d86af64fa44c08b317ad86e7[1].htm (36028 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.6 (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe (12251 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8IZK4DIW.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XRSM1SYU.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[5].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyoLightGrayStripesBG[1].jpg (439 bytes)

The process biclient.exe:1760 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0ZXSMBUT.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\G4EMRU6A.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2YAKCMQE.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\11H1CVWK.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F8VDJPMY.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[3].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MCEUOC87.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ARAVBC6Q.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XT3O6SY5.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\5ee27ba0e055bb4684b8648858d31d9a[1].htm (34716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FFA3HBHT.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BDVF95Q7.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3KR1O1W4.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)

The process biclient.exe:3896 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\N3J3D9ZZ.txt (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[2].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IWHOVB19.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.4 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.5 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.6 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.7 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.0 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.1 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.2 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.3 (4152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[2].png (1277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\8b685dcf684f214ea8b00dc2c916e842[1].htm (34823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TE7T15RC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FNHOZK1G.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp (34243 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UEDY9YTQ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\32X7O7GH.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Q8XWSLCR.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\YK3867F1.txt (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\eula[1].htm (1058 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0982L053.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8SWC09PC.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\eula-youtubeaccelerator[1].htm (2713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[2].htm (1061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TZJ60FG3.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[2].htm (4391 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\1K9S4IKF.txt (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2I762JJ4.txt (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LEX2PBNZ.txt (775 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L4B69UQE.txt (129 bytes)

The process b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\334.js (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\dd664ae6f5b9fff9189830efc4277c1f.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e8bf7602a41c0cdd14ad3540f08069cf.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\d0ac5e3ab61d9c9d036ca53d47b29da9.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\cf410972f8f7d9ce4b77ee942f1466ad.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\e0aa67c698a956adcab1a009989465d9.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\a212c1cc5036af14d61114d057025057.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d7a9ef674b92bd799ec4bb2c4ad621ef.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\9c5116558c43d87c3a32571c768872c8.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\be649c4e3a3e93d8a40243a4b8fc8344.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b7b54f267e564c72cde2760d1dbd8ba2.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e5f493e4f10da2ac3e336eaebbe86097.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\b4bb02edd36de53e69ba6b93fbbaf546.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d3f76309e3ba67b37724cd13c2a877ab.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\0177f7adb3a7120281e3dc4ad27672bd.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\192.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\7bded2a2506031aee5561ee8095bfcda.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\cd42e843c315396a255ec90674730514.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\337.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\281.js (461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\f533812f59e22810ff3bc56548ce46a5.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\527d5f3becaec0408e1ef15ac8f13bb8.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\491bb26de8d74c88f4ef82985489e2a7.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\f15d508ac04f84271fdf78b6cd665aeb.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\390.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\162678864fe0dce10da8913dbd7ae511.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ef5f49cce70bb46b02b28579a3bd464b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\3d33016b291b0f7bcfe763a02760e8c7.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a4216ae64b11870b51e4b6ddf906205d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\fc95591e3359f30c3025d78dffef3f08.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\23ee7c2ff74dde91e4fef185b27fc94c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\1d8df16ea3f4be636f5817d37d006df5.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\193.js (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\57897893dc3d4deec228a28f1d8f10b2.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e38361e1c88892cbd641c1625e826699.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0d3c7da494fcbab7f37c0e38eed8654c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d599fcb25ec9c785d2c1d66a72962be4.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\83bbdd4a0fff63d909d0a0d0e0e6bd38.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\0f728b47f95c6ce7ef2de6868fd3ac67.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\3c15b1a00edb4ad7a7b6ea0c2f029e60.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\356.js (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b23a8e0fe71c1dea24c69cf3bfa392b4.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\c0f52d7d6baeb5125934e7f4ae3aaaff.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\7fb62ef1207bd6500db94456a32fafff.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\34b8f82350c85955993d9f02d0941792.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b33ac672edd3e152a7f18f3bbccca9ef.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\a6bfe546fc476bf6efa27bce866a3a5f.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a3dd82821479da5accbcad4543805ae5.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\447b6d228c0833ca1c3560e0acb7ff93.js (659 bytes)

The process ins_yta.exe:1244 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLB4191.tmp (144 bytes)

The process QQBrowser.exe:604 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\scrollbar.bmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code6.jpg (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5D5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\remoterequest.js (2 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe (14022 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml (553 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5C5.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\vi\locale.properties (2 bytes)

The process QQBrowser.exe:3556 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (148 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (40 bytes)

The process DesktopMessenger.exe:3944 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[2].gif (35 bytes)

The process testlsp.exe:4468 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log (372618 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log (2150 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log (1295 bytes)
C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log (449 bytes)

The process powershell.exe:2340 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1GTL8DZTBO258N0GHLR0.temp (196 bytes)

The process powershell.exe:3496 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7O3W63F2E3I22BLN6TOW.temp (196 bytes)

The process powershell.exe:4512 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D34R02L3N7OKWC8P2R3J.temp (196 bytes)

The process powershell.exe:1684 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XZNWAHWP4KMSA08GUC3P.temp (196 bytes)

The process powershell.exe:2388 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZG7QQZ7AW1JD8CDIB6CZ.temp (196 bytes)

The process powershell.exe:2708 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L0DHHN7AY5J5O0FAV13K.temp (196 bytes)

The process setup.exe:3664 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files%\Common Files\ShopperPro\spbii64.exe (17848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\MoreInfo.dll (15 bytes)
%Program Files%\Common Files\ShopperPro\spbia.exe (11344 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.exe (33633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll (11659 bytes)
%Program Files%\Common Files\ShopperPro\spbiw.sys (1552 bytes)
%Program Files%\Common Files\ShopperPro\spbii32.exe (13368 bytes)
%Program Files% (x86)\ShopperPro\Updater.exe (25112 bytes)
%Program Files%\Common Files\ShopperPro\spbiu.exe (69777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\jsdrv.exe (100669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn697C.tmp (360871 bytes)
%Program Files% (x86)\ShopperPro\FireFox\chrome.manifest (113 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\System.dll (23 bytes)
%Program Files%\Common Files\ShopperPro\spbici32.dll (37025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (100378 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro.dll (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsExec.dll (14 bytes)
C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (1 bytes)
%Program Files% (x86)\ShopperPro\FireFox\install.rdf (828 bytes)
%Program Files%\Common Files\ShopperPro\spbici64.dll (48241 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.json (11 bytes)
%Program Files% (x86)\ShopperPro\SPRemove.exe (20416 bytes)
%Program Files% (x86)\ShopperPro\ShopperPro64.dll (18424 bytes)
%Program Files% (x86)\ShopperPro\database1_0_0.ej (14 bytes)
%Program Files% (x86)\ShopperPro\manifest.json (595 bytes)
%Program Files% (x86)\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)

The process setup.exe:1756 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_60.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_65.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c5.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a5.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f349.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2935.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f648.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f429.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f637.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-active.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f682.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a3.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_72.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_62.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23eb.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f699.png (691 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute.png (445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f453.png (867 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68e.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f1.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f472.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f645.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2601.png (626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23e9.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44c.png (812 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f518.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f237.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40d.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23-20e3.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b9.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f476.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f501.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f608.png (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f511.png (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a3.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2139.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f301.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe (21399 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40b.png (910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f521.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus-active.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68b.png (681 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a7.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f308.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f406.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ac.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ec.png (773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cb.png (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50a.png (708 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264d.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\30-20e3.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25c0.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE-GRAPHICS (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_02.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a0.png (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a9.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_20.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f506.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_49.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7.png (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4af.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f196.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f564.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f631.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_78.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f485.png (602 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fc.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53b.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ba.png (517 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none-blue.png (755 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f602.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f539.png (308 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f380.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f558.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31b.png (826 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (22093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55b.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f416.png (569 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21a9.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2734.png (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\send_message.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_44.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264b.png (701 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_56.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fe.png (472 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f6.png (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f335.png (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274e.png (442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2665.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21aa.png (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f364.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_55.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fb.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2648.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f400.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message_test.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f561.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f303.png (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f425.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f694.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d3.png (590 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2716.png (443 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f459.png (978 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f508.png (293 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2615.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60f.png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fb.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f467.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f427.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f487.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52e.png (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44e.png (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f305.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40a.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f341.png (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f615.png (623 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2194.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f373.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31d.png (878 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f5.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f194.png (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f629.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a8.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f497.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f310.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f626.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2049.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f408.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f343.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\260e.png (963 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b4.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c1.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f451.png (740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b50.png (552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61b.png (848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f523.png (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f647.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f517.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_57.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3f0.png (511 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4be.png (359 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb-1f1f7.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f236.png (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_11.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f316.png (981 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_73.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a9.png (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\35-20e3.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f352.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\libs.js (4316 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c5.png (476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49c.png (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69f.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f525.png (991 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f414.png (935 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f613.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f515.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c9.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64d.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-active.png (410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c9.png (699 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_71.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f693.png (743 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2796.png (184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2753.png (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63c.png (973 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f442.png (928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69d.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f371.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f620.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e4.png (495 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f004.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f498.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f376.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62f.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f684.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f493.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_38.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2693.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\default_photo.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a4.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a2.png (767 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68f.png (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49d.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit-active.png (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f457.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31f.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_59.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f407.png (908 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ab.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f624.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45c.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f423.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f509.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a6.png (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f354.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f384.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f567.png (629 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7-1f1fa.png (238 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b1.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f649.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fc.png (659 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ac.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45e.png (639 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ed.png (420 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60a.png (839 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f379.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f606.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4de.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b6.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f535.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25aa.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5ff.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\24c2.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f402.png (617 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52b.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a2.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f553.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f234.png (526 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_25.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2795.png (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3eb.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f504.png (643 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_37.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e6.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48d.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f5.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_47.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36b.png (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a9.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c4.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f696.png (986 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50c.png (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f2.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f340.png (739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_26.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f500.png (542 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f21a.png (596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fd.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f455.png (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34f.png (802 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f348.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2195.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f519.png (730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f304.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25b6.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f356.png (916 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_28.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f2.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c3.png (449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27bf.png (725 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\263a.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\36-20e3.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f412.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61f.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f639.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f690.png (774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ba.png (789 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f681.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f198.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f382.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_14.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2708.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ea.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62a.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52f.png (820 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55a.png (889 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f446.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33b.png (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e9.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll (8406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e0.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f410.png (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_77.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f495.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f435.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47b.png (877 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b8.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\261d.png (585 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\settings.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_69.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b4.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55c.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2714.png (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f502.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c7.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61d.png (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f622.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ae.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51b.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2649.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ea.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a1.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f390.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c5.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42a.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f625.png (957 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\main.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_30.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f560.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53a.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ca.png (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e8.png (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_41.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6aa.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\203c.png (210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_13.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51d.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31a.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-out.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea-1f1f8.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42c.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f4.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec-1f1e7.png (747 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f195.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60b.png (931 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f300.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2705.png (390 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb.png (362 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f470.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f358.png (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\33-20e3.png (554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35e.png (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-close.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ac.png (556 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f342.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_53.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f503.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f437.png (958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f202.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b05.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ed.png (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49f.png (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f338.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\index.html (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f566.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2733.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53c.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2728.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f418.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f491.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f344.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4db.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_16.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fd.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2652.png (430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49b.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_32.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_22.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c7.png (422 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f636.png (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e7.png (662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34b.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2663.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50e.png (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f232.png (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f484.png (574 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f555.png (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d2.png (901 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_43.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50b.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f346.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f551.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f529.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ab.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51f.png (619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231b.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f452.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fc.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_67.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_35.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64e.png (772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\ae.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2755.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f623.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_19.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f557.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f431.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d5.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_76.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f482.png (782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f357.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f4.png (603 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31c.png (845 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17e.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f632.png (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b0.png (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f0cf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e6.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ab.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e2.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f685.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_54.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f355.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_34.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_63.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f351.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus.png (149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f251.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c4.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f462.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_03.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f687.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f426.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f627.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37c.png (621 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f413.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ee.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2712.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\34-20e3.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b06.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f605.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48b.png (631 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f319.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ef.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f403.png (756 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47d.png (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\32-20e3.png (518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f448.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_08.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f640.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f530.png (382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f363.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f454.png (992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fe.png (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ba.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50f.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f680.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f314.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61e.png (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\37-20e3.png (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270b.png (496 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f450.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f527.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3299.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a6.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a0.png (833 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f309.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e2.png (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27b0.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ee.png (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bb.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f538.png (307 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f393.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bf.png (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bc.png (435 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f374.png (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e7.png (656 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f405.png (926 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60e.png (924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f460.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f638.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4aa.png (742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47f.png (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_80.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f633.png (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2744.png (698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f8.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit.png (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f479.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_66.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f520.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2122.png (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f365.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2934.png (453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e3.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f171.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36a.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa.png (451 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f683.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f490.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f522.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f0.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41c.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c0.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1b.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264f.png (462 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f439.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f510.png (709 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38f.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2754.png (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264c.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ff.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f607.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f528.png (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f18e.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b8.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_79.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b0.png (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25ab.png (138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f466.png (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38d.png (865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3aa.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f603.png (850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26be.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d9.png (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61a.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f440.png (446 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69b.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fa.png (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2660.png (500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4eb.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f562.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f192.png (614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main_test.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\hatter.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f19a.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2600.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4df.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a7.png (337 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f616.png (885 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f359.png (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f367.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f197.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f239.png (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f514.png (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f312.png (956 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_64.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f692.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f3.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48e.png (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f475.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b7.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f532.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_33.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c3.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c6.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-none.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37a.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f191.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f494.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f315.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f618.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_15.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f334.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c2.png (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f444.png (766 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30e.png (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fc.png (539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270c.png (685 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f604.png (836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63d.png (968 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f370.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f695.png (718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fd.png (613 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a7.png (522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea.png (378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26d4.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\message.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f306.png (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f507.png (882 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b0.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f609.png (788 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f307.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a2.png (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1c.png (201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f619.png (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8.png (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44d.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef-1f1f5.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ea.png (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f391.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f458.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267f.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bd.png (616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2651.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f443.png (857 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f688.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f534.png (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f461.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ae.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2197.png (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e3.png (389 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45a.png (920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f409.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bb.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3297.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f332.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52a.png (530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264e.png (561 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f23a.png (549 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68c.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43e.png (573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48c.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c1.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f438.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f3.png (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f415.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_50.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_45.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45f.png (532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ce.png (624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f1.png (251 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\303d.png (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f353.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ef.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus-active.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f6.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_17.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dd.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0-1f1f7.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_04.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f464.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f302.png (918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52c.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f317.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f697.png (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f449.png (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a5.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f7.png (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2797.png (284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f250.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b6.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55e.png (831 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2198.png (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d4.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e5.png (315 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f377.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c0.png (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f401.png (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f488.png (492 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34a.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68d.png (514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bf.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f492.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f516.png (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f383.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b9.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f526.png (589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f536.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f193.png (528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f411.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f233.png (533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f3.png (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f422.png (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51a.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f330.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f478.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_75.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f385.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f360.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f477.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_31.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2614.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f691.png (791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2199.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f433.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f480.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f235.png (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_12.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_24.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f378.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69a.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e6.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3030.png (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31e.png (902 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b2.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f22f.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9-1f1ea.png (267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fb.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c6.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f552.png (702 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45d.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267b.png (951 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ec.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a0.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49e.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42b.png (792 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f524.png (608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fa.png (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f686.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f468.png (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bb.png (320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2747.png (473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f612.png (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f559.png (809 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_58.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_18.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b5.png (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f471.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e4.png (494 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62b.png (974 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d8.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\jquery.min.js (4267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fb.png (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47e.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cc.png (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f420.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c8.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f698.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ce.png (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f387.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b5.png (437 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f617.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f366.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f238.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f614.png (688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f550.png (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cd.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f9.png (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa-1f1f8.png (310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6af.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f611.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f362.png (780 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f456.png (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a4.png (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c0.png (781 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fe.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f428.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50d.png (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\Data\Config.xml (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f434.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f199.png (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f419.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f347.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a0.png (655 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoDB13.tmp\nsisFirewall.dll (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_68.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c2.png (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f646.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\a9.png (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\e50a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d6.png (694 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ad.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2653.png (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ec.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ea.png (551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27a1.png (372 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f339.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f445.png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f473.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d1.png (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c1.png (223 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34e.png (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f489.png (779 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f311.png (712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f170.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f486.png (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e9.png (524 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ae.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f531.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2650.png (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f512.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ad.png (519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_42.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-icon.png (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2196.png (356 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_46.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f556.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264a.png (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_52.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f481.png (972 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bc.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f331.png (504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f350.png (595 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a8.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55f.png (905 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_21.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49a.png (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35d.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f635.png (770 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bd.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_10.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cf.png (572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f333.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274c.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f345.png (881 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f337.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee.png (302 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270f.png (648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8-1f1f3.png (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43d.png (466 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f447.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4da.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e8.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e1.png (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26aa.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_05.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_51.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f313.png (887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f424.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_40.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_27.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f381.png (477 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_29.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17f.png (413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2757.png (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270a.png (665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2611.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f465.png (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_09.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45b.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a5.png (393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b8.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62e.png (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f3.png (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b7.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2764.png (513 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f537.png (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d0.png (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d7.png (570 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f634.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51c.png (733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f392.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f386.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2668.png (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f5.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_61.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f533.png (247 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f389.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c4.png (425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f372.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log.png (670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_23.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35f.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f496.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bf.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ab.png (735 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e0.png (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f483.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_39.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ca.png (954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f554.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b07.png (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef.png (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b7.png (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f621.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f388.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2666.png (407 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f369.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f463.png (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33a.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f565.png (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2709.png (599 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c8.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2702.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37b.png (875 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f436.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e5.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f201.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30a.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f689.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a1.png (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b3.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f375.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_74.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b3.png (498 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b1.png (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\31-20e3.png (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f318.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ed.png (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3be.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f432.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36c.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f368.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_70.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231a.png (754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f601.png (679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f474.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64b.png (945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f600.png (815 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69e.png (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62c.png (678 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f513.png (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f417.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f630.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_01.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f499.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f430.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36d.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53d.png (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f421.png (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bc.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\38-20e3.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55d.png (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a6.png (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b55.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48a.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\39-20e3.png (527 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a1.png (738 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a4.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f563.png (787 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f469.png (873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main.html (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f610.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_36.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f9.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a8.png (555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46e.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f505.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_06.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b1.png (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f404.png (927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_07.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e7.png (468 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f628.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f361.png (806 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6be.png (736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee-1f1f9.png (245 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f320.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3af.png (1 bytes)

The process HPNotify.exe:2060 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\conf (1480 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (24 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (24 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (24 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (49 bytes)

The process cmdshell.exe:4028 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\HPNotify.exe (675 bytes)

The process ShopperPro.exe:4088 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\ShopperPro\config.json (487 bytes)
C:\ProgramData\ShopperPro\ShopperPro.dll (2321 bytes)
%Program Files% (x86)\ShopperPro\config.json (1254 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (291 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\database1_0_0.ej (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\config.json (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\database1_0_0.json (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\install.rdf (828 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (22786 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\chrome.manifest (113 bytes)
C:\ProgramData\ShopperPro\database1_0_0.ej (14 bytes)
C:\ProgramData\ShopperPro\ShopperPro64.dll (3361 bytes)
%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\config.json (767 bytes)

The process Ussgbdqdxxc.exe:4744 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\System.dll (808 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\125b6778-a7b3-42de-b39a-7082dbd6c683-4.dll (38103 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe (7433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\lutouoko.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp (4 bytes)
%Program Files% (x86)\iWebar\utils.exe (63821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\wuogor.dll (8 bytes)
C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\133 (3589 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\340584 (92733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\kvwinpd.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA60F.tmp (601872 bytes)
%Program Files% (x86)\iWebar\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\hmwmphigb.dll (14 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\bakxdyd.dll (31241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\eaxnwm.dll (13 bytes)
%Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe (9147 bytes)

The process 125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\08698225a6048f6e460097f16e02e704.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\71d4611ff095ba11d5170e66cbcb1f99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e495468dafb76cfdaf72e5fa8d28a349.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\64e8d4e87627d5c1948a0bcef5d8bddf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\27cf8aa127aac261d305fe9089529830.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\376.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\3d80de7fb266005117ceaafcc80fdce9.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\cd81bdfb69d0d25218ce67718be563af.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\399.js (525 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\385.js (805 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (506 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\1780bb19c407d25583ce46e040481d99.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\85ea74e5af2c1af63fce579c5ab50f9f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (622 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b25ebd4eb2e834fb9cccdc10bb148863.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\fbbdb0f74062a849bda57f6fe11fcf32.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f769131cae2813ce580e9e94c4e96f9c.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e7c458df68b2cf4608fc221688ae08ca.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ebf33cc6f061080861c3e83c583756dc.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\290.js (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\fd27a2fb33b55a5f18ab50f4ba936cd4.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0bec9e6b7afcc4c4516f35378da8e8f9.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\af5a57f759bd1cf2e294bcfccaf931fb.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\686b2fd98f5ea3e56eaaef1af8491492.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\3e381797919b94e2bb615148f7e47028.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\56d8099de7f917a05ebc946e4ff23a90.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffb8884740ec4a25e7613eb834ca1913.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\79f3c8aab387a44396d3dacdadf581ca.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0034b573374c522556781d729432c887.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\525208f03fe2d8bef8b7bb6b8ef4fce1.js (649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\287fabae0a36fcfbc8d77dcdaaaad216.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\8c01eaa93fd0bc0662848c840cae8041.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b790483a12fb1b0b6cd3863184729b25.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\633a77e2ae00bb6d6d2e3abbbbe03912.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\269585125e1cb71c5dfc6f15d18aba48.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\01b19a2e32d1a93bc2187a399e31eb51.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\edc254d662db048aede80d03ff95a848.js (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\5647e30e6af0add68690b1d263429c43.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\eca39140ee956f1f06527fb9ad62e501.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b7c3eebfc78cf0199ff6ad83ec7241bf.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e83df05e1cf9ce178c9205b266814e5e.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\69a7dc8ac94d415bb9c821991dc88c28.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (899 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\29d9a644a93fb36aff415aeea5c35684.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\8c47021875b6fd49edb959b301d1c49a.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\437c9512ae40f6cf2212e22d83fc0762.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\6aacfc15412fb43d4bcd12a55d84a7ac.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\391.js (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\1358a6937d07734cf85a79aaec52d489.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\a48b2e165ded142e4fd41c767365d414.js (26 bytes)

The process smt_istartsurf.exe:1836 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\MessageBox.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (76650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowser.exe (5199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\sweetsearch!1.0.0.1031.xpi (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (16944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg2.zip (259958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\conf (79 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\quick_searchff#5.4.10.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\UninstallManager.exe (60186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg1.zip (172558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox.png (545 bytes)

The process ins_shopperpro.exe:3416 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup1.exe (144456 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61CF.tmp (155198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup.exe (1606835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\D1958.dll (30 bytes)

The process %original file name%.exe:2636 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe (8409 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nshCF02.tmp (7098 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\config.ini (113 bytes)

The process regsvr32.exe:3248 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\YTAHelper\YTAHelper.dll (409 bytes)

The process regsvr32.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\YTAHelper\YTAHelper64.dll (491 bytes)

The process regsvr32.exe:1116 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\ShopperPro\ShopperPro64.dll (528 bytes)

The process regsvr32.exe:1868 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\ShopperPro\ShopperPro.dll (442 bytes)

The process lspinst.exe:4328 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\YouTube Accelerator\instlsp.log (295 bytes)
C:\ProgramData\TEMP:56E2E879 (417 bytes)

The process lspinst.exe:3788 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\YouTube Accelerator\instlsp.log (253 bytes)
C:\ProgramData\TEMP:56E2E879 (417 bytes)

The process YTAHEL~1.EXE:796 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\YTAHelper\FireFox\content\YTAHelper_64.png (4 bytes)
%Program Files% (x86)\YTAHelper\FireFox\chrome.manifest (111 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.exe (32784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\YTAHelper\FireFox\install.rdf (884 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.sys (1856 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.js (13 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\overlay.xul (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\jsdrv.exe (100669 bytes)
%Program Files% (x86)\YTAHelper\JSDriver\jsdrv.exe (100378 bytes)
C:\Users\Public\Documents\YTAHelper\JsDriver\Config.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B02.tmp (118586 bytes)
%Program Files% (x86)\YTAHelper\yta_database1_0_0.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll (12 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper.dll (13584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll (11667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\System.dll (23 bytes)
%Program Files% (x86)\YTAHelper\YTAHelper64.dll (16424 bytes)
%Program Files% (x86)\YTAHelper\FireFox\content\shopperpro_128.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\MoreInfo.dll (15 bytes)

The process DCytaiesmt_smtyc_setup.exe:3580 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe (7726 bytes)

The process DCytaiesmt_smtyc_setup.exe:3856 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe (48375 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe (31105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe (18619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe (7726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe (50552 bytes)

The process DCytaiesmt_smtyc_setup.exe:4260 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log (15488 bytes)

The process spbiu.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\ShopperPro\spbihe.js (435 bytes)

The process spbiu.exe:2612 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\ShopperPro\spbihe.js (435 bytes)
%Program Files%\Common Files\ShopperPro\spbia.exe (327 bytes)

The process 6650.tmp:3864 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\NSISEncrypt.dll (3342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\inetc.dll (44 bytes)

The process INS_SENSE.EXE:4724 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Sgfzhi.tmp (390774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Npjwb.exe (1335155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\gzxaaspvo.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\pvgykk.dll (2121 bytes)

The process taskeng.exe:1420 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (291 bytes)

The process ytaiesmt_smtyc_setup.exe:3588 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\4D90EAE405E9E2FF (34773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\NK.lky (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\D1989.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe (379403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3247.tmp (35697 bytes)

The process INS_IWEBAR.EXE:4644 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\pvgykk.dll (2121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\emfom.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Ussgbdqdxxc.exe (1340508 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Rtmrbzobbxy.tmp (392398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\gzxaaspvo.dll (30 bytes)

Registry activity

The process WerFault.exe:3548 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"

The process WerFault.exe:2924 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"

The process WerFault.exe:2488 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "09 04 00 C0 01 00 00 00 00 00 00 00 F7 F4 D6 00"

The process Npjwb.exe:4764 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"CrPublisherId" = "20891"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "35 11 53 32 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"DisplayVersion" = "1.36.01.22"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"

[HKLM\SOFTWARE\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "69 41 55 2F FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"DisplayIcon" = "%Program Files% (x86)\SensePlus\utils.exe"

[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"

[HKLM\SOFTWARE\Wow6432Node\SensePlus\Installer]
"BundledFirefox" = "1"

[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"Publisher" = "Sense "
"DisplayName" = "SensePlus"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 59 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus]
"CrAppId" = "70299"
"UninstallString" = "%Program Files% (x86)\SensePlus\Uninstall.exe /fcp=1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKCU\Software\InstalledBrowserExtensions\20891]
"70299" = "SensePlus"

[HKCU\Software\InstalledBrowserExtensions\Sense ]
"70299" = "SensePlus"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Tempo]

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process YTAHelper.exe:2072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"UserId" = "%%PIXGUID(aff=smtyc"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
"{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "CF DC F1 27 FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
"{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"
"NoExplore" = "1"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"CONFIGLOCATION" = "C:\ProgramData\YTAHelper"
"Version" = "1.5.4.199"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 50 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Aff" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator\ExtraInfo]
"DBVersion" = "1.0.0.1"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"DBLocation" = "C:\ProgramData\YTAHelper"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following registry key(s):

[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process GLB4191.tmp:2908 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Goobzo\YouTube Accelerator]
"InstallTime" = "1429596744"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage" = "0"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"ShowAds" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator]
"(Default)" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Aff" = "smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowAds" = "1"

[HKCU\Software\Goobzo\Language\YouTubeAccelerator\Settings]
"CurrentLanguage" = "1033"

[HKCU\Software\Goobzo\YouTube Accelerator]
"DontShowAccelerationNotSupported" = "1"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Publisher" = "Goobzo Ltd."

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LspInstall" = "%Program Files% (x86)\YouTube Accelerator\"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\system32]
"AniGIF.ocx" = "1"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"ZippedRules" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"URLInfoAbout" = "http://www.youtubeaccelerator.com/support/"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"InstallTime" = "1429596744"
"DllInstall" = "%Program Files% (x86)\YouTube Accelerator\"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Beta" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayIcon" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe,-0"
"InstallLocation" = "%Program Files% (x86)\YouTube Accelerator"

[HKCU\Software\Goobzo\YouTube Accelerator]
"HideAccList" = "0"
"ShowTrayIcon" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"HelpLink" = "http://www.youtubeaccelerator.com/about/"

[HKCU\Software\Goobzo\YouTube Accelerator]
"BuildNumber" = "102"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"UninstallString" = "%Program Files% (x86)\YouTube Accelerator\YTAUninstall.exe"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Version" = "3.3.9.6"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Contact" = "[email protected]"
"DisplayVersion" = "3396(build_102)"

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayName" = "YouTube Accelerator"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"(Default)" = ""

[HKCU\Software\Goobzo\YouTube Accelerator]
"Aff" = "smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Version" = "3.3.9.6"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\YouTube Accelerator]
"Order" = "E0 80 00 00 00 20 00 00 0D C0 10 00 00 10 00 00"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Beta" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application" = "http://www.fileextensionpro.com/redir.aspx?s=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&LangID=x&Ext=%s"

[HKCU\Software\Goobzo\YouTube Accelerator]
"RunFinishInstall" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Engine]

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"tver"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Br"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"BrName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"HideAccList"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Engine]
"Mode"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Goobzo\YouTube Accelerator]
"BrName"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"Br"
"ShowTrayIcon"

The Application disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"YouTubeAccelerator"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"

[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VARemove"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"

The process ProtectWindowsManager.exe:3696 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"

Proxy settings are disabled:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"

The process ProtectWindowsManager.exe:3648 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\services\eventlog\Application\WindowsMangerProtect]
"EventMessageFile" = "C:\ProgramData\WindowsMangerPro盺}"
"TypesSupported" = "7"

The process GLJ41D1.tmp:3252 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5]
"(Default)" = "Animation GIF Control"

[HKCR\AniGIFPpg2.AniGIFPpg2]
"(Default)" = "AniGIFPpg2 Class"

[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ToolboxBitmap32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx, 1"

[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus]
"(Default)" = "0"

[HKCR\AniGIFCtrl.AniGIF\CLSID]
"(Default)" = "{82351441-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "IAniGIF"

[HKCR\AniGIFPpg.AniGIFPpg]
"(Default)" = "AniGIFPpg Class"

[HKCR\AniGIFPpg2.AniGIFPpg2.1]
"(Default)" = "AniGIFPpg2 Class"

[HKCR\AniGIFPpg.AniGIFPpg\CurVer]
"(Default)" = "AniGIFPpg.AniGIFPpg.1"

[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}]
"(Default)" = "IAniGIFEvents"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "IAniGIF"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}]
"(Default)" = "Animation GIF Control"

[HKCR\AniGIFCtrl.AniGIF\CurVer]
"(Default)" = "AniGIFCtrl.AniGIF"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb\0]
"(Default)" = "&Properties,0,2"

[HKCR\AniGIFPpg2.AniGIFPpg2\CurVer]
"(Default)" = "AniGIFPpg2.AniGIFPpg2.1"

[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"Version" = "1.5"

[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}]
"(Default)" = "AniGIFPpg Class"

[HKCR\AniGIFCtrl.AniGIF]
"(Default)" = "Animation GIF Control"

[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\AniGIFPpg.AniGIFPpg.1]
"(Default)" = "AniGIFPpg Class"

[HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"Version" = "1.5"
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Version]
"(Default)" = "1.5"

[HKCR\AniGIFPpg.AniGIFPpg.1\CLSID]
"(Default)" = "{6DC82D15-92F2-11D1-A255-00A0C932C7DF}"

[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"

[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"

[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\0\win32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"

[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\FLAGS]
"(Default)" = "2"

[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}]
"(Default)" = "IAniGIFEvents"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb]
"(Default)" = ""

[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"Version" = "1.5"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ProgID]
"(Default)" = "AniGIFCtrl.AniGIF"

[HKCR\AniGIFCtrl.AniGIF\Insertable]
"(Default)" = ""

[HKCR\AniGIFPpg2.AniGIFPpg2.1\CLSID]
"(Default)" = "{61AB12E1-A5FF-11D1-B2E9-444553540000}"

[HKCR\Wow6432Node\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}]
"(Default)" = "AniGIFPpg2 Class"

[HKCR\Wow6432Node\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\HELPDIR]
"(Default)" = "C:\Windows\SysWow64\"

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\InprocServer32]
"(Default)" = "C:\Windows\SysWow64\AniGIF.ocx"

[HKCR\Wow6432Node\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"Version" = "1.5"

[HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
"(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

[HKCR\Wow6432Node\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
"ThreadingModel" = "Apartment"

The Application deletes the following registry key(s):

[HKCR\Wow6432Node\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Programmable]

The process YouTubeAcceleratorService.exe:1348 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "04 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

The process YouTubeAcceleratorService.exe:1664 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "01 00 00 00"
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\InProcServer32]
"ThreadingModel" = "Both"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{K7C0DB872A3F777C0}" = "E8 93 CD 16 42 17 1F FF FF FF FF 64 22 18 AF D9"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"(Default)" = "Seeking"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\InProcServer32]
"(Default)" = "C:\Windows\SysWOW64\quartz.dll"

The Application deletes the following value(s) in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"0"

The process YouTubeAcceleratorService.exe:2932 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ}JbXMHpbpODr"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 06 00 00 00 09 00 00 00 00 00 00 00"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKU\.DEFAULT\Software\GOOBZO\YouTube Accelerator]
"LastUpdateTime" = "1429596791"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LSPTestSucceeded" = "1"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "09 00 00 00"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"XMLVersion" = "0"
"XMLUpdateFailed" = "0"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPPW" = "GLA9Y4un"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"VA_Aff" = "NONE"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|ab@_w}Yu`gBISI`@Ndl"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"UpdateReason" = "0"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "7A 33 65 29 FA 7B D0 01"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAPW" = "mm7DBqQs"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAIDV" = "0"
"SBPIDV" = "0"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"resver" = "1.0.0.8"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPID" = "134bc0d4-cd69-4c5d-bd9b-0a36a7095905"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "7A 33 65 29 FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LspVersion" = "1.0.0.1"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "YeDT^L`~p"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAID" = "7f18dd1b-ec41-4752-9468-5f9624612952"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

Proxy settings are disabled:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following registry key(s):

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]

The Application deletes the following value(s) in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"Uojvoqeov"
"qvorsEtjxw"
"qvbbRNdMg"
"cgcdxuSksc"
"LdsE"
"fSXewhkfv"
"yxQHXfdfitoe"
"pxylOXnGwpXkz"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"jugyvwoEcjGw"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"rffapxdttSchh"
"yEsrDTepOCs"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"hFLwn"
"DxOl"
"FdUXjkIpvn"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"qPacydvhduuR"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"MNEMOyZJWG"
"omdjT"

[HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"uqmpybcjdI"
"pseKcc"

The process YouTubeAcceleratorService.exe:3648 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "07 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

The process ctmpua.exe:2288 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\BI]
"w2mi" = "false"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5E 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process ctmpua.exe:3432 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\BI]
"w2mi" = "false"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5F 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process ctmpua.exe:4816 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\BI]
"w2mi" = "false"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5D 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process ProtectService.exe:3944 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 49 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\IHProtect]
"ptid" = "smt"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process ProtectService.exe:3960 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 05 00 00 00 09 00 00 00 00 00 00 00"

Proxy settings are disabled:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"

The process XTab_Setup2121.exe:3784 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\XTab"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
"{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" = "1"

[HKLM\SOFTWARE\Wow6432Node\supTab]
"ptid" = "smt"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"TopResultURL" = "http://www.bing.com/search?q={searchTerms}&src=IE-TopResult&FORM=IETR02"
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 47 00 00 00 09 00 00 00 00 00 00 00"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0]
"(Default)" = "SupTabLib"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURL" = "http://www.bing.com/favicon.ico"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
"(Default)" = "IETabPage Class"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved]
"{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" = ""

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\Version]
"(Default)" = "1.0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico"
"DisplayName" = "Bing"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconURL" = "http://www.google.com/favicon.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}"

[HKLM\SOFTWARE\Wow6432Node\SupDp]
"dir" = "%Program Files% (x86)\XTab"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconURL" = "http://do-search.com//favicon.ico"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"TopResultURL" = "http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"TopResultURL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\PROTECTEDMODESECURITY]
"CheckedValue" = "PMIL"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURLFallback" = "http://www.bing.com/favicon.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"DisplayName" = "Google"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"DisplayName" = "e"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\PROTECTEDMODESECURITY]
"DefaultValue" = "PMIL"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{E733165D-CBCF-4FDA-883E-ADEF965B476C}.ico"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process YouTubeAccelerator.exe:684 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Goobzo\YouTube Accelerator]
"UiResVer" = "1000008"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "3B 5A C5 2D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "0C 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "D6 80 6E 2B FA 7B D0 01"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\"

[HKCU\Software\Goobzo\YouTube Accelerator]
"CommTestBootNeeded" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 54 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TimeLimit" = "1"
"TimeStamp" = "1429596761"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process jsdrv.exe:200 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro\JsDriver\Tracer]
"TraceLevel" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "47 38 DC 29 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "D6 80 6E 2B FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 51 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process 1F52.tmp:3644 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "8C ED 90 F5 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4B 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process wpm_v20.0.0.1953_0302.exe:3616 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

"UNCAsIntranet" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process biclient.exe:2936 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "25 CC 85 1E BF 72 D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "AD D1 5A E2 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process biclient.exe:4192 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "70 71 C8 61 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5C 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process biclient.exe:1760 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "3E 84 1A 21 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "0E 99 D6 26 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4E 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process biclient.exe:3896 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "A8 FB 71 F5 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 48 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKLM\SOFTWARE\Wow6432Node\SensePlus\BdC8v2inq6DW0g 17Itij/Ao6qs7VY2UO/GLLUG vwECX0QzvPokNprJa 54LBUUswWEm5FuqOnu5tFjnTqkaee0MtijumFPn5RIL3h694Qb26mrJ47q4ZppeNcqx5gSlSy5rqRSjxMv SwJaW0v4syWcWjxlduFPAWXIrOGxo8=]
"Ep6RiGazZALFlmrTnWf1Z5S23oPOb5Bdil0Tu6jOzEGh4I/ pY/mBVxLTMDLxoAWZLmghf/uhnKXU2ew/DoyBxlJZSV EJNyM3nX5DIcxGhQnPmv0Vh3JNSqHfUZQcT8ztyH69YC/0L5MiY400AtutKJLFyGrRrRZ1aJs0z5o7M=" = "1"

[HKLM\SOFTWARE\Wow6432Node\SensePlus\kOh3UM0sElMiqev3yfmeSQG kIDfQMrDtUUKdBeZQFYRDn 4vqALxCRhdjVUQuH02yH41TJV1E8pqvbhPOggZ5Ln6qV98SgznqY9yJY5JtWQyQOBj2KP1Oo6KStyL37EiRvGTGPJMEDJGk0 f2wuncrPpvLrepeO3UC8nxb/hJI=]
"EjBZWTgzCSYnv0us2GklJd9kak/HonX7GcA9biIxImj2lk6xB/XpnoQzpEobQ4Di8Cm5mO7lN2MCHfl3qtk13f Lwvu9/2Bbl/41z66wiep4fCgs4UOAaD1Gu1t4uL/m lEmLwy3igXug1J0xltFV0VByOF7d2Q6l5XweQi9vIs=" = "1"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Tempo]

The process QQBrowser.exe:604 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Mozilla\Extends]
"AppID" = "[email protected]"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E\@""%windir%\System32]
"ie4uinit.exe"",-738" = "Start Internet Explorer without ActiveX controls or browser extensions."

[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Search Page" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"Publisher" = "istartsurfᄀ盛t"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Search_URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
"(Default)" = "%Program Files% (x86)\Mozilla Firefox\firefox.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "istartsurf"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\istartsurfSoftware\istartsurfhp]
"oem" = "smt"
"Time" = "Type: REG_QWORD, Length: 8"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E\@""%systemroot%\system32\windowspowershell\v1.0]
"powershell.exe"",-111" = "Performs object-based (command-line) functions"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Clients\StartMenuInternet\VMWAREHOSTOPEN.EXE\shell\open\command]
"(Default)" = "%Program Files%\VMware\VMware Tools\VMwareHostOpen.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
"(Default)" = "%Program Files% (x86)\Google\Chrome\Application\chrome.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
"(Default)" = "%Program Files%\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe"

[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"
"Search Page" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKCU\Software\Mozilla\Extends]
"UID" = "535559167_198339_B48A115F"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.istartsurf.com/web/?type=ds&ts=1429596648&from=smt&uid=535559167_198339_B48A115F&q={searchTerms}"
"DisplayName" = "istartsurf"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKCU\Software\Mozilla\Extends]
"ptid" = "smt"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.istartsurf.com/?type=hp&ts=1429596648&from=smt&uid=535559167_198339_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"DisplayName" = "istartsurf uninstall"

[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe -ptid=smt"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "istartsurf"

The process QQBrowser.exe:3556 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process DesktopMessenger.exe:3944 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "67 4F A4 61 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5B 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process testlsp.exe:4468 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "14 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "3B 5A C5 2D FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"

"TimeLimit" = "1"
"TracerDoBackup" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 57 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TimeStamp" = "1429596761"
"TimeLimit" = "1"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process powershell.exe:2340 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:3496 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:4512 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:1684 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:2388 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:2708 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

The process setup.exe:3664 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll,"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro]
"UninstallString" = "%Program Files% (x86)\ShopperPro\SPremove.exe"
"DisplayName" = "Shopper-Pro"
"DisplayIcon" = "%Program Files% (x86)\ShopperPro\ShopperPro.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro.exe]
"(Default)" = "%Program Files% (x86)\ShopperPro\ShopperPro.exe"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process setup.exe:1756 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DesktopMessenger]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
"DesktopMessenger.exe" = "11000"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DesktopMessenger]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe /S"
"DisplayName" = "DesktopMessenger"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DesktopMessenger" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe"

The process cmdshell.exe:4028 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "8C ED 90 F5 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4A 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process ShopperPro.exe:4088 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"UserId" = "dcdf22cc-90c9-4f0a-9d09-8ebad4636366"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "47 38 DC 29 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"NoExplore" = "1"

[HKLM\SOFTWARE\ShopperPro]
"CONFIGLOCATION" = "C:\ProgramData\ShopperPro"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"Aff" = "smtyc"

[HKLM\SOFTWARE\ShopperPro]
"DBLocation" = "C:\ProgramData\ShopperPro"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "CF DC F1 27 FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ExeLocation" = "%Program Files% (x86)\ShopperPro"
"Version" = "3.1.9318.1773"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"DBLocation" = "C:\ProgramData\ShopperPro"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4F 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"CONFIGLOCATION" = "C:\ProgramData\ShopperPro"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ChromeExtFile" = "ShopperPro.crx"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"ChromeExtID" = "ojhagnahfpegocdhlopgljpaafeogmcc"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro]
"DriverVersion" = "1.42.0.1773"

[HKLM\SOFTWARE\Wow6432Node\ShopperPro\ExtraInfo]
"DBVersion" = "1.0.1.4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process Ussgbdqdxxc.exe:4744 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"DisplayName" = "iWebar"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"CrAppId" = "70121"

[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"Publisher" = "Webby"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"

[HKLM\SOFTWARE\Wow6432Node\iWebar\Installer]
"BundledFirefox" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "69 41 55 2F FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21836]
"70121" = "iWebar"

[HKCU\Software\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "e9d6e2e9e6a34b6d6a4be51af1aeacc2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"UninstallString" = "%Program Files% (x86)\iWebar\Uninstall.exe /fcp=1"

"DisplayIcon" = "%Program Files% (x86)\iWebar\utils.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
"WpadDecisionTime" = "31 FB 2C 32 FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
"Bic" = "d5d8d8a61601751d467a5854a16ce35aIE"

[HKLM\SOFTWARE\InstalledBrowserExtensions\21836\Status]
"Installed" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
"DisplayVersion" = "1.36.01.22"
"CrPublisherId" = "21836"

[HKCU\Software\InstalledBrowserExtensions\21836]
"70121" = "iWebar"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 58 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKLM\SOFTWARE\InstalledBrowserExtensions\21836]
"70121" = "iWebar"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\InstalledBrowserExtensions\Webby]
"70121" = "iWebar"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Tempo]

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process 125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKLM\SOFTWARE\Wow6432Node\iWebar\kOh3UM0sElMiqev3yfmeSQG kIDfQMrDtUUKdBeZQFYRDn 4vqALxCRhdjVUQuH02yH41TJV1E8pqvbhPOggZ5Ln6qV98SgznqY9yJY5JtWQyQOBj2KP1Oo6KStyL37EiRvGTGPJMEDJGk0 f2wuncrPpvLrepeO3UC8nxb/hJI=]
"EjBZWTgzCSYnv0us2GklJd9kak/HonX7GcA9biIxImj2lk6xB/XpnoQzpEobQ4Di8Cm5mO7lN2MCHfl3qtk13f Lwvu9/2Bbl/41z66wiep4fCgs4UOAaD1Gu1t4uL/m lEmLwy3igXug1J0xltFV0VByOF7d2Q6l5XweQi9vIs=" = "1"

[HKLM\SOFTWARE\Wow6432Node\iWebar\BdC8v2inq6DW0g 17Itij/Ao6qs7VY2UO/GLLUG vwECX0QzvPokNprJa 54LBUUswWEm5FuqOnu5tFjnTqkaee0MtijumFPn5RIL3h694Qb26mrJ47q4ZppeNcqx5gSlSy5rqRSjxMv SwJaW0v4syWcWjxlduFPAWXIrOGxo8=]
"Ep6RiGazZALFlmrTnWf1Z5S23oPOb5Bdil0Tu6jOzEGh4I/ pY/mBVxLTMDLxoAWZLmghf/uhnKXU2ew/DoyBxlJZSV EJNyM3nX5DIcxGhQnPmv0Vh3JNSqHfUZQcT8ztyH69YC/0L5MiY400AtutKJLFyGrRrRZ1aJs0z5o7M=" = "1"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Tempo]

The process smt_istartsurf.exe:1836 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "AD D1 5A E2 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "71 A5 B7 E8 F9 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json,"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process %original file name%.exe:2636 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe,"

The process regsvr32.exe:2428 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\ShopperPro.ShopperProBHO]
"(Default)" = "Shopper Pro"

[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\VersionIndependentProgID]
"(Default)" = "ShopperPro.ShopperProBHO"

[HKCR\ShopperPro.ShopperProBHO.1\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "ShopperPro 1.0 Type Library"

[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro64.dll"
"ThreadingModel" = "Apartment"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro64.dll"

[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ProgID]
"(Default)" = "ShopperPro.ShopperProBHO.1"

[HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "Shopper Pro"

[HKCR\ShopperPro.ShopperProBHO\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

[HKCR\ShopperPro.ShopperProBHO\CurVer]
"(Default)" = "ShopperPro.ShopperProBHO.1"

[HKCR\AppID\ShopperPro.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"

[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "ShopperPro"

[HKCR\ShopperPro.ShopperProBHO.1]
"(Default)" = "Shopper Pro"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"

"NoExplorer" = "1"

The process regsvr32.exe:3248 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\YTAHelper.YTAHelperBHO.1]
"(Default)" = "YTAHelper"

[HKCR\YTAHelper.YTAHelperBHO.1\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"

[HKCR\YTAHelper.YTAHelperBHO]
"(Default)" = "YTAHelper"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\ProgID]
"(Default)" = "YTAHelper.YTAHelperBHO.1"

[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "YTAHelper"

[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"

[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "YTAHelper 1.0 Type Library"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper.dll"

[HKCR\AppID\YTAHelper.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"

[HKCR\YTAHelper.YTAHelperBHO\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"

[HKCR\YTAHelper.YTAHelperBHO\CurVer]
"(Default)" = "YTAHelper.YTAHelperBHO.1"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelper"

[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"NoExplorer" = "1"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper.dll"

[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}]
"(Default)" = "IYTAHelperBHO"

[HKCR\Wow6432Node\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\Wow6432Node\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\VersionIndependentProgID]
"(Default)" = "YTAHelper.YTAHelperBHO"

[HKCR\Interface\{5428DAA1-5A6B-4443-9CAD-60D5C2F38F1B}]
"(Default)" = "IYTAHelperBHO"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]

The process regsvr32.exe:3604 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\YTAHelper.YTAHelperBHO.1]
"(Default)" = "YTAHelper"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "YTAHelper 1.0 Type Library"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper64.dll"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"(Default)" = "C:\ProgramData\YTAHelper\YTAHelper64.dll"

[HKCR\YTAHelper.YTAHelperBHO.1\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"

[HKCR\AppID\YTAHelper.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\ProgID]
"(Default)" = "YTAHelper.YTAHelperBHO.1"

[HKCR\YTAHelper.YTAHelperBHO\CLSID]
"(Default)" = "{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}"

[HKCR\YTAHelper.YTAHelperBHO\CurVer]
"(Default)" = "YTAHelper.YTAHelperBHO.1"

[HKCR\YTAHelper.YTAHelperBHO]
"(Default)" = "YTAHelper"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelper"

[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "YTAHelper"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\VersionIndependentProgID]
"(Default)" = "YTAHelper.YTAHelperBHO"

[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
"(Default)" = "YTAHelperBHO"

"NoExplorer" = "1"

The process regsvr32.exe:1868 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "Shopper Pro"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro.dll"

[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\VersionIndependentProgID]
"(Default)" = "ShopperPro.ShopperProBHO"

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"(Default)" = "C:\ProgramData\ShopperPro\ShopperPro.dll"

[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\ShopperPro.ShopperProBHO\CurVer]
"(Default)" = "ShopperPro.ShopperProBHO.1"

[HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
"(Default)" = "ShopperPro"

[HKCR\AppID\ShopperPro.DLL]
"AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"

[HKCR\ShopperPro.ShopperProBHO]
"(Default)" = "Shopper Pro"

[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"Version" = "1.0"

[HKCR\ShopperPro.ShopperProBHO.1\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"Version" = "1.0"

[HKCR\ShopperPro.ShopperProBHO\CLSID]
"(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
"(Default)" = "IShopperProBHO"

[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\ShopperPro.ShopperProBHO.1]
"(Default)" = "Shopper Pro"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\HELPDIR]
"(Default)" = "C:\ProgramData\ShopperPro"

[HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
"(Default)" = "ShopperPro 1.0 Type Library"

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\TypeLib]
"(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

[HKCR\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
"(Default)" = "IShopperProBHO"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"(Default)" = "ShopperProBHO"

[HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ProgID]
"(Default)" = "ShopperPro.ShopperProBHO.1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
"NoExplorer" = "1"

[HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]

The process lspinst.exe:4328 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ`DvisWwj@pPX["

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60101"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-100"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "11 00 00 00"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-101"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Next_Catalog_Entry_ID" = "1022"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-103"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
"ProtocolName" = "YTALSP"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60101"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Num_Catalog_Entries" = "13"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
"PackedCatalogItem" = "25 77 69 6E 64 69 72 25 5C 73 79 73 74 65 6D 33"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60100"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
"ProtocolName" = "@%SystemRoot%\System32\wshqos.dll,-102"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|acP_w}Yu`fRISI`@Ntl"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [TCP/IPv6]]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [UDP/IP]]"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\FdUXjkIpvn]
"(Default)" = "R[vJIqJXaKp}DD^P"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
"PackedCatalogItem" = "25 77 69 6E 64 69 72 25 5C 73 79 73 74 65 6D 33"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
"ProtocolName" = "VMCI sockets STREAM"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [TCP/IP]]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
"ProtocolName" = "YTALSP over [RSVP UDPv6 Service Provider]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
"ProtocolName" = "YTALSP over [RSVP TCP Service Provider]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
"ProtocolName" = "YTALSP over [RSVP TCPv6 Service Provider]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Serial_Access_Num" = "19"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
"PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
"PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"LspCategories" = "1"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60102"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
"ProtocolName" = "YTALSP over [RSVP UDP Service Provider]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
"ProtocolName" = "YTALSP over [MSAFD Tcpip [UDP/IPv6]]"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
"ProtocolName" = "VMCI sockets DGRAM"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"ProtocolName" = "@%SystemRoot%\System32\wshtcpip.dll,-60100"

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
"ProtocolName" = "@%SystemRoot%\System32\wship6.dll,-60102"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "F}FdcTzbnLZBznXQtn["

The Application deletes the following registry key(s):

[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000018]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000019]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000012]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000013]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000016]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000017]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000014]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000015]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001B]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001C]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000001A]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
[HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]

The Application deletes the following value(s) in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"FdUXjkIpvn"
"jugyvwoEcjGw"
"Uojvoqeov"
"rffapxdttSchh"
"yxQHXfdfitoe"
"qPacydvhduuR"
"qvorsEtjxw"
"qvbbRNdMg"
"yEsrDTepOCs"
"cgcdxuSksc"
"MNEMOyZJWG"
"LdsE"
"fSXewhkfv"
"omdjT"
"hFLwn"
"DxOl"
"uqmpybcjdI"
"pseKcc"
"pxylOXnGwpXkz"

The process lspinst.exe:3788 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\fSXewhkfv]
"(Default)" = "_xYZQ`DvisWwj@pPX["

[HKLM\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\pseKcc]
"(Default)" = "LIEk`RXP|SyWrfDL`L{A~sXFDUSkB"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 79 A4 44 A3"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\cgcdxuSksc]
"(Default)" = "mA_vX[@|ipql`LRKtAe^~Eu"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\uqmpybcjdI]
"(Default)" = "KtKyrWmlh|ac`_w}Yu`fbISI`@Ntl"

[HKLM\SOFTWARE\Wow6432Node\Licenses]
"{I3B3ED09D712B0615}" = "0E 00 00 00"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\FdUXjkIpvn]
"(Default)" = "R[vJVqJXaK{RyQ\p"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\sehlsRMuplph]
"(Default)" = "}QJijLDlnGtvlM\Dt`eRLXEYtLli@u"

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\Uojvoqeov]
"(Default)" = "F}FdcTzbnLZBznXQtn["

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}\LdsE]
"(Default)" = "mncEDgoMD^EumhBjdoZbJ"

The Application deletes the following value(s) in system registry:

[HKCR\Wow6432Node\CLSID\{52988E8B-7806-3101-0E6E-1189876F2078}]
"sehlsRMuplph"
"wjxsvv"
"FdUXjkIpvn"
"jugyvwoEcjGw"
"Uojvoqeov"
"rffapxdttSchh"
"yxQHXfdfitoe"
"qPacydvhduuR"
"qvorsEtjxw"
"qvbbRNdMg"
"yEsrDTepOCs"
"cgcdxuSksc"
"MNEMOyZJWG"
"LdsE"
"fSXewhkfv"
"omdjT"
"hFLwn"
"DxOl"
"uqmpybcjdI"
"pseKcc"
"pxylOXnGwpXkz"

The process YTAHEL~1.EXE:796 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll,"

The process DCytaiesmt_smtyc_setup.exe:3580 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "2E 37 95 20 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4C 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process DCytaiesmt_smtyc_setup.exe:4188 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "44 07 28 2F FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 55 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process DCytaiesmt_smtyc_setup.exe:3856 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "BD 7B CD 1D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Success]
"InstallStr" = "ok"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "3E 84 1A 21 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Success]
"Install" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4D 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer" = "2"
"MaxConnectionsPer1_0Server" = "2"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process DCytaiesmt_smtyc_setup.exe:3976 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "2D B6 24 2B FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 53 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process DCytaiesmt_smtyc_setup.exe:3084 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "2D B6 24 2B FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "BC FE B6 2C FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 52 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process DCytaiesmt_smtyc_setup.exe:4260 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "80 D7 E1 2C FA 7B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"
"TraceLevel" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "27 F9 46 2F FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 56 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1429596761"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process spbiu.exe:3144 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Gcf" = "D9 91 CF EC EE 40 F4 7E 74 E4 CF FB 2F 99 75 C3"

[HKLM\SOFTWARE\ShopperPro\SPBIUpd\Users\Default]
"Ucf" = "AF 19 06 18 24 A7 78 A7 83 2B E1 77 84 81 A9 3B"

[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Scf" = "B7 D9 57 AC 22 CD 0F FA 23 62 C0 8C 21 AB 1C 1F"

The process spbiu.exe:2612 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\ShopperPro\SPBIUpd]
"Ult" = "Type: REG_QWORD, Length: 8"

The process wscript.exe:2072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process 6650.tmp:3864 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "99 5B C5 37 FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
"WpadDecisionTime" = "11 21 A7 5D FA 7B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 5A 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process taskeng.exe:1420 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{8B1CB6DE-FFAC-4723-BC59-32D8149549E7}]
"data" = "4D 45 4F 57 01 00 00 00 E4 B7 BD 92 8B F2 A0 46"

The process ytaiesmt_smtyc_setup.exe:3588 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.25.11, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe,"

Dropped PE files

MD5 File path
88856f63e45c974b19a323e07a01b0a7 c:\Program Files (x86)\SensePlus\Uninstall.exe
19c952082b23910ad46f25db7a10b9bc c:\Program Files (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe
ec82f7731f3bc5b84d3faa10569b78c9 c:\Program Files (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe
26ccd2418100ccc2886fdc94d0a8ca2e c:\Program Files (x86)\SensePlus\utils.exe
262285531c6570177301e8e27145470c c:\Program Files (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe
bd7d9c5152704a1e11d32d0a0b729cb3 c:\Program Files (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys
262285531c6570177301e8e27145470c c:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe
bd7d9c5152704a1e11d32d0a0b729cb3 c:\Program Files (x86)\ShopperPro\JSDriver\jsdrv.sys
7d8f239f995a9387dbca08b11c523cab c:\Program Files (x86)\ShopperPro\SPRemove.exe
5471f0ae1b92c014ea32f0ec5c11f923 c:\Program Files (x86)\ShopperPro\ShopperPro.dll
d6d6cc5817bd22d993545804fb250903 c:\Program Files (x86)\ShopperPro\ShopperPro.exe
f6884feeba4191fb3e8fbb09e6d54b74 c:\Program Files (x86)\ShopperPro\ShopperPro64.dll
82cbb6a522abe82d144c6593a026a3a5 c:\Program Files (x86)\ShopperPro\Updater.exe
33a33e52e9c7db9063cbac82fa9e28d4 c:\Program Files (x86)\XTab\BrowerWatchCH.dll
9def3a62487338e892ce4fffa8efa5d2 c:\Program Files (x86)\XTab\BrowerWatchFF.dll
5785680870eff9ba7b4f58c726552013 c:\Program Files (x86)\XTab\BrowserAction.dll
7e4e734d5adbbc4026a5db2e63c29d40 c:\Program Files (x86)\XTab\CmdShell.exe
8c15f35314eadbe08375dd47ad62439a c:\Program Files (x86)\XTab\HPNotify.exe
e6aac50b9fc19546c5e524c47be5d66d c:\Program Files (x86)\XTab\IeWatchDog.dll
e98c5cfa4051bfa3e2cb0afb10ff4cab c:\Program Files (x86)\XTab\ProtectService.exe
fc60e0ceb67207edd48ed4acbea5de98 c:\Program Files (x86)\XTab\SupTab.dll
3e29914113ec4b968ba5eb1f6d194a0a c:\Program Files (x86)\XTab\msvcp110.dll
4ba25d2cbe1587a841dcfb8c8c4a6ea6 c:\Program Files (x86)\XTab\msvcr110.dll
ff73e8efe2b7f0f134dda89694299ff5 c:\Program Files (x86)\XTab\uninstall.exe
99762975ae78b591fa6699cc460bb5f7 c:\Program Files (x86)\YTAHelper\JSDriver\jsdrv.exe
43901c75bcf54be31a8f15bae77a3865 c:\Program Files (x86)\YTAHelper\JSDriver\jsdrv.sys
e0e06dca0f07ebaba0545450d0f69ade c:\Program Files (x86)\YTAHelper\YTAHelper.dll
c254e02e1b6fe3b7f33426bebb9e6af2 c:\Program Files (x86)\YTAHelper\YTAHelper.exe
a3b46b4c5d373c51e6e489bb603dba9f c:\Program Files (x86)\YTAHelper\YTAHelper64.dll
76f41068f2fa82523736c58c6a6a27db c:\Program Files (x86)\YouTube Accelerator\Res.dll
973567b98cdfc147df4e60471d9df072 c:\Program Files (x86)\YouTube Accelerator\UNWISE.EXE
850e72f521667f04a1fa06bc92311b37 c:\Program Files (x86)\YouTube Accelerator\Updater.exe
29605c3fee628f62dea028a354425e3f c:\Program Files (x86)\YouTube Accelerator\YTAHUninstall.exe
4a53830f2e9fa95a7873dcebd0249e80 c:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe
46e2c40e8adae15d5e3a164e7b65fe40 c:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe
a77332904ccef3efc9dbb27bfc8dfd31 c:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe
3f4049d8bf040812a96680c5a6b377fd c:\Program Files (x86)\YouTube Accelerator\cabex.dll
f756379f1f0fbad6bcf53170aa804918 c:\Program Files (x86)\YouTube Accelerator\engine.dll
81baf300ca0dc9a3d557d0e84567b1a2 c:\Program Files (x86)\YouTube Accelerator\helper.dll
c014a1dddb4677f54f88efaaa492ddce c:\Program Files (x86)\YouTube Accelerator\ipc.dll
f6ac21939884df5c0201cdf1ead06b90 c:\Program Files (x86)\YouTube Accelerator\lspinst.exe
2c3a467735e2d937ce44034869b43231 c:\Program Files (x86)\YouTube Accelerator\lspinst2.exe
a082e5473b2a9a4d846ed7ddf637ac76 c:\Program Files (x86)\YouTube Accelerator\sporder.dll
5e2c0de2f0f15923154293dea89d196b c:\Program Files (x86)\YouTube Accelerator\testlsp.exe
39d9593e5c43d81fe9724fb0f7b16cc0 c:\Program Files (x86)\YouTube Accelerator\unelevate.exe
e0024c585767d4851de5e7331ac91ee5 c:\Program Files (x86)\YouTube Accelerator\xmldb.dll
c84cbb44c3aca460522eba9bd033cd62 c:\Program Files (x86)\YouTube Accelerator\ytalsp.dll
b4f8404b51e99487e56d8fa84a1e9470 c:\Program Files (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe
4078d3e9f16bd51b05b5b02c7ca96ad9 c:\Program Files (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe
88856f63e45c974b19a323e07a01b0a7 c:\Program Files (x86)\iWebar\Uninstall.exe
668eebc218927987ba2a477283807c6f c:\Program Files (x86)\iWebar\utils.exe
e3d3a05e0f184054036de52a1a67fd29 c:\Program Files\Common Files\ShopperPro\spbia.exe
cbb3b002a2aee773dd68372eb4608c2a c:\Program Files\Common Files\ShopperPro\spbici32.dll
2cad1194367243b4846957c0284c60e1 c:\Program Files\Common Files\ShopperPro\spbici64.dll
98e5ae670756522d1720d8ce5e9b2ed2 c:\Program Files\Common Files\ShopperPro\spbii32.exe
cb2a46d93fb166d882658145017a73ab c:\Program Files\Common Files\ShopperPro\spbii64.exe
25c8ef9478f078b849b63d0d199291d9 c:\Program Files\Common Files\ShopperPro\spbiu.exe
94cea41b991986be61facf8741db2a0a c:\Program Files\Common Files\ShopperPro\spbiw.sys
5471f0ae1b92c014ea32f0ec5c11f923 c:\ProgramData\ShopperPro\ShopperPro.dll
f6884feeba4191fb3e8fbb09e6d54b74 c:\ProgramData\ShopperPro\ShopperPro64.dll
f94557f8fd41731a3d180383a516fbe3 c:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
e0e06dca0f07ebaba0545450d0f69ade c:\ProgramData\YTAHelper\YTAHelper.dll
a3b46b4c5d373c51e6e489bb603dba9f c:\ProgramData\YTAHelper\YTAHelper64.dll
5471f0ae1b92c014ea32f0ec5c11f923 c:\Users\All Users\ShopperPro\ShopperPro.dll
f6884feeba4191fb3e8fbb09e6d54b74 c:\Users\All Users\ShopperPro\ShopperPro64.dll
f94557f8fd41731a3d180383a516fbe3 c:\Users\All Users\WindowsMangerProtect\ProtectWindowsManager.exe
e0e06dca0f07ebaba0545450d0f69ade c:\Users\All Users\YTAHelper\YTAHelper.dll
a3b46b4c5d373c51e6e489bb603dba9f c:\Users\All Users\YTAHelper\YTAHelper64.dll
0f1a901cfbd8fc3f17ac2cdbd4875ae3 c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe
7fcbd6dc217380f995c83d1a7cc7f4c2 c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe
cb63b3e387caf96c3322aaa51ca36fce c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe
46539173b56ba94ccd9e702d4a2d8e30 c:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll
ea0ca98847dc1a403ffec3be116e8b2f c:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe
ea0ca98847dc1a403ffec3be116e8b2f c:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe
f58984ad99ca43a9506569e447f64737 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp
f58984ad99ca43a9506569e447f64737 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp
f58984ad99ca43a9506569e447f64737 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp
f58984ad99ca43a9506569e447f64737 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp
d65611fbc4da8cea4e886076bec82d1e c:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe
77cb93857d577104595f4671d9ede81d c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe
f6f9963a698423d4e2cd03e118e4a037 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe
f2ee77e64e6d8944c1a440ab24d0dadb c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe
f8076da03b6b36fa1ec0bd5a082d8d95 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe
45960b40c1ecb75ed5549a80049879e1 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx
76f41068f2fa82523736c58c6a6a27db c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll
29605c3fee628f62dea028a354425e3f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe
6f4f8c2cb7e07436aa59a72c89fbaa4a c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe
46e2c40e8adae15d5e3a164e7b65fe40 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe
a77332904ccef3efc9dbb27bfc8dfd31 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe
f756379f1f0fbad6bcf53170aa804918 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll
81baf300ca0dc9a3d557d0e84567b1a2 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll
c014a1dddb4677f54f88efaaa492ddce c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll
f6ac21939884df5c0201cdf1ead06b90 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe
2c3a467735e2d937ce44034869b43231 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe
a082e5473b2a9a4d846ed7ddf637ac76 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll
5e2c0de2f0f15923154293dea89d196b c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe
39d9593e5c43d81fe9724fb0f7b16cc0 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe
850e72f521667f04a1fa06bc92311b37 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe
e0024c585767d4851de5e7331ac91ee5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll
c84cbb44c3aca460522eba9bd033cd62 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll
4a53830f2e9fa95a7873dcebd0249e80 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe
ef7d1863f4980ab0c8bda142fee67f92 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe
518879abe3170dabd172dfffcd165598 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe
1bdf5e5015efcaa68b05cec0a79be484 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe
3f4049d8bf040812a96680c5a6b377fd c:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll
6f7d9e111a17fab195efe0bbd3a0442d c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll
faa7f034b38e729a983965c04cc70fc1 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll
3a9ce8edf728d00a44376a75fe7b2aca c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll
f0438a894f3a7e01a4aae8d1b5dd0289 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll
ea0ca98847dc1a403ffec3be116e8b2f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe
a08f4ec3efa60141725cf723b0b5e773 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe
62d52491695400e8d14b30876f476933 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe
39d9593e5c43d81fe9724fb0f7b16cc0 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\unelevate.exe
69d2894206516657b7a06eeea5b917e5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe
3663b55452d8e814f62d6fae8eb32d65 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe
f94557f8fd41731a3d180383a516fbe3 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe
acf2f3ad315964ec2ed1ec4e61bd1f96 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe
a5bfd6a87161d5dfa81cb5c2c6d29488 c:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe
45960b40c1ecb75ed5549a80049879e1 c:\Windows\SysWOW64\AniGIF.ocx
45960b40c1ecb75ed5549a80049879e1 c:\Windows\System32\AniGIF.ocx

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 2.0.0.0
File Description: Powered by BetterInstaller
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 28860 29184 4.36907 33e8227bf6edbf3997e3d0895494668e
.data 36864 140 512 0.818223 1b0351714f371c0ba066871d4e504b00
.rdata 40960 3196 3584 3.54441 88a268b1fac88e9fad865c68cf3abce2
.bss 45056 110088 0 0 d41d8cd98f00b204e9800998ecf8427e
.idata 155648 4932 5120 3.53424 11c816edc4ef9cc4aa5511f8a707232b
.ndata 163840 32768 1024 0 0f343b0931126a20f133d67c2b018a3b
.rsrc 196608 17800 17920 3.94947 910d365c8572b40bfb8141bb8ae1ba88

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 3664
7f6d030a23f210ff0f767468fe3edd48
9fe8b39c75f8ed0d56094fe69fbf2c3f
0f8cfe6c36d70739199896a29a9ab59e
9c25ad5c86c1bf46d4564075b019e71c
9c129a294d7cc0fe9ed53d890dbde85f
b9569d981dd7f0516c10295bcb118f65
f3a31b785aef97068400d0987e8505fa
bbef8102d6345f6e5aea4567f3493da7
5423049c0be0b64dd47e76f4552912c0
e994aa2020aa429e7ed46bde26100014
90351671e65f1bb12916d1e9ec86ed49
13df569a80b0b685ba250ad7617fe738
a16c30b5aa236dc78beea2d35406b2b7
b3fa5976434ce1e51a1bd370e2aefd3c
7f9d59c48734f851495f71f0c539537b
22754d84b6a8863fdb8bcc5c56c849cb
58fe62f415a645bea095e193a1676101
2a2a5c35d16c851fbe31471dc439b39c
92c551fd1abfe685fd18911e9ab08526
0d213295b19e20e1fecc37345c3e009b
e7b769fcb3292ae349d046038146b08d
a6fc7dda6bdd315dfd5980ac76fb22d0
ba8a944ac777b66e2f8831e41c48a17e
52f55df57abbba5785a9fc223655676d
43e6206ab7ba8f798441f29b86ac7746

URLs

URL IP
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/247cff67b7ccf545bc359dea5d4fdcca?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4
hxxp://d110jf50ovcr9h.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg
hxxp://d1h8rlkib3jo2q.cloudfront.net/images/Tokyo/tokyo_sprite_full.png
hxxp://installer.betterinstaller.com/installer/ajax
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/istartsurf/eula-istartsurf.html
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/speedbit/eula-youtubeaccelerator.html
hxxp://www-google-analytics.l.google.com/ga.js
hxxp://www.girlliuxiaowei.com/home/smt_istartsurf.exe
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=891678463&utmhn=bi.bisrv.com&utmhid=446800634&utmr=-&utmp=Installer_Init&utmht=1429596636339&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1909607576&utmredir=1&utmu=qhCAAAAAAAABAAAAAAAAAAAE~
hxxp://d2z5psu5fxw71b.cloudfront.net/sponsored/swiftrecord/eula-swiftrecord.html
hxxp://d2z5psu5fxw71b.cloudfront.net/affiliates/filesfrog/eula.html
hxxp://mirror.frogdownload.com/software_files/vlc/vlc_48.png
hxxp://a1726.d.akamai.net/sd?is=sm
hxxp://d2otsfra4otprh.cloudfront.net/mag/ytaiesmt_smtyc_setup.exe
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/pc_messenger_for_android/default/setup.exe
hxxp://mirror.frogdownload.com/software_files/vlc/2_0_2/vlc-2.0.2-win32.exe
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&display_height=50&0.9153985493271659
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&0.8522578642015259
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=2&index_in_screen=1&index_in_session=2&display_height=170&0.9592077379969404
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=2&index_in_screen=1&index_in_session=2&0.8782558746692214
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=3&index_in_screen=1&index_in_session=3&display_height=80&0.1334864874963183
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=3&index_in_screen=1&index_in_session=3&0.8799863343719936
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=4&index_in_screen=1&index_in_session=4&display_height=195&0.7944516260210912
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=4&index_in_screen=1&index_in_session=4&0.5368077775084833
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action1=xa.geoip&action2=visit&action3=smt.visit.istartsurf&update1=ref,smt&update2=identifier,installer&update3=version,6.6.86.1606&update4=nation,us&update5=language,en
hxxp://dqoup4b5zs0bi.cloudfront.net/infv5/index/3428/bnd
hxxp://dlrkbt247pbk6.cloudfront.net/3428_3b67a5ef5d450c1556c543c6323981d9/1.pak
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=247cff67b7ccf545bc359dea5d4fdcca&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=istartsurf&tokyo_csrf2_key=6789fbe64a1c0288ff867f772fe2c0ef&tokyo_csrf2_timestamp=1429596583&slot_number=1&index_in_screen=1&index_in_session=1&0.8875708268396014
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=2&utmn=1803266286&utmhn=bi.bisrv.com&utmhid=446800634&utmr=-&utmp=Offer_Accepted&utmht=1429596646250&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.regok
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.ds
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.hp
hxxp://log.very911.com/install.gif?bundle=istartsurf&ptid=smt&uid=535559167_198339_B48A115F
hxxp://download.dynect.mozilla.net/?product=firefox-34.0.5-complete&os=win&lang=en-US
hxxp://a1284.g.akamai.net/pub/firefox/releases/34.0.5/update/win32/en-US/firefox-34.0.5.complete.mar
hxxp://www.google.com/
hxxp://www.google.com.ua/?gfe_rd=cr&ei=6-k1VfOpLYOu8we8uoDwBA
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.nt.ff.tab
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.finish
hxxp://dqoup4b5zs0bi.cloudfront.net/infv5/index/3428/3rd
hxxp://dqoup4b5zs0bi.cloudfront.net/3428_92a5d683c188790231b1aa2af09de41e/2.pak
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.wpm
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action=visit.heartbeat.wpmvt&update3=version,20.0.0.1953
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action=visit.heartbeat.wpmvt
hxxp://xa.xingcloud.com/v4/sof-installer/535559167_198339_B48A115F?action=smt.installer.istartsurf.ient
hxxp://xa.xingcloud.com/v4/sof-ient/535559167_198339_B48A115F?action0=xa.geoip&action2=visit&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,2.8.8.2102&update4=chptid,smt
hxxp://xa.xingcloud.com/v4/sof-ient/535559167_198339_B48A115F?action1=install.smt
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=3&utmn=692550647&utmhn=bi.bisrv.com&utme=8(sp_slug)9(istartsurf)&utmhid=446800634&utmr=-&utmp=Install_Complete&utmht=1429596666051&utmac=UA-31676879-1&utmcc=__utma=1.1401191557.1429596636.1429596636.1429596636.1;+__utmz=1.1429596636.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qxCAAgAAAAABAAAAAAAAAAAE~
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/8b685dcf684f214ea8b00dc2c916e842?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4
hxxp://up.soft365.com/Fan/rebirth?uid=535559167_198339_B48A115F&ptid=smt&ver=4.0.1.1716&dname=istartsurf
hxxp://xa.xingcloud.com/v4/searchprotect/535559167_198339_B48A115F?action=visit.heartbeat.smt&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,4.0.1.2105
hxxp://xa.xingcloud.com/v4/searchprotect/535559167_198339_B48A115F?action0=xa.geoip&action1=visit&action2=install
hxxp://d1h8rlkib3jo2q.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg
hxxp://d110jf50ovcr9h.cloudfront.net/images/Tokyo/tokyo_sprite_full.png
hxxp://d1h8rlkib3jo2q.cloudfront.net/sponsored/swiftrecord/eula-swiftrecord.html
hxxp://d110jf50ovcr9h.cloudfront.net/affiliates/filesfrog/eula.html
hxxp://d1h8rlkib3jo2q.cloudfront.net/affiliates/filesfrog/eula.html
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=1665638849&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Installer_Init&utmht=1429596667810&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1063059989&utmredir=1&utmu=qhCAAAAAAAABAAAAAAAAAAAE~
hxxp://d2z5psu5fxw71b.cloudfront.net/sponsored/speedbit/eula-youtubeaccelerator.html
hxxp://xa.xingcloud.com/v4/sof-windowspm/?action0=xa.geoip&action1=visit&action2=install&update0=ref,wpmvt&update1=nation,us&update2=language,en
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/nerocrossrider/appshat_generic.exe
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&display_height=170&0.43209955227997554
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.8902343800499003
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&display_height=80&0.5999672903135584
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&0.3944050553270405
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=3&index_in_screen=1&index_in_session=3&display_height=195&0.7397356789101737
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=3&index_in_screen=1&index_in_session=3&0.6216911406062087
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=4&index_in_screen=1&index_in_session=4&display_height=90&0.9088924169240506
hxxp://www.theviilage.com/windowspm/up?ptid=wpmvt&sid=WindowsMangerProtect&ln=en_us&ver=20.0.0.1953&uid=&upv=
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=4&index_in_screen=1&index_in_session=4&0.09920990337743929
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.6710044187465542
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=2&utmn=387526838&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Offer_Accepted&utmht=1429596733521&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~
hxxp://theswiftrecord.com/mg?alpha=dEExCndCCQVYMzd5HiB4dQViB3d0BzN7f3EqRzxidWNwFHYjPix4bwMFMH0gXF8pXQ4CQld+RmszYCcXZ0kLBwUMFi1FfCRlQzZrVi9y
hxxp://theswiftrecord.com/fp?alpha=fTYJCFZWOBozTQkRJiJZfHJaBVZ9ah95F1o3SBcKeiIECBB/RwENPQsAHAl0PCgIXylgRBF/EnxBXiBIZWFwflUbQjgXJCwbaRtAWGJyBUk+NwpECGouXnxTA1gJSkN4YkgcUi1MAHc6enEVEwQnJQRcKXxIZw4JYDBYVlYqICsFRm5zGlYFMW8ZHQdVJndmRG4qH15be2JUZFMKSA0fVypuRR1XOEsJbj52ZEcMF3InHA9+bRRlHEY8PTgMHy09LEAwd2EYTA5zNkBaWlR1bxowSzxdG15mMVx1VwteC0hcKiQJEzRxFF0hfzxkYVtRdH5YCGgTDGQDF2U3Wm5WPSYsXC1iNEMUVFhvGRByCTEOe1JKLw5Ee2IwWGlXC14COEgIYCdqJypmBHNqVFpP
hxxp://theswiftrecord.com/ii?alpha=ATNRByFYY01YMmRBfi0uAHcCCiEBb10vLDQARRZkU28bQGQUQjI2FlU1XWMlDnoWBktYA2pHGkk4Als2AXgtA0ltMA0bI1VvRAJiJHAqKHIsbAoWfFJnEjh2elUgQElzawpiOVxLU3JSBwc4B20sIyBaQANASXBra0YDLzd1EDtaEWI1BV0qUm9GB2p9NzlrIl0vU1N9FDYSL3QhLxEaMF43RVF4Cw0EZxtWJz9DLzsoVVJDAVs2B2MdKwFdMgZnO1ACME1MSCo1DFFdNzl6ZzwuJHYJAiJQdRhrJ3NAARx5ET1OV3EWQiwoHEEuDl4mGTUzCwNVGnhGcxolYBloUjNuRA4wb0JHNy5/V0QhP3B+Nn1TJUdQYxYoA30hdk0QEH9BO15ENBQeAipfCWFMH3BLehcODF8SMnA9SmlZGG8UfkhZDitkRwtEFD4DVzdkJXkvLkc5CVQ9Gn8SKmd6VFNZPAdgG0x1WU9Re0oDe0gHel8kXlJcC0I7EyNCYQ0tZlgleBEDMGxNFlMuADlzYilsejouN1w4KAwBYkB2RwoaAgdoG3JrbGMFDQRhKVozCUQhATU3Qj5yJkYVF0R2W0tDUSB0VAJ5cUgWMQUxFA91a3kqaFYhNWoCVyY=
hxxp://theswiftrecord.com/if?alpha=ATNRByERDF14DT1Kfi0uAHcCCiEBb10vLDQARRZkU28bQGQUQjI2FlU1XWMlDnoWBktYA2pHGkk4Als2AXgtA0ltMA0bI1VvRAJiJHAqKHIsbAoWfFJnEjh2elUgQElzawpiOVxLU3JSBwc4B20sIyBaQANASXBra0YDLzd1EDtSBGJSS057DBYZWzAGans1QAR2EwUlAWtCdiVhG15HPQZnExEgSk1Qb08HdE0CcEtxAQQvQxoyXDZVdVwEdVFweVIBHXNMfSpRb1kCanQxJ2k9QilSVHwBYVEkXSgOXiBeET1OVW0UGlwWFl0lEkYzQTVSVkBTHHsTPF5zVRk6eT9+RQgsbkVfNzc2GVYrOnA3bjMjbQgAKFR1XSR/JgFDOy0XJFhTZw0QD2FFE3dTAG5aI1RTTUIQfUM6TmAQG2ZXPT0NR24vEw14EzMWXCNwRnk+fxpsD0ZlcmhdP3QjTTABbEM3TggyCglcdVldcw0MOUt0El9UAVk+BWELaFFWNwRsKAddajcZGSZab0YIc3klZzZ3TlkGCj5CIFAkfClQJztSeRMbRXsJHFwFPGwPPBckGSgyLxpQB2oZc3tIRwp1UXZLXhUrdEJHNzN/JHEXBCNTMGAYPyMDO05lUUNmKg1kGgE=
hxxp://installer.betterinstaller.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=1&index_in_screen=1&index_in_session=1&0.7190371375746383
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/install.ashx?e=HfxXOGS/z9OZB5OpWDIhcI98vG 5fsxoWca3XTKXJfYriJQgYTNdKsv4S/K6mfkWhIAbznvPq9KP4omGccpXw4yox39H7ctICby7qJ3JU/SrJhv0HKSN7fI2lN9tDRbVkdht9YBbn9NoW7mKnZ2EeHpRzM4tyPZ3W7FDeAWA9Q/G654koUNxkMghSR4V61YBKj3opCu/EfMW3Pvdol3JD1RxnOeX4PrAM1cCPzZPV1Ir4SzzVigRZY8bmcjLPajJTihKLG4th75spw/7f00hPFp9lYCrTzudqPNcAS1l461ySja6I2xEDkC5Utp4ACue1aHGmPAFInybwpTFcYOvmsbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXvnPdWmxNjVj021585MfhSlKeRKeVWAD5
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=F94QJJu2atmfZNC1TqAoBPMVqHgy q6Y1VMaOJFqXYpxTYwWxYG9WJlbztiqtoL/oUDW29 K3KYjf9BDcIeJg3f1ws7XaD2yRYhZSGl8ahHJscN vLrCozg0PJKmtjhbnF8rmHTkMqGy2eGRx58JVeIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSa9/CpuCTIAF0=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/t.ashx?e=eFCD8T/coiezrE/yDXLQyaBYTa7YJ/ddFibV1lgn9kL8ln8Iap23//2TEkHeJNDUga zuhV9q9GgigC dQ2qERB/SoLmDeveGxrTqW15vZAdYLC6Fwg82dCUHeR8YCF3BQ8MIYMfS0viLuGcd2F1x25D993ilxFQ7nJDKdFRkjljTyNjjzEEmvfwqbgkyABd
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=F94QJJu2atmfZNC1TqAoBPMVqHgy q6Y1VMaOJFqXYpxTYwWxYG9WJlbztiqtoL/oUDW29 K3KYjf9BDcIeJg3f1ws7XaD2yIg0p1vUMLr4E8SFHLIEPsGJTlYCQaOf7GuVxeoIbRG3Yz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW Q==
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=3&utmn=1730329326&utmhn=installer.filebulldog.com&utmhid=1199314850&utmr=-&utmp=Offer_Accepted&utmht=1429596739155&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=8b685dcf684f214ea8b00dc2c916e842&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=youtubeaccelerator&tokyo_csrf2_key=de5e2fbb94f6883241c0b511847dd6e7&tokyo_csrf2_timestamp=1429596667&slot_number=2&index_in_screen=1&index_in_session=2&0.5906745765326631
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=KC52kqqAunDZ0iLC9WK4WFxXO2/ZuraujA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/iAIKZZuIG7pa1yMTX l/6fI6tVPrdYEHziRovMIdqiLY4G r 3F6T71bPtYaZyj1jXJFnq8uZ2OtcEDHjhn1UqBPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/install.ashx?e=s5Ydxb c7o1WuN7nJmKQv/x82bD1CPIVfvVXty/UsTroUht0DV8eHWD3h9gcT/r2iwEbfeVtNep9AGHLpPN9dvm9MH d93Mvga zuhV9q9Hxu1y 6Ac0RKhN6psLdnSsdosECI4dMRD6OfU8/FMPXH6dYg1rlTgUy/ecrRsbq5tpfYOBgM/eiVGOPVXIjHvBQBWGehDOL40qPeikK78R8xbc 92iXckPWyDeCB2 tfyPfcw3xSS2sC8A9/jgya9LlYcK O052ZC0GDTXqk98YFU/GQ/6lQnvZ9NUWB1HEgAqPeikK78R8xbc 92iXckPVHGc55fg sAzVwI/Nk9XUivhLPNWKBFljxuZyMs9qMlOKEosbi2HvmynD/t/TSE8Wn2VgKtPO52o81wBLWXjrXJKNrojbEQOQLlS2ngAK57VocaY8AUifAZ5Zhb6cYHbZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmBdCfoOhw1AmusrAPq35vVlc7I2zAtpd BrFRBRwOvfmpZiAUeJqQd3w7C/8Waki4UTdhHKpI8R4g==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/t.ashx?e=XJYuqQQo69eJxiP7f9a/G5kHk6lYMiFw8F7JKJBcHiFAXdQqxJ1va3sc7hbJtTJHVR5AawbKoxrmEFSc9UZ7HoLfo4buCUHLYCpHZc9ZUaGLbhvor/ikhRQC drCF7eFysWDrahxHN1nWpr61EGbEgSa6Z efd4uyZD6A1psf2ya3UsgcT0aYMiISMf8I5JK
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=obiBp3WOda80dGo5FFu/Rfx82bD1CPIVMg4/1 uL4Rx4E7mrr1h80riKIFo3W8f23Wq7IsWCDz6QG2IGXsglf9aoPZj94HyT6LOwEGQvh2zV2TxY7/sL 44G r 3F6T7xRE3XrPaz9SlN4/jP vfgHFG19d2lv/HJ3iKHvUBVBgUcVzVK9Vv1mcf8BCmUGG46EQb8iyo3pFzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhcOJRGQPMpOEZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmDIiEjH/COSSg==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=obiBp3WOda80dGo5FFu/Rfx82bD1CPIVMg4/1 uL4Rx4E7mrr1h80riKIFo3W8f23Wq7IsWCDz6QG2IGXsglf9aoPZj94HyTzprDiolRFccz/yeZN BbCCmF904v4t2DaVtcL0PMGkj3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22OWbU/CGmJ5Yn
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtSOm5eZ4cw1FBPrMwLm 2sRKYX3Ti/i3YOiW0 omKwO0XPGGaK58CUdKIVyy9nVE95oyD6CU7dt4Wn8ksZ3j7x1iB5kmKu6piWQOuYQ194zIMgZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/ S e3Qk oWjiLuGcd2F1x25D993ilxFQ7nJDKdFRkjljTyNjjzEEmn/Mv081ozH 6ysA rfm9WVzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhRN2EcqkjxHi
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRAkqBmtM5btymF904v4t2DqIs V7Ds6CRuZZIi5/tojmg8l4itKbh/HiBn688lkcr8toCm18jzwzsvB25MJtnS1urDxSq54gttr9SYvZpGaZcc7RKjUBXhxuC523JvYYdSkkpIJMyTNdApcSbF ajtWckiMiVYfJeK7a1soWlgbXd/rihenux9ySc2qnm2W09Gzz7wQc0vaHURkj7Q ftYGzj3tdSkW4Zmvpo8LqZZFg==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/yta33_full.exe
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=4mC0vXGWFtrPpyTTOfle7KBYTa7YJ/ddzVEHgY7Nvtv8ln8Iap23/wrmOSgIBLqiUA7dl9owwhJzsjbMC2l34GsVEFHA69 almIBR4mpB3fDsL/xZqSLhUUzEuqmKn8FFjCwIjKziMWX1FtTkCv6XNG/q7d0kZqG4nJwzEzT2yGx2KlVs8m8LqSlVGmgAnwDgZiB55ZFi610O2zSRBrcbfeJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5tMM9FOiO9IIcxXLgDRmHLIooHpf zDreu25mDZEkSyn7iqNbFXibXo4EEUq2YBBrBKqBh/IhxWU=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtSSe6wB6uwHTPUd/QfilrMBAltiGSLIu3jTI/BdPpi2K8DfJqMJzaCLHcPH8e2aI0 M8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj247L51k5jm4zsBCEmBDvTUsTZINeK/JOSL 3WfbvnIvNzoFM0vxjvvSqcviFu3/GkUyaD6UnFJmg
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtQ3HFDGhcCtcymF904v4t2DkuWOvdnHdKumYTzO WELM7Ot/W9fkCR9BPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTTuh9zxLe96tCUHeR8YCF3eUieKUOy0CNssIFedkeDcwU A6kiYcjN5jgwqhpV 3QaM eJWkTw6uIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRohYWVSD9bxhD4NsK07Wi5s IILilpWF2KgswbSwpeyhmehRlAIZWixXuPFOdxmQSrMrg41l/Ly7CST5Ycto3cE6nMAQ0x67lxVrNxtz1yEZXZrelYJPLUp3totELV0vAUMpiXMw4KN81q3cIZb5NgZjB6lpXcvb8ETDauskRD13csfOMEkERp
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTF/nvWLek4mQTxIUcsgQ wziIw8Q49/dgttmOVSqw04CNiCF4FJfQXuVsw3gS4GmHhRrrlB59yRveJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5tMM9FOiO9IIcxXLgDRmHLIooHpf zDreu25mDZEkSyn7iqNbFXibXo4EEUq2YBBrBKqBh/IhxWU=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtQQuxFFygAloQTxIUcsgQ wWDLNdKr8lljanAVHlmf vATxchauHrQ9hdXWs9gHCsWrLZx3iqhAOXSh4 HSf3c17G8X1negC9ViA7TIcAcS/PSaXpttQq9u6mIlOXI595 bsMJhchpB dLHn2izZkEYSae6pFGeTxOSDd4/R9r/g==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtRaYa2XOOQuZBQC drCF7eF7LQ fMG3nUOoTeqbC3Z0rIzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=2fVCHF6kf8gIOxOHRe9xgPx82bD1CPIVbDRqKGjbJHd4E7mrr1h80pGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfxoLy7RXgEKjmVvO2Kq2gv SYeASUebplo0f1E0tBirtj0N7bp/0QtTvsEASNc/caY4G r 3F6T7M 2x4nq/V4db8yl/lmEDu8bgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=F94QJJu2atmfZNC1TqAoBBIAXT6v72bD1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglf K9V0GRRES3IlxQB6eB5S9R7UpgWEByNCUHeR8YCF3MktO1JB6jbL3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22ObTDPRTojvSCHMVy4A0ZhyyKKB6X/sw63rtuZg2RJEsp 4qjWxV4m16OBBFKtmAQawSqgYfyIcVl
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=QgW8pN5r26bof2QYjF1uPw 1b2jb81yhAZx7JfD/ZiMQyol6Hp9RdsFeXk7XK CmZc1aUYNgRmYUMpiXMw4KN81q3cIZb5NgZjB6lpXcvb8ETDauskRD18KD4bIu5UqAjKjHf0fty0jJarzC68jV81FHLC9J469/1QHs3X92ilHJn1GegIILyOsrHZsRsIfMRhg0WUsz0Xly/L51iHZ9rxr2JHwunefehyr8tn/scJASvby4dPZrV Iu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=4OQPU60dJ1qZB5OpWDIhcAe6sha6wrcYQF3UKsSdb2sRoGJKEMpEhX5dMiu8MPG0ffYljA3T0gt1hsGb8yo/2TkjhBdHIT10cuvvLWnJm1UnwfzR3S4hQtSSaUQFDqWEnmP3t8anGDckr4PJ1IiKN1 JfVwpv1Wv4yV9gTVq WZsJKoGkBMBgLPiCC4paVhdOS 6WDi3NsuM8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj247L51k5jm4zsBCEmBDvTUsTZINeK/JOSL 3WfbvnIvNzoFM0vxjvvSqcviFu3/GkUyaD6UnFJmg
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=DNkDj dFVmCfZNC1TqAoBLWRhHmxIJa51VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfzMncK1Qz/SNyETj4nts NPl9AOtqZ1I9ymF904v4t2DIdOulZ3X5yT2e6nYO18M sRH TBIllJr94khRQjb0om5r9iFtppC1uEsoMnuAcfjiugW2mv9tjm0wz0U6I70ghzFcuANGYcsiigel/7MOt67bmYNkSRLKfuKo1sVeJtejgQRSrZgEGsEqoGH8iHFZQ==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6sAcx93N9gOwKrHgy/oM8tnisgFVrwdvYUha2hWnuyChQC drCF7eFK1fB54AeplfjV/OYuilSzqVKY5y Qu9A4i7hnHdhdcduQ/fd4pcRUO5yQynRUZI5Y08jY48xBJp/zL9PNaMx/usrAPq35vVlc7I2zAtpd BrFRBRwOvfmpZiAUeJqQd3w7C/8Waki4UTdhHKpI8R4g==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/27001.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6sAcx93N9gOwKrHgy/oM8tnisgFVrwdvYUha2hWnuyChQC drCF7eFhyLMFTfLfGniVx6hrLaV8djP1QedMB/cy/B6ujnJrtI0fJ30mPWB3MJ9BqBjylb5Pk55LBQN29oKKSszP/5sI8gZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/CgTTFbRks1o=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qayD5Sh2iPx4Tl/DvTHZIAKtATxIUcsgQ wusjSmD/os8shJkdH5jOhAHvojBYZTAl2SDGL01oIa7jD3Psqw12eBUNQkrQodbn4W0C6B oLg2/kIgqoM4zGjB6RUS1Mgh81BPFyFq4etD2F1daz2AcKxastnHeKqEA5dKHj74dJ/dzXsbxfWd6AL1WIDtMhwBxL89Jpem21Cr27qYiU5cjn3n5uwwmFyGkH50sefaLNmQRhJp7qkUZ5PE5IN3j9H2v
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qayyETj4nts NO517CUeh0QiwTxIUcsgQ wusjSmD/os8uUYk8/b2 6EUeCMSNo5dvN0DAe2B9i5kJssIFedkeDcwU A6kiYcjN5jgwqhpV 3RVAAKZHGiEvoUuxfjpmZqkclTumrkXWbdv qR/r3k14sbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY=
hxxp://cds.c5z6s5a3.hwcdn.net/spd/shopp/iweb.exe
hxxp://cds.c5z6s5a3.hwcdn.net/spd/shopp/sense9.exe
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/ShopperProJSINJFull.exe
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBPkHsplmp21I1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglfwNM5Vck/qay3IlxQB6eB5S9R7UpgWEByNCUHeR8YCF3TCM72XKEiy8qCttwK9rPhasyuDjWX8vLsJJPlhy2jdwTqcwBDTHruXFWs3G3PXIRldmt6Vgk8tSne2i0QtXS8BQymJczDgo3zWrdwhlvk2BmMHqWldy9vwRMNq6yREPXdyx84wSQRGk=
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=5&utmn=1464879343&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Installer_Init&utmht=1429596751514&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAAAAAAABAAAAAAAAAAAE~
hxxp://54.197.238.106/app/ping.ashx?e=LCnUzM5l8JJPNjxRBLtb4/zZkW6G79bUt8f6YpiR28K/M iZRiJnRnHdTB6jkze/avGlMWAqZVGhQNbb34rcpnjQavldL2jCXHOzMoXfreuzIeRzata1huhetAXEFso2Hd5atJBamYqM8MU7L6Z1XFzslN/Oom5DbE2hSZV1srvsrduYhMMj23LymH6HWKlXaBQc7HR56MWNJxXQawroNmbktPzt6FdqtvzSMXg z9WmrvcVl0Mf/w==
hxxp://54.197.238.106/app/ping.ashx?e=QgW8pN5r26byj2QAAnEFBPx82bD1CPIVl505lEjGRHKRoZJTpqsyZxASc9FSZWyoGYsEX4kIHlu/0mFZouDnPtaRJ3Kmqu0qPF/e8UuaTHBgKkdlz1lRoYUad3QpOh3uU8/inQ0dV1y6KJfGT/oeAyr6Se9TnnMMjPDFOy mdVxc7JTfzqJuQ2xNoUmVdbK77K3bmITDI9ty8ph h1ipV6k2NKjmbE4rFDKYlzMOCjfNat3CGW TYGYwepaV3L2/BEw2rrJEQ9cb WUhAeb4M8AeXrDcfXn1
hxxp://54.197.238.106/app/ping.ashx?e=b1dRW7RxYKfwl4DCqEaRhC8ev2TZOcii62ls PLHCLAq gheK7Gg4DZ3oi5EKsF2X3dll9ySpyXBi830LV6OHeQDoeGvwbJQMRM hXxEXcCcOCzurm ZeawY6pZsyp29dVn5miu3RfPczYZ7/4oF2Mbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXoDAbDf1f5I9gDcoAJAtAYWupXyB/g5yjGYsEX4kIHlvi5n nh6YVLffopz0y2Q7Y
hxxp://54.197.238.106/app/ping.ashx?e=lOCrbsNL2zWYW6sXTpZ7/KBYTa7YJ/ddDe4S81RKSSsyIvs8NVvu9kXFDxkTgufFt5aWEmvF1lmyibNNhHQuhqoPWDE/bHCMqUVvKp9Lg9WpU9MRQHad4Zw4LO6ub5l59bC43VoLO9EMGHDQVw/vzGhU19XqFTVuS55OePfOVKxbaMNHmg 4ouIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSa8OW8dQbOsF zv/F4nWpfy1LqqCcUKB 1ai329YoT/oQo3Gv nP8wmYBlKlGJcuDg
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=Ka qOJkckoXHjWHokC5IQCi9f0a46N9/eq10/GADmDBu89fJv3K/CWQ14on7GBy1f82ojUnVmk1jg4jhBREgIvCV4d3G7GmUuX P2xaLa6cCbsn9VEgrCJGhRXiiBAM32H7YvwLcDXXIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZfwe6XX8Ler0VWuHFN9lRYXm3sb/Jc9bi4CY6tkU PjWGlHVWy8T0I6XgvyObhcmYFVDq65iJ/PSima3r97HUBE6rMrg41l/Ly7CST5Ycto3cE6nMAQ0x67lxVrNxtz1yEZ3jd05TL7uA7e7JlmIOJU/BXl5O1yvgpmXNWlGDYEZmFDKYlzMOCjfNat3CGW TYGYwepaV3L2/BEw2rrJEQ9ceEUGZ7qw47sqwZwxAX4ff
hxxp://173.239.4.56/online/Register.aspx?CV=2.0.0.0&ProductID=12000&UserID=&Password=&OS=10&EMail=&Newsletter=&V=3.3.9.5&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=PcwT4QFtuPDEA05CBT6a0fx82bD1CPIVuKcNdKpB42 RoZJTpqsyZxASc9FSZWyoGYsEX4kIHlu/0mFZouDnPtaRJ3Kmqu0qPF/e8UuaTHBgKkdlz1lRofUDr3 uV4Ko6jA0ovCT514E8XIWrh60PYXV1rPYBwrFqy2cd4qoQDl0oePvh0n93F2fKohH1AHQrJh3xkjGF5PIGVAz0udrAvPNAytr0BkG FJiQzt6kUHWE1CF4DuZf3BUb3WcrzZ7HySmeDQikgk=
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=FwW11b 20b6fZNC1TqAoBA2dE/SZourWTEgCpOx0T0GQL2F0hg1RicLJlw9FGc64W40V8RHoWcfADsKdK4BIvJzI6WjgFlNrd6j7/wRBDsRoqvWX6JwkevDehHIxlAXyb98NyY 3Jv/oKdNf4wHzMP/l0k1T1nn7b588fAguahpqadCmmmNJTNNeVrTC3wKjwfrj lvkwi3PeAWvHdcyb2damvrUQZsSBJrpn5593i7JkPoDWmx/bJrdSyBxPRpgkex5UpBoxTMMW2oEbpyuz9p5gsvoA3US
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=KC46TpkJIZznGREG7sgAN5kHk6lYMiFwka70kbUmYHH7RH4w/5EvdUqAWhGQi7pGk2HxL2Lh3QfhrDqaDSP7qD7whcneFjZtnMjpaOAWU2t3qPv/BEEOxGiq9ZfonCR68N6EcjGUBfJv3w3Jj7cm/ gp01/jAfMw/ XSTVPWeftvnzx8CC5qGmpp0KaaY0lM015WtMLfAqPB uP6W TCLfid DGu7L2IfOGA aYz3qB2EfZmulEUHKsyuDjWX8vLsJJPlhy2jdwTqcwBDTHruXFWs3G3PXIR40rkbBe1jq 6d7D/p//KBBNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaC5k/79Gow98g==
hxxp://s3-1-w.amazonaws.com/partner/gim394750002/release/live/InstallGenieo.exe
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=wlkQ3WKgYpSE2rQtmh2LBMH64/pb5MItlzMqADZ2OvYSZTerw9Y85XkjLFx9TDtKeHo6FOnjNt3Tp8VZQ/4p3GivYS/d2rWv9A8dpvtBeO2hc3DbjNrW8PQYnQ1xoKSBiZYn8TH3Pe3MlW9RFqOniiR/VPwArHZ1QMCg3fniKLWzp3t4zCe899YNvMh53GZd/HzZsPUI8hXft0AGFKL6V8UWbVgwixNWt9kbY6X6G3rYz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW aNKDh4dmbgaJe7HkSXGWaA0BPmlVlU0prupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8MNAWquLWplE=
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=984e31dVhw3Z0iLC9WK4WOZsZFYgTv0v2YTeaOaZJPFysSIQM/WMqtGQDVZU32tJRZ4jWEvEgl1Ieo6/gOuIoWivYS/d2rWv9A8dpvtBeO2hc3DbjNrW8PQYnQ1xoKSBiZYn8TH3Pe3MlW9RFqOniiR/VPwArHZ1QMCg3fniKLWzp3t4zCe899YNvMh53GZd/HzZsPUI8hXft0AGFKL6V8UWbVgwixNWt9kbY6X6G3rYz9UHnTAf3Mvwero5ya7SNHyd9Jj1gdzCfQagY8pW aNKDh4dmbgaJe7HkSXGWaA0BPmlVlU0prupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8MNAWquLWplE=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=j7YMo/n29XMqqDJt46TNcdnSIsL1YrhY5mxkViBO/S MDmRWpWBZ0PxJo1EJGyYRjOluN4MfK82Ul/CEn08 CUbPPvBBzS9odRGSPtD5 1gbOPe11KRbhmNS7NBdn5Y UeZLRmueCpr 7rPtSKe/ JqfQ7l07EVJDzWhC2rNQ6ya2dF0VKZsa4Q2/MQzLTqMBPEhRyyBD7A7Ux5MSUiBG6zbMzc4pOx2GGp9MstS3cDTDTdslR3ozsRaU2At1Xqvl0LTeIZ6yJ92wY9krKeIwcv4S/K6mfkWhIAbznvPq9LAXh4LPUO ueIu4Zx3YXXHbkP33eKXEVDuckMp0VGSOWNPI2OPMQSaf8y/TzWjMf7rKwD6t b1ZXOyNswLaXfgaxUQUcDr35qWYgFHiakHd8Owv/FmpIuFE3YRyqSPEeI=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/25296.ashx?e=043Mckb8Lnj5nRk39lR6RcH64/pb5MItBBvtTcvyOOgDt2EUeZbtRVHmS0Zrngqa/u6z7Uinv/jJ625QtO7cCECN9h bV19VoPPb/i9FtJTgL4xsffnkQbPiCC4paVhdAGW4B5KF0X3G4Lnbcm9hh1KSSkgkzJM10ClxJsX5qO1ZySIyJVh8lz8lbkb0am4Y
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/25296.ashx?e=043Mckb8Lnj5nRk39lR6RcH64/pb5MItBBvtTcvyOOgDt2EUeZbtRVHmS0Zrngqa/u6z7Uinv/jJ625QtO7cCECN9h bV19VdXQO8eCkzNk9LWPkwGrB/imF904v4t2DTTuHrYVulo109x0h yMmOq3 e5cYLWVDvEq1XCmEIT/KGwMMc0gnpNgExseWQzn2f6OZPQtzuZxpdD3k9Bz56StbFykGQeFJDeQKlJvveiYBN5p9ENNd42Jy LrysKIChDb8xDMtOox69ZimTX2csKzbMzc4pOx2GGp9MstS3cDTDTdslR3ozqAqUZoVYaYqOh7dSyef3K/a9dSBDkVKEEn/27iYAIjK5pdl3V4yoSZtC3ZUXmNv4hOEZ9fC9NN7s9C7tmmeIQ4UJj9eY3tRmk7I4yfJnN09f40hcgVNJWNmhoIRlNpk1mikCyRdzxo8v7Oo1qwnkCjjbJDwZzUwO IENZVDItwmaAzdvG4/9NloJg2UA3GeKNsBE3goakaNuPR5NfrntvDVo4ooxmVMPwjkjucBSk1dZJXwSvkB4LUW2SuoR83S f89O44axxrpFmpWsqJza8G jCJhwZ2krd1LISTKeN3CckdTtpt CJF3lUqbxpVPs/eJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5ZtT8IaYnlic=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=uWabAt9SLcwd5zMhdw4gNpkHk6lYMiFwapPLbuJFxiVAXdQqxJ1vaxGgYkoQykSFfl0yK7ww8bR99iWMDdPSC3WGwZvzKj/ZOSOEF0chPXRy6 8tacmbVSfB/NHdLiFC1JJpRAUOpYSeY/e3xqcYNySvg8nUiIo3aTN6JbPRttbb8zyMlAjNJ94BVzIM sbWFAL52sIXt4UeH8s8AG8ECxxc81u2rgCm44UuTa3qd5D7MusukiOxFQ/nGwVmCS6yE4/IIoWPFRUEB1KJjJJfUAE70KA8ZXhbA8YCZx49749T/rv 3Ugl9NjP1QedMB/cy/B6ujnJrtI0fJ30mPWB3MJ9BqBjylb5Pk55LBQN29oKKSszP/5sI8gZUDPS52sC880DK2vQGQb4UmJDO3qRQdYTUIXgO5l/CgTTFbRks1o=
hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=/kyMh6fFcsSfZNC1TqAoBOrinWEtHMrXiUSU3wY9EyZgKkdlz1lRoe viA2bCzBJ8S85LP28b9XoIGt9tn96dHczOeuk4NHAZlWzJoJS0vpeeVUornuiCLupiJTlyOfefm7DCYXIaQfnSx59os2ZBGEmnuqRRnk8cyhMDFV3OWTM2kLK0Eh6GOhAyMRSteYLfy2nd2OoBNWZcVk3bWa3iMJb UIfjrRxmoi0CE64JPPM/9VP4YRizveJIUUI29KJua/YhbaaQtbhLKDJ7gHH44roFtpr/bY5x 9v0hi6ojl/pUrWo8oa7dY GMQdF3uJi4Hm9PT1ORmf0Es2LXheJLtuZg2RJEsp 4qjWxV4m16OBBFKtmAQa wAawvpuok/gc3cbc64uvo=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/1638.ashx?e=o4wkB1bL2nKZB5OpWDIhcGqTy27iRcYlQF3UKsSdb2t7HO4WybUyR1UeQGsGyqMaUBoq0tYrWJQaFTly08TKaZ9eFhsT1abeQqykZerlmJWOBvq/txek 4iYlmtiSGZOjPDFOy mdVxc7JTfzqJuQ2xNoUmVdbK77K3bmITDI9tzfMa2zgJTnw==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=j7YMo/n29XMVCZIctrluXvx82bD1CPIVELGhIJQe0HZ4E7mrr1h80riKIFo3W8f23Wq7IsWCDz7LtnwqBBAAaNaoPZj94HyTzprDiolRFccz/yeZN BbCCmF904v4t2DaVtcL0PMGkj3iSFFCNvSibmv2IW2mkLW4Sygye4Bx OK6Bbaa/22OWbU/CGmJ5Yn
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=j7YMo/n29XMVCZIctrluXvx82bD1CPIVELGhIJQe0HZ4E7mrr1h80riKIFo3W8f23Wq7IsWCDz7LtnwqBBAAaNaoPZj94HyT6LOwEGQvh2zV2TxY7/sL 44G r 3F6T7U6q7EvjWjEUpXTEKkNwLoQKR8BH1AzvaPPinFkosvv9rREKBtez 7WKW/rKS vRXCAOOMT3NqqKes3TcA28cXQBEHhrcWo7yWUQOfMPJmmh0ybeGoyy0n/LTq3A5G0uD18dH0Dqne6k4zRLhdZdA1ySsz132oq8QdKhmr1s1SeLNSxMOktmsJuXkffI7Bc/8CjIrR103eiScpBTrnNl8 QzgS38rypWTnpREYU9txHgvkahbKtRxSuTlLpRpGef1HRWCGgD35NKpP/58BClMEV0zgN2QlL7bUZOTrxLzAqz5PbKQnR2ahvRSgOOuFwqPUe/lNjkrreVLV GIYMVmKXpVpzwoowpDIzgoMNgVSZqtuKkFbJdih3 4IimkuEAS4i7hnHdhdcduQ/fd4pcRUO5yQynRUZI5Y08jY48xBJr38Km4JMgAXQ==
hxxp://test.youtubeaccelerator.com/video_accelerator/wizardtest/SMALLTEST.HTM?random=561931&mode=nolsp
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=EYAmqppYZO/Z0iLC9WK4WDbtqEH pn2ijA5kVqVgWdAgLxC0aXqYrYyox39H7ctIe8oePBO1o3KmcJNx5UwP Vi2s6XsF8NYPpbX8eNZzIIUAvnawhe3hU72ISjKawWsoSwUHtq20zGrMrg41l/Ly7CST5Ycto3cE6nMAQ0x67kcucdFKeANzw==
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=EYAmqppYZO/Z0iLC9WK4WDbtqEH pn2ijA5kVqVgWdAgLxC0aXqYrYyox39H7ctIe8oePBO1o3KmcJNx5UwP Vi2s6XsF8NY0jd2Ua9SYWgE8SFHLIEPsNuIAbgWXib3hDb8xDMtOox69ZimTX2csKzbMzc4pOx2GGp9MstS3cDTDTdslR3ozqAqUZoVYaYqOh7dSyef3K80qxoLIs2wicAgCBrynT3T/Dw8o2fbvVqcMM7jAoddqLdDuCot28iq0o3 yQeiL1SuvBinayp0tcns/kzQV2BeVzGXirEinUjygIx XkkBquLrC93K5FW5l208O4rRao0E6NcS/ao7oObdRP0O2TtGfu0Hoi4IoRaoc6SnqWp/oWNRnHx8enwk/aK7d1sV3iVS6qgnFCgftRA3YsNRBZWc6/aMBz7Ly9o89e8YHMKynf1HMm1Ts0Hqd5LUq7 5Y6PN25QukZWk/lWZ9Aknq7ogvFXyQpt50unG4Lnbcm9hh1KSSkgkzJM10ClxJsX5qO1ZySIyJVh8lz8lbkb0am4Y
hxxp://test.youtubeaccelerator.com/youtube_accelerator/wizardtest/SMALLTEST.HTM?random=564177&mode=nolsp
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/13570.ashx?e=hXeqmv1IpelezyBKiN6u EaSrJjHbiRO7OXLse4BafQHqUQ0J3/4E9SSaUQFDqWEnmP3t8anGDd5NQIjO3Pvbce7kS6GRZSsCy5U1DKQBR/1HrjuYPfZlNCUHeR8YCF3eUieKUOy0CNssIFedkeDcwU A6kiYcjN5jgwqhpV 3RVAAKZHGiEvoUuxfjpmZqk49BuL0n8vhTQE6ga EGy2YzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbc3zGts4CU58=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/28148.ashx?e=b1dRW7RxYKceWuDhZt9/CZkHk6lYMiFwsTnO2KqeLVhAXdQqxJ1va3sc7hbJtTJHVR5AawbKoxrV3H17CkcJAVCJBxBnzZq4YCpHZc9ZUaFgmm5xjmBlpCI3FLqKedV9QoAE/or KqogGeUpHHIWiSSfRcuIfR0fUu0KI1IApgUwqc65TUDdvwHwk6fyNraudfO3QRiGoOfMI41K2f6iZFP u/7dSCX02M/VB50wH9zL8Hq6Ocmu0jR8nfSY9YHcwn0GoGPKVvk=
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=100&n=init_start_funnel_step_name&rnd=1429596767
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=100&n=init_start_funnel_step_name&rnd=1429596768
hxxp://ipgeoapi.com/
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=70121&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_32&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&mdat=&procstarttime=1429596767&procruntime=3&rnd=1429596770
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=70299&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_36&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&mdat=&procstarttime=1429596768&procruntime=2&rnd=1429596770
hxxp://s3-website-us-east-1.amazonaws.com/installer-error.gif?action=sesamy&app=70121&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&error=0&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596767&procruntime=3&rnd=1429596770
hxxp://s3-website-us-east-1.amazonaws.com/installer-error.gif?action=sesamy&app=70299&appver=0&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&error=0&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596768&procruntime=2&rnd=1429596770
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000171&country=ua&app=70121&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596767&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596767
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=200&n=init_end_funnel_step_name&rnd=1429596770
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000805&country=ua&app=70299&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596768&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596768
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=200&n=init_end_funnel_step_name&rnd=1429596771
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=300&n=deploy_start_funnel_step_name&rnd=1429596771
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=300&n=deploy_start_funnel_step_name&rnd=1429596771
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=500&n=deploy_notification_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=500&n=deploy_notification_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1429596772
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=700&n=deploy_ch_start_funnel_step_name&rnd=1429596773
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=700&n=deploy_ch_start_funnel_step_name&rnd=1429596773
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=800&n=deploy_nova_start_funnel_step_name&rnd=1429596773
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=800&n=deploy_nova_start_funnel_step_name&rnd=1429596773
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=900&n=deploy_ff_start_funnel_step_name&rnd=1429596773
hxxp://173.239.4.56/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596773&SBPIDS=1&KA=1
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=900&n=deploy_ff_start_funnel_step_name&rnd=1429596773
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596773&SBPIDS=1&KA=1
hxxp://online.speedbit.com/online/RegisterAnon.aspx?ProductID=12000&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1429596774
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1429596775
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1429596775
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1429596776
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000171&i=10000&n=deploy_end_funnel_step_name&rnd=1429596776
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1429596777
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1429596777
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&LFMR=_ffDll_0&app=70121&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_32&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596767&procruntime=12&rnd=1429596779
hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=70121&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0D9ACFEE1BA741D1AC9CCD394DDF1D99PI&srcid=000171&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx6dHNtdHljMCxkY2RmMjJjYy05MGM5LTRmMGEtOWQwOS04ZWJhZDQ2MzYzNjYsIiwidW5xIjoiZGNkZjIyY2MtOTBjOS00ZjBhLTlkMDktOGViYWQ0NjM2MzY2In19&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1429596767&lifetime=0&silent=1&crtnm=na&procstarttime=1429596767&procruntime=12&rnd=1429596779
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000171&country=ua&app=70121&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596767&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596767
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1429596779
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2QI8HtM9wp5Tx0cXu7AB1uimF904v4t2DIApimWCrqanh60kwO3gtxYzwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2yETj4nts NO517CUeh0QiwTxIUcsgQ wfJnh8VDEgRSlTNRWMyvAk6UqjDuAivmJ4m/vJXDvF2G8SrVcKYQhP8obAwxzSCek2ATGx5ZDOfYQeWksviRUhRe13wRG2Zyfh8h5o3YrXrZv qR/r3k14sbgudtyb2GHUpJKSCTMkzXQKXEmxfmo7VnJIjIlWHyXiu2tbKFpYG13f64oXp7sfcknNqp5tltPRs8 8EHNL2h1EZI 0Pn7WBs497XUpFuGZr6aPC6mWRY=
hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000805&i=10000&n=deploy_end_funnel_step_name&rnd=1429596779
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=bNFVvuIwcz7Z0iLC9WK4WBIP0bnKg50jjA5kVqVgWdD8SaNRCRsmEYzpbjeDHyvNlJfwhJ9PPglGzz7wQc0vaHURkj7Q ftYGzj3tdSkW4ZjUuzQXZ WPlHmS0Zrngqa/u6z7Uinv/ian0O5dOxFSSpm3wyZBT 2yETj4nts NO517CUeh0QiwTxIUcsgQ wWs /9f4We1ocVdO68mAhaoKbHXQ3LZlHwdE4jBu2OwY8 KcWSiy /2tEQoG17P7tYpb spL69FcIA44xPc2qop6zdNwDbxxdAEQeGtxajvJ8DVynAnBV8ozwxTsvpnVcXOyU386ibkNsTaFJlXWyu yt25iEwyPbjsvnWTmObjOwEISYEO9NSxNkg14r8k5Iv7dZ9u ci83OgUzS/GO 9Kpy IW7f8aRTJoPpScUmaA=
hxxp://wt94bf4ec-g48pastf.netdna-ssl.com/10068.ashx?e=s0jsdppK9OufZNC1TqAoBE3dSGLo0YSs1VMaOJFqXYpm5LT87ehXaouB5vT09TkZn9BLNi14XiS7bmYNkSRLKfuKo1sVeJtejgQRSrZgEGvsAGsL6bqJP7iKIFo3W8f23Wq7IsWCDz6QG2IGXsglf6yVpsz5btdlnKfUFSSn msc10t7BHb3gMjKRY6Iofb7CNjw3TJVaaftecqRQrG/Wx7XFrkvV19SZ1qa tRBmxIEmumfnn3eLsmQ gNabH9smt1LIHE9GmAQ VwoE0aIX/TbXnzkx FKpYXnBYRIAoJ1hsGb8yo/2TkjhBdHIT10cuvvLWnJm1UiAOXU9hSaAQ==
hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&LFMR=_ffDll_0&app=70299&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_36&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=17179873281&asw=0&asw2=1073750533&asw3=-2147475456&asw4=34816&crtnm=na&procstarttime=1429596768&procruntime=13&rnd=1429596781
hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=70299&appver=&ver=1_36_01_22&version_date=15-04-21&bic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&upi=d5d8d8a61601751d467a5854a16ce35a&procid=3A4CAEB17143417A8BA6A3F590C2EA8EPI&srcid=000805&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJGNEx3c210eWMxLCUlUElYR1VJRChhZmY9c210eWMmc3ViPTEmcHJvZHVjdD15dGE=,&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1429596768&lifetime=0&silent=1&crtnm=na&procstarttime=1429596768&procruntime=14&rnd=1429596782
hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=d5d8d8a61601751d467a5854a16ce35aIE&verifier=e9d6e2e9e6a34b6d6a4be51af1aeacc2&campaign=000805&country=ua&app=70299&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1429596768&asw=0_1073750533_-2147475456_34816&browser=ff&rnd=1429596768
hxxp://online.speedbit.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=7f18dd1b-ec41-4752-9468-5f9624612952&Password=mm7DBqQs&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596785&SBPIDS=1&KA=1
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=7f18dd1b-ec41-4752-9468-5f9624612952&Password=mm7DBqQs&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596785&SBPIDS=1&KA=1
hxxp://www.theviilage.com/searchprotect/up?ptid=smt&sid=IHProtectPlugin&ln=en_us&ver=4.0.1.2105&uid=535559167_198339_B48A115F&dp=0
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=0&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1429596790&SBPIDS=0
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=2&index_in_screen=1&index_in_session=2&display_height=195&0.8906559107847234
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.5528722536780852
hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=134bc0d4-cd69-4c5d-bd9b-0a36a7095905&Password=GLA9Y4un&OS=10&V=3.3.9.5&VS=1&Beta=0&Aff=smtyc0_0_0_0_0,dcdf22cc-90c9-4f0a-9d09-8ebad4636366,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=20131113143800&XMLUpdateFailed=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1429596796&SBPIDS=0
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=pc_messenger_for_android&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=2&index_in_screen=1&index_in_session=2&0.4142904310700625
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.9104375687078131
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=3&index_in_screen=1&index_in_session=3&0.4049143552587808
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.9583576309473749
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?95e2710ce7116392
hxxp://a1621.g.akamai.net/pki/crl/products/WinPCA.crl
hxxp://a1621.g.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=4&index_in_screen=1&index_in_session=4&0.2014881967661576
hxxp://installer.betterinstaller.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.49850194038478096
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=6&utmn=933000356&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Offer_Accepted&utmht=1429596840246&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~
hxxp://theswiftrecord.com/mg?alpha=UUFbQCJjAx9tEGh1dGotUAUITSJRB1kxK1JZLwU8VRUaI1UFT0YyTVsKWjd2DyVDFCpQNTczZDxCeGozQklhTVApFkcPKQFAQzZrVi9y
hxxp://theswiftrecord.com/fp?alpha=XjJ8Pkx/TBBzLSYRUxRDX3YvM0xebmpPDXkzPSEQWSZxPgpcQ3U9VCp3YjoYH1ELakJDQBM0B19FKGAoRmZ0PzgyQTpTT30YbS1ae2YHM1MdM39yEkkqK0pJIFx8fFlbZj0qSA5IdUEgWXVgJR4EIXFqM19MEjgTQzQtYEwJJF4zXE13b2AfEmtsKx12IgJQXk0uamhBWGYhUkkpTHgpTQlqMCtNG098WCRVYDI6DVEjaTlkThAQKlwfOU06BQ45WXYqVGVtehRQMjVsQHdxGiwqaDgoLURFNSlDTShafn5GCSB8JS5SECgXZR9gFG1LV3otPnIwCBE1DUYzL1hMHiJZajdBMDYiTntrbCZoKjV7TUhpK3tyYUE0LV9NKFp3DlIrZFJcPQkqFRx/Sgx9
hxxp://theswiftrecord.com/ii?alpha=XjJ8Pkx4FBptWzEwUxRDX3YvM0xebnAWQWsBaC8JDG42eQlLQx8Pewo0cFpIUXs7PyYHAkd+dxY5L2JbXnkAOiQyMSAiTgpuaTsPe3EHER9zbScvEQ1mPwEbJVULCiZfYSItVH48fTo/WHFoMQBzIXsZLV8wEz4MMzBcZygtYBZjfD00KGRHDW5rPgciNhRSTwIufmoQSzc/Fhl+LjwjXQE2aGgVVAwpXnYJJhJ6QmQpeGsuXlobPg5CKixkX1lmFmlvb0xhcUdqDXxkWmZ7SgVDe3ckO08PdDVSSixBLCUUTjxjbhxJQwERcR4vI2dLRjQeMm4KG1V/HkUkTSAFDTJDfWNvbm9+WnF+en1MYHFTDxAMJGppDkkpLkRMKUw9KRIeOnN9WUsfLxMyVmBhJh0Uezo3YQATH0lQFWh0IQJLf2VgY3RlajIpSz8ublo7JFQWQxg4JG1QRX4/EwolVX5gUVhhNnUYBk58QidcemU+FwAlc2sxVEMWKk4dYCAUCwckVShub21gLz5xARRKD3ZtVwNDaF0VEWFeY21PKlUbLz4FRHNGVQ5aDClYRAUyJH1MXjQae1MtJ2sseht3dnIuDiFZbW8mcGUvXFowOTYYNHgHUQM+UitJAjk=
hxxp://theswiftrecord.com/if?alpha=YS9EPRcOZjJOP1cmaxcYYGsXMBdhc0gVGlQcUCxSM3MOelJ0XicMIDUpSFkTbmYDPH04H399LCkkF2EAYWQ4OX8NLBghFTVzUThURGw/EkRMcB8sSjJ7BwJAGkgzCX1gfBouD0EhRTlkZ2xQMltMPEMadmAtKz1XDC1kZHMSfS5oMgJOXnRNbAoMYQZmdm4PdmRqBj8TYXdXTBMBB0t9C2Z7BisWKlFFVXlnaFg4RittFD4ZIwYnZgA1aUk+QzFsbGg3fW9ZRxwxc0w4XBQtMlMLIjVHbkphfUQea0gSSxpocSFbb1t0BkksID05B3wFISlHbHYzAG4pCj5vQCMMGSNrfz5MclBlAVcqDGwdWmwiVAVDcR06HjRpSB5JRh1WARt3OE1pUW0MGltzc2tGOlg6P0FpeyIMaHkMLnwFIVA3ISg3cQ4zBjdOcy8DZhUQWmwESXpwGnxTEnRIBUJDUSU7WiMrWzIEahVJT289bxg2DytoB2ViYUUrP1drdERsAWRwPT1rCisMIxA6c1MyRRk5cgxBLkUTMAgiPEUeSklMMgFkGQ8Of01pAEk/CgwTKS0SeTQnFSwwG38jRRtUUjBDMWpeZCNLaFd9AVNjMUshZD9GClZ4IzY5DS55RHlQcCcRPCI=
hxxp://installer.betterinstaller.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=5ee27ba0e055bb4684b8648858d31d9a&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=a2ad2313ef53bd72292b756abcab96ff&tokyo_csrf2_timestamp=1429596751&slot_number=1&index_in_screen=1&index_in_session=1&0.9208263061749289
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.6.4&utms=7&utmn=1472907400&utmhn=installer.filebulldog.com&utmhid=356683587&utmr=-&utmp=Offer_Accepted&utmht=1429596847128&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAgAAAAABAAAAAAAAAAAE~
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=73055282&utms=9&utmt=event&utme=5(Messenger*install-desktop-client-new*1.2.23)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/DesktopMessenger.exe/11111&utmp=stats&utmac=UA-53163344-3&utmcc=__utma=37894201.75610525.1429574400000.1429574400000.1429574400000.2;+__utmb=37894201;+__utmc=37894201;+__utmz=37894201.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/DesktopMessenger.exe|utmcct=/11111|utmcmd=referral;+__utmv=37894201.-;
hxxp://installer.betterinstaller.com/awegvlcmediaplayer1900/vlcmediaplayertcmt/40da6fd4d86af64fa44c08b317ad86e7?v=2.0&muid=96D78F35E7B7EA4FC32736D428DF43B4
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=69679079&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=54986866.62946922.1429574400000.1429574400000.1429574400000.2;+__utmb=54986866;+__utmc=54986866;+__utmz=54986866.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=54986866.-;
hxxp://d2z5psu5fxw71b.cloudfront.net/images/Tokyo/tokyoLightGrayStripesBG.jpg
hxxp://d2z5psu5fxw71b.cloudfront.net/images/Tokyo/tokyo_sprite_full.png
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=82030882&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=59077916.52149898.1429574400000.1429574400000.1429574400000.2;+__utmb=59077916;+__utmc=59077916;+__utmz=59077916.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=59077916.-;
hxxp://plus.l.google.com/__utm.gif?utmwv=5.6.4&utms=9&utmn=1727154030&utmhn=installer.filebulldog.com&utmhid=1748701739&utmr=-&utmp=Installer_Init&utmht=1429596849188&utmac=UA-31676879-1&utmcc=__utma=1.1440305718.1429596668.1429596668.1429596668.1;+__utmz=1.1429596668.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=&utmu=qhCAAAAAAAABAAAAAAAAAAAE~
hxxp://plus.l.google.com/__utm.gif?utmwv=5.3.8&utmn=27137216&utms=9&utmt=event&utme=5(installRun*failed*ie,ff,ch)&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=1&utmfl=-&utmdt=-&utmhn=web.com&utmr=res://C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe/11111&utmp=stats&utmac=UA-51970895-2&utmcc=__utma=31941152.92397420.1429574400000.1429574400000.1429574400000.2;+__utmb=31941152;+__utmc=31941152;+__utmz=31941152.1429574400000.2.2.utmccn=(referral)|utmcsr=C:/Users/adm/AppData/Local/DesktopMessenger/web2mob/ctmpua.exe|utmcct=/11111|utmcmd=referral;+__utmv=31941152.-;
hxxp://d1z9ocnzqrnjt0.cloudfront.net/mirror/nerocrossrider/appshat_generic.exe
hxxp://d17g6dyg7fgcv7.cloudfront.net/mirror/filesfrog/UpdateCheckerSetup.exe
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5f7079ad37977473
hxxp://a1621.g.akamai.net/pki/crl/products/microsoftrootcert.crl
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt?a7806eeaf8fe6574
hxxp://crl.globalsign.net/root-r3.crl
hxxp://crl.globalsign.net/gscodesignsha2g2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQpEOCqbmTiQA9OjY//t2aa8NSkuwQUGUq4WuRNMaUU5V7sL6Mc+oCMMmsCEhEhZyg35kUM7JUe4UHDT5+Nwg==
hxxp://crl.globalsign.net/root.crl
hxxp://crl.globalsign.net/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhZ1N/ArcYWNWqP8XWy7QmXA==
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBILJd3le4hjatTZfSO5nIg=
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s=
hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs=
hxxp://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQDmFsbNcBDBl+cij2b1soa7
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=1&index_in_screen=1&index_in_session=1&display_height=170&0.6079360980039414
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc=
hxxp://a1621.g.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8=
hxxp://installer.betterinstaller.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=swiftrecord&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=1&index_in_screen=1&index_in_session=1&0.4441371446485662
hxxp://installer.betterinstaller.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=40da6fd4d86af64fa44c08b317ad86e7&uniqid=false&affiliate_id=awegvlcmediaplayer1900&software_id=vlcmediaplayertcmt&sponsored_id=appshat_madness&tokyo_csrf2_key=6624f6f23bec107dc44665390494c8f6&tokyo_csrf2_timestamp=1429596849&slot_number=2&index_in_screen=1&index_in_session=2&display_height=90&0.45001640321370245
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo=
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U=


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

The Application connects to the servers at the folowing location(s):

ProtectWindowsManager.exe_3696:

.text
`.rdata
@.data
.rsrc
@.reloc
j.Yf;
_tcPVj@
.PjRW
SHELL32.dll
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
GetProcessWindowStation
operator
MaxPolicyElementKey
pExecutionResource
SHLWAPI.dll
USERENV.dll
%dYeArdMoNthdDaY
file_url
GET %s%s%s HTTP/1.1
Host: %s
%sUser-Agent: Mozilla/4.0 %s
POST %s HTTP/1.1
%sContent-Type: %s
User-Agent: Mozilla/4.0
Content-Length: %u
%*s %d %*s
%*[ ]%[^
?456789:;<=
!"#$%&'()* ,-./0123
ShellExecuteExW
SHDeleteKeyW
GetWindowsDirectoryA
GetProcessHeap
GetSystemWindowsDirectoryW
KERNEL32.dll
USER32.dll
RegCloseKey
RegOpenKeyExW
RegCreateKeyW
ReportEventW
RegOpenKeyW
ADVAPI32.dll
PSAPI.DLL
InternetCrackUrlW
WININET.dll
WS2_32.dll
WinHttpReceiveResponse
WinHttpSetTimeouts
WinHttpSetOption
WinHttpGetIEProxyConfigForCurrentUser
WinHttpSendRequest
WinHttpWriteData
WinHttpConnect
WinHttpCloseHandle
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpOpen
WinHttpOpenRequest
WinHttpGetProxyForUrl
WinHttpCrackUrl
WinHttpReadData
WinHttpAddRequestHeaders
WINHTTP.dll
SensApi.dll
VERSION.dll
GetCPInfo
.?AVunsupported_os@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AUIExecutionContext@Concurrency@@
zcÁ
.?AVCHttpClient@@
.?AVCTcpipSocket@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
6!676$717
,050'101
7"7&7*7.72767:7
1!1%1)1-11151
00S0d0
5 5$5(5,505
? ?<?@?`?
3 3@3`3|3
combase.dll
kernel32.dll
mscoree.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
USER32.DLL
portuguese-brazilian
advapi32.dll
WindowsMangerProtect
SOFTWARE\supWindowsMangerProtect
xa.geoip
visit.heartbeat
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action0=%s&action1=visit&action2=%s&update0=ref,%s&update1=nation,%s&update2=language,%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s
hXXp://xa.xingcloud.com/v4/sof-windowspm/%s?action=visit.heartbeat.%s&update3=version,%s
Report Start.
C:\DoStartTEST.DAT
Report Heart beat.
ProtectWindowsManager.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
TypesSupported
%s is already installed
%s installed
%s failed to install. Error %d
%s is not installed
Could not remove %s. Error %d
WindowsProtectManger
Advapi32.dll
/c ping 127.0.0.1 -n 2 > nul && del
"%s" %s
psapi.dll
Explorer.exe
update.exe
%s_%s
\\.\Phys
hXXp://
Software\Microsoft\Windows\CurrentVersion\Internet Settings
http=
..\Src\json\src\json_value.cpp
..\Src\json\src\json_reader.cpp
xxxx
WinHttpClient
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
hXXp://xa.xingcloud.com
..\Src\json\src\json_writer.cpp
Assertion failed: %s, file %s, line %d
WindowsMangerProtect Service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
WindowsMangerProtect service
SysTool PasSame LIMITED
Windows SysTool Service
20.0.0.1953
Windows SysTool.exe

ProtectService.exe_3960:

.text
`.rdata
@.data
.rsrc
@.reloc
GET %s%s%s HTTP/1.1
Host: %s
%sUser-Agent: Mozilla/4.0
POST %s HTTP/1.1
%sContent-Type: %s
User-Agent: Mozilla/4.0
Content-Length: %u
%*s %d %*s
%*[ ]%[^
?456789:;<=
!"#$%&'()* ,-./0123
file_url
E:\supsoft\SupSearchProtectV4\SearchProtect\Bin\Release\ProtectService.pdb
GetProcessHeap
GetSystemWindowsDirectoryW
KERNEL32.dll
USER32.dll
RegOpenKeyW
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
SHELL32.dll
MSVCP110.dll
InternetCrackUrlW
WININET.dll
WS2_32.dll
SHLWAPI.dll
MSVCR110.dll
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
_calloc_crt
__crtGetShowWindowMode
_amsg_exit
_wcmdln
__crtSetUnhandledExceptionFilter
WinHttpCloseHandle
WinHttpOpen
WinHttpSetTimeouts
WinHttpCrackUrl
WinHttpConnect
WinHttpOpenRequest
WinHttpSetOption
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpReadData
WINHTTP.dll
SensApi.dll
VERSION.dll
PSAPI.DLL
USERENV.dll
.?AVCHttpClient@@
.?AVCTcpipSocket@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
2-2v2
hXXp://
Software\Microsoft\Windows\CurrentVersion\Internet Settings
http=
WinHttpClient
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0) in my heart of heart.
hXXp://xa.xingcloud.com
xxxx
%u_%u
%s_%s
%s_X
\\.\PhysicalDrive%d
UpDateProcess.exe
hXXp://VVV.theviilage.com/searchprotect/up?ptid=%s&sid=%s&ln=%s_%s&ver=%s&uid=%s&dp=%s
g{2EFFE99D-743D-44D0-BBF2-F9DDDEA2F92D}
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
Report HeartBeat
cmdshell.exe
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=visit.heartbeat.%s&update0=ref,%s&update1=nation,%s&update2=language,%s&update3=version,%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action0=xa.geoip&action1=visit&action2=install
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=uninstall
explorer.exe
Advapi32.dll
"%s" %s
psapi.dll
Explorer.exe
json_value.cpp
ljson_reader.cpp
ProtectSvc.exe
4.0.1.2105

HPNotify.exe_2060:

.text
`.rdata
@.data
.rsrc
@.reloc
<9%uo
wszUrl
strUrlTemp
hKEY
strSelUrl
strUrl
strConfUrlTemp
strDsUrl
strHpUrl
strCmdLine
tCPW
%UUUU
e_GetBrowserCurrentHpUrl
e_GetBrowserCurrentDsUrl
URLDownloadToFileW
URLDownloadToFileW ret:0XX
Error : %d
inflate 1.1.3 Copyright 1995-1998 Mark Adler
1.1.3
monochrome
unsupported bit depth
`'\%D,3
Run-Time Check Failure #%d - %s
%s%s%p%s%ld%s%d%s
%s%s%s%s
RegOpenKeyExW
RegCloseKey
del /s/q %1\*.*
%suninstall.bat
E:\supsoft\SupSearchProtectV4\SearchProtect\bin\Release\HPNotify.pdb
KERNEL32.dll
GetKeyState
USER32.dll
GDI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteA
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
SHDeleteKeyW
SHLWAPI.dll
MSVCP110.dll
MSVCR110.dll
_calloc_crt
_CRT_RTC_INITW
__crtGetShowWindowMode
_amsg_exit
_wcmdln
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
__crtSetUnhandledExceptionFilter
GdiplusShutdown
gdiplus.dll
IMM32.dll
DeleteUrlCacheEntryW
WININET.dll
COMCTL32.dll
GetProcessHeap
#*1892 $
%,3:;4-&
.?AVCActiveXEnum@DuiLib@@
.?AVCWebBrowserUI@DuiLib@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='x86' publicKeyToken='6595b64144ccf1df' language='*' />
3?3
1-2}2
77t7
9":,:6:@:
12u2
: :$:(:,:0:
4 4$4(4,404
>$?(?,?0?
2 2$2(2,20242
0 1@1\1|1
hXXp://VVV.bing.com/
hXXp://VVV.yahoo.com/
hXXp://VVV.google.com/
%sconf
web/?type=dspp&
web/?type=dspp
hXXp://VVV.v9.com/
Itemd
BrowserAction.dll
%u_%u
%s_%s
%s_X
\\.\PhysicalDrive%d
\\.\Scsi%d:
UrlEdit
conf.xml
hXXp://v9.com/license_agreement.html
hXXp://v9.com/privacy_policy.html
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.show.%s
hXXp://xa.xingcloud.com/v4/searchprotect/%s?action=set.other.%s
%stmp%d.tmp
urlmon.dll
main.xml
explorer.exe
Global\{5F26509F-29FE-4598-8800-FA22CE9CC17F}__Mutex
IeWatchDog.dll
BrowerWatchFF.dll
BrowerWatchCH.dll
Global\GUID(6D05BFEC-4307-4649-8963-962A24345DF4)
msimg32.dll
User32.dll
WM_KEYDOWN
WM_KEYUP
WM_SYSKEYDOWN
WM_SYSKEYUP
0xX
keyboard
msftedit.dll
password
%s%s%s
Correct password required
%s\%s
WebBrowser
transshadow
transshadow1
dest='%d,%d,%d,%d'
dest='%d,%d,%d,%d' source='%d,%d,%d,%d'
source='%d,%d,%d,%d' dest='%d,%d,%d,%d'
M-d-d
WebBrowserUI
errorUrl
{D27CDB6E-AE6D-11CF-96B8-444553540000}
user32.dll
MSPDB110.DLL
ADVAPI32.DLL
/c ping 127.0.0.1 -n 2 > nul && del /s/q
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
%Program Files% (x86)\XTab\skin\
SupHPNot.exe
4,0,1,1716
SupHPNty.exe

YouTubeAcceleratorService.exe_2932:

.text
`.rdata
@.data
.text1
.adata
.data1
.pdata
.rsrc
uh9.tZ
otuh9.tZ
tZ9.tB
tV9.tB
l$$9.tZ
t9.tZ
uB9.tF
Windows CE
Windows 7
Windows Vista
Windows 2003 Server
Windows XP
Windows 2000
Windows NT
Windows Me
Windows 98
Windows 95
[CAcceleratorService::ExecuteServerAsWD] Exit
[CAcceleratorService::ExecuteServerAsWD] Impersonate Wakeup
\\.\pipe\GOOBZO_VAPIPESERVERENG
[CAcceleratorService::ExecuteServerAsWD] Enter
[CAcceleratorService::CreateEngineThread] Create thread result %d
[CAcceleratorService::CreateEngineThread] ___Error Creating the Engine Keep Alive event. error: %d
[CAcceleratorService::StopServiceExitMode] Name: %s
[CAcceleratorService::ProcessTimeoutEvent] ___Error wait for thread termination result %d
[CAcceleratorService::ProcessTimeoutEvent] ___Error StopThread result %d
[CAcceleratorService::ExecuteServer] Leave
[CAcceleratorService::ExecuteServer] Calling to ExecuteServerAsWD
[CAcceleratorService::ExecuteServer] ___Error creating the service named event. LE: %d
[CAcceleratorService::ExecuteServer] Enter
%d.%d.%d.%d
Name: %s
Path: %s
Version: %s
%s_%d.log
[CAcceleratorService::InstallDriver] Driver name: %s, Driver path: %s
[CAcceleratorService::UninstallDriver] Driver name: %s
[CAcceleratorService::InstallLsp] Module not found - LE: %d
[CAcceleratorService::InstallLsp] Function Install not found - LE: %d
[CAcceleratorService::InstallLsp] Module path: %s
[CAcceleratorService::UninstallLsp] Module not found - LE: %d
[CAcceleratorService::UninstallLsp] Function Remove not found - LE: %d
[CAcceleratorService::UninstallLsp] Module path: %s
[CAcceleratorService::RunCommand] Command: %d
[CLSPKeepAlive::GetLastLSPTestStatus] return %d
[CLSPKeepAlive::CheckOurLSPStatus]
[CLSPKeepAlive::Work] CheckOurLSPStatus - our LSP is installed!
[CLSPKeepAlive::Work] ___Error CheckOurLSPStatus - *** SBLSP NOT Installed ***
[CLSPKeepAlive::Work] ___Error creating the service named event. LE: %d
%sLow\%s\
%C:\Users\Public\Documents\%s\%s\
%s\%s\%s\
%s\Application Data\%s\%s\
[CDriverManager::CreateDriver] CreateService failed: %d
Tcpip
[CDriverManager::CreateDriver] Name: %s, Path: %s
[CDriverManager::Install] OpenSCManager failed: %d
[CDriverManager::Install] Name: %s, Path: %s
[CDriverManager::DeleteDriver] DeleteService failed: %d
[CDriverManager::DeleteDriver] OpenService failed: %d
[CDriverManager::DeleteDriver] Name: %s
[CDriverManager::UnInstall] OpenSCManager failed: %d
[CDriverManager::UnInstall] Name: %s
[CDriverManager::StartDriver] OpenService failed: %d
[CDriverManager::StartDriver] Name: %s
[CDriverManager::Load] OpenSCManager failed: %d
[CDriverManager::Load] Name: %s
[CDriverManager::StopDriver] OpenService failed: %d
[CDriverManager::StopDriver] Name: %s
[CDriverManager::UnLoad] OpenSCManager failed: %d
[CDriverManager::UnLoad] Name: %s
[CEventsThread::SetTimeoutResolution] From: %d -> To: %d
[CEventsThread::WaitForMultipleEvents] Released on Signaled: %d ms
[CEventsThread::WaitForMultipleEvents] Released on Timeout: %d ms
[CEventsThread::WaitForMultipleEvents] ___Error MsgWaitForMultipleObjectsEx. LE: %d
[CEventsThread::WaitForMultipleEvents] TID=%X
[CEventsThread::CreateNamedEvent] OpenEvent. LE: %d
[CEventsThread::CreateNamedEvent] ___Error OpenEvent: LE: %d
[CEventsThread::CreateNamedEvent] ___Error CreateEvent. LE: %d. Try OpenEvent...
[CEventsThread::Start - Leave] TID=%X
[CEventsThread::Start] ___Error - Failed to create thread: %X
[CEventsThread::Stop - Leave] TID=%X
[CEventsThread::Stop - Enter] TID=%X
[CEventsThread::CallProcessTimeoutRoutines] ___Error Invalid Event Entry: %d, Timeout: %d
[CEventsThread::AlertEvent] ___Error SetEvent failed: %d
[CEventsThread::AlertEvent] ___Error Invalid Event Entry: %d
[CEventsThread::AlertEvent] ___Error Not found Event: %d
[CEventsThread::SetGlobalEvent] ___Error Invalid Event Entry: %d
[CEventsThread::SetGlobalEvent] ___Error Not found Event: %d
[CEventsThread::SetGlobalEvent] Event: %d
[CEventsThread::ResetEvent] ___Error ResetEvent failed: %d
[CEventsThread::ResetEvent] ___Error Invalid Event Entry: %d
[CEventsThread::ResetEvent] ___Error Not found Event: %d
[CEventsThread::ResetEvent] Event: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Entry: %d
[CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Index: %d
[CEventsThread::RemoveEvent] ___Error CloseHandle failed: %d
[CEventsThread::RemoveEvent] ___Error Invalid Event Entry: %d
[CEventsThread::RemoveEvent] ___Error Not found Event: %d
[CEventsThread::RemoveEvent] Event: %d
[CEventsThread::Cleanup] ___Error CloseHandle(0x%p) failed: %d
[CEventsThread::Cleanup] Closing Handle: %d
[CEventsThread::WaitEvent] TID=%X
[CEventsThread::Work] TID=%X - Exit !!!
[CEventsThread::Work] WAIT_ABANDONED - %d
[CEventsThread::Work] TID=%X
[CEventsThread::AddEvent] ___Warning event handle already exists %d
[CEventsThread::AddEvent] ___Error invalid event handle %d
[CImpersonate::Impersonate] ImpersonateLoggedOnUser - Error: %d
[CImpersonate::Impersonate] Impersonated: %d
[CImpersonate::Revert] RevertToSelf - Error: %d
[CImpersonate::Revert] Impersonated: %d
[CImpersonate::Cleanup] Impersonated: %d
[CImpersonate::GetUserSID] LookupAccountNameW failed. GetLastError returned: %d
[CImpersonate::GetUserSID] The SID for %s is invalid.
[CImpersonate::GetUserSID] Not Enough Memory: %d
[CImpersonate::SetPrivilege] AdjustTokenPrivileges - Error: %d
[CImpersonate::SetPrivilege] LookupPrivilegeValue - Error: %d
[CImpersonate::OpenCurrentUserDesktop] - The function does not support Windows Vista and Windows 98
[CImpersonate::OpenCurrentUserDesktop] OpenDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenInputDesktop - Error: %d
[CImpersonate::OpenCurrentUserDesktop] SetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] OpenWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] GetProcessWindowStation - Error: %d
[CImpersonate::OpenCurrentUserDesktop] - The function does not support MAC
[CImpersonate::CreateProcessAsCurrentUser] CreateProcessAsUser - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] CreateEnvironmentBlock - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] AddAceToWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetLogonSID - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] DuplicateTokenEx - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenDesktop - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] SetProcessWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] OpenWindowStation - Error: %d
[CImpersonate::CreateProcessAsCurrentUser] GetProcessWindowStation - Error: %d
[CImpersonate::AddAceToWindowStation] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToWindowStation] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToWindowStation] CopySid - Error: %d
[CImpersonate::AddAceToWindowStation] AddAce - Error: %d
[CImpersonate::AddAceToWindowStation] GetAce - Error: %d
[CImpersonate::AddAceToWindowStation] GetAclInformation - Error: %d
[CImpersonate::AddAceToWindowStation] GetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] SetUserObjectSecurity - Error: %d
[CImpersonate::AddAceToDesktop] SetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] AddAccessAllowedAce - Error: %d
[CImpersonate::AddAceToDesktop] AddAce - Error: %d
[CImpersonate::AddAceToDesktop] GetAce - Error: %d
[CImpersonate::AddAceToDesktop] GetSecurityDescriptorDacl - Error: %d
[CImpersonate::AddAceToDesktop] GetUserObjectSecurity - Error: %d
[CImpersonate::OpenCurrentUserKey] LoadUserProfile - SUCCESS
[CImpersonate::OpenCurrentUserKey] LoadUserProfile failed - Error: %d
[CImpersonate::GetLogonUserName] GetLogonUserName - Error: %d
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - Error: %d
[CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - SUCCESS
[CImpersonate::OpenCurrentUserKey] Impersonated: %d
[CImpersonate::FindLoggedOnUser] Process32First - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcess - Error: %d
[CImpersonate::FindLoggedOnUser] OpenProcessToken - Error: %d
[CImpersonate::FindLoggedOnUser] CreateToolhelp32Snapshot failed - Error: %d
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
explorer.exe
[CImpersonate::FindLoggedOnUser] Impersonated: %d
[CImpersonate::GetLogonUserName] Name: %s
[CImpersonate::GetLogonUserName] GetUserName - Error: %d
[CImpersonateThread::NotifyImpersonateLogon] Time: %d
[CImpersonateThread::NotifyImpersonateLogoff] Time: %d
[CImpersonateThread::ProcessEvent] CreateProcess - CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::CreateProcess] CmdLine: %s, AppName: %s, ShowCmd: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(TRUE), LE: %d
[CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(FALSE) failed: %d
engine.dll
DestroyPipeEventThreadManager
CreatePipeEventThreadManager
ipc.dll
xmldb.dll
config.xml
<d/d/%d d:d:d::d 0x%X>
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegNotifyChangeKeyValue
[SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegOpenKeyEx
[SbTracer::RecursiveCreateDirectory] Directory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - CreateDirectory: %s
[SbTracer::RecursiveCreateDirectory] ___Error - Directory: %s
[SbTracer::ReadConfiguration] Trace Max Size: %d
[SbTracer::ReadConfiguration] Trace Time Stamp: %d
[SbTracer::ReadConfiguration] Trace Time Limit: %d
[SbTracer::ReadConfiguration] Trace Backup: %d
[SbTracer::ReadConfiguration] Trace Destination: %d
[SbTracer::ReadConfiguration] Trace Level: %d
[SbTracer::FormatFilePath] Log Path: %s
[SbTracer::FormatFilePath] ___Error - RecursiveCreateDirectory: %s
[SbTracer::FormatFilePath] ___Warning - No Log folder: %s
[SbTracer::FormatFilePath] ___Error - GetModuleFileName: %s
\StringFileInfo\x\%s
[SbTracer::BackupTraceFile] %s
[SbTracer::OpenTraceFile] Done %s
[SbTracer::OpenTraceFile] ___Error: %d, File: %s
[SbTracer::WriteTraceLine] !!! OVERFLOW or FORMAT ERROR !!! - (%d) %s
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] SetSecurityDescriptorDacl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeSecurityDescriptor failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the trusted owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the Everyone group. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the queue owner. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeAcl failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetLogonSID failed. Error code: 0x%X
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AllocateAndInitializeSid failed. GetLastError returned: %d
[CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetTokenInformation failed. GetLastError returned: %d
[CServiceController::ChangeStartType] ___Error ChangeServiceConfig failed: %d
[CServiceController::ChangeStartType] ___Error OpenService: %s, failed: %d
[CServiceController::ChangeStartType] ___Error OpenSCManager failed: %d
[CServiceController::ChangeStartType] Name: %s
[CServiceController::ExecuteServer] Exit
[CServiceController::ExecuteServer] Enter
[CServiceController::ServiceMain] ___Error SetServiceStatus Failed: %d
[CServiceController::ServiceMain] ___Error RegisterServiceCtrlHandler Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error Exception StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] ___Error StartServiceCtrlDispatcher Failed: %d
[CServiceController::UpdateServiceDespatchTable] Enter, %s
[CServiceController::Remove] ___Error OpenService Failed: %d
[CServiceController::Remove] ___Error OpenSCManager Failed: %d
[CServiceController::GetStatus] ___Error QueryServiceStatus Failed: %d
[CServiceController::GetStatus] ___Error OpenService Failed: %d
[CServiceController::GetStatus] ___Error OpenSCManager Failed: %d
[CServiceController::Start] The service %s was started
[CServiceController::Start] ___Error StartService Failed: %d
[CServiceController::Start] ___Error OpenService Failed: %d
[CServiceController::Start] ___Error OpenSCManager Failed: %d
[CServiceController::Start] Going to start the service %s
[CServiceController::Stop] The service %s was stopped
YoutubeAcceleratorService.exe
[CServiceController::Stop] ___Error ControlService Failed: %d
[CServiceController::Stop] ___Error OpenService Failed: %d
[CServiceController::Stop] Going to stop the service %s
[CServiceController::Stop] ___Error SetServiceStatus Failed: %d
[CServiceController::Install] ___Error OpenService Failed: %d
[CServiceController::Install] ___Error QueryServiceStatus Failed: %d
[CServiceController::Install] ___Error CreateService Failed: %d
[CServiceController::Install] ___Error OpenSCManager Failed: %d
%s -%s -%s
%s\%s
[CServiceController::Install] ___Error GetModuleFileName Failed: %d
[CServiceController::GetArgsFromCmd] Exit
[CServiceController::GetArgsFromCmd] m_bSCMCmd = TRUE
[CServiceController::GetArgsFromCmd] Enter
[CServiceController::RunCommand] Args: %s
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
operator
GetProcessWindowStation
USER32.DLL
c:\BUILDS\Build_YTA\Client\VA_3_2\Bin\Release\YouTubeAcceleratorService.pdb
KERNEL32.dll
USER32.dll
ADVAPI32.dll
SHELL32.dll
VERSION.dll
USERENV.dll
PSAPI.DLL
.?AVIPipeEventsThread@@
.?AVCPipeEventThread@@
.?AV?$IMultiBaseInterface@VIPipeEventThreadManagerFactory@@@@
.?AVIPipeEventThreadManagerFactory@@
.?AV?$CMultiBaseInterface@VCPipeEventThreadManagerFactory@@VIPipeEventThreadManagerFactory@@@@
.?AVCPipeEventThreadManagerFactory@@
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe
aSSSh
FTPjK
FtPj;
C.PjRV
]@ ]( ]8
tGHt.Ht&
FTPQ
.?AVunsupported_thread_option@boost@@
zcÁ
SetProcessShutdownParameters
kernel32.dll
COMCTL32.DLL
boost::too_few_args: format-string referred to more arguments than were passed
boost::too_many_args: format-string referred to less arguments than were passed
Required USB Key not found
Failed to execute target process
Cannot find import; DLL may be missing, corrupt, or wrong version
File "%s", function "%s"
File "%s", ordinal %d
File "%s", error %d
(Error code %d)
%X:DAF
(Location XEB, error code %d)
_PAD%d
RNX
%X::DAX
KERNEL32.DLL
.DbgLog
GetWindowsDirectoryW
CreateDialogIndirectParamW
Kernel32.dll
User32.dll
ComDlg32.dll
1.2.3
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_DENORMAL_OPERAND
boost::unsupported_thread_option
mscoree.dll
Visual C   CRT: Not enough memory to complete call to strerror.
.mixcrt
ADVAPI32.DLL
portuguese-brazilian
Broken pipe
Inappropriate I/O control operation
Operation not permitted
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService-2.DbgLog
GetWindowsDirectoryA
EnumThreadWindows
EnumWindows
CreateDialogIndirectParamA
GetAsyncKeyState
GDI32.dll
comdlg32.dll
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
^.Ad/
.Zvv[
j%FwL
e.tu/
5%up/
A.YNpN\n
%Um-IF
.BV$L|
%X1:S
`?T%Sj
%x@k4
.iyDY
j.Wsf
Cr.BxL
V.Fb7|
$"bM-Q}n
%x R\X
4%sPp
_%S3@
.LvHT
.owm;y,
}R.zmA
.bi@{
>I|.pt|d
t_\A
p}.GF
G){.mf
.xh$x
U.gs!
J|0.tL
.iJp`
.zE:aG
.7%Xs
-DED%xFqz
%cnzb
%UQzss
1%.Ey\=
/\%Dg
.FlC\5
.cA~;
P?=I_.or\
E.yb|4
%SuSw
T.UHuR
LZÁ
Q,-I}g_
4.gtE
-;M.EZk
1:](P%X
g.RUg
fH.XFH
.cP;_
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
OUTUB~1\YouTubeAcceleratorService.exe
3.3.9.5

YouTubeAccelerator.exe_684:

.text
`.rdata
@.data
.text1
.adata
.data1
.pdata
.rsrc
uh9.tZ
otuh9.tZ
tZ9.tB
tV9.tB
l$$9.tZ


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    WerFault.exe:3548
    WerFault.exe:2924
    WerFault.exe:2488
    Npjwb.exe:4764
    YTAHelper.exe:2072
    GLB4191.tmp:2908
    ProtectWindowsManager.exe:3696
    ProtectWindowsManager.exe:3648
    GLJ41D1.tmp:3252
    YouTubeAcceleratorService.exe:1348
    YouTubeAcceleratorService.exe:1664
    YouTubeAcceleratorService.exe:3648
    ctmpua.exe:2288
    ctmpua.exe:3432
    ctmpua.exe:4816
    ProtectService.exe:3944
    ProtectService.exe:3960
    XTab_Setup2121.exe:3784
    jsdrv.exe:200
    1F52.tmp:3644
    wpm_v20.0.0.1953_0302.exe:3616
    biclient.exe:2936
    biclient.exe:1760
    biclient.exe:3896
    b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe:4108
    ins_yta.exe:1244
    QQBrowser.exe:604
    QQBrowser.exe:3556
    DesktopMessenger.exe:3944
    testlsp.exe:4468
    powershell.exe:2340
    powershell.exe:3496
    powershell.exe:4512
    powershell.exe:1684
    powershell.exe:2388
    powershell.exe:2708
    setup.exe:3664
    setup.exe:1756
    HPNotify.exe:2060
    cmdshell.exe:4028
    ShopperPro.exe:4088
    Ussgbdqdxxc.exe:4744
    125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe:5092
    smt_istartsurf.exe:1836
    ins_shopperpro.exe:3416
    %original file name%.exe:2636
    regsvr32.exe:2428
    regsvr32.exe:3248
    regsvr32.exe:3604
    regsvr32.exe:3144
    regsvr32.exe:1116
    regsvr32.exe:1868
    lspinst.exe:4328
    lspinst.exe:3788
    YTAHEL~1.EXE:796
    DCytaiesmt_smtyc_setup.exe:3580
    DCytaiesmt_smtyc_setup.exe:4188
    DCytaiesmt_smtyc_setup.exe:3856
    DCytaiesmt_smtyc_setup.exe:3976
    DCytaiesmt_smtyc_setup.exe:3084
    DCytaiesmt_smtyc_setup.exe:4260
    spbiu.exe:3144
    spbiu.exe:2612
    wscript.exe:2072
    6650.tmp:3864
    INS_SENSE.EXE:4724
    taskeng.exe:1420
    ytaiesmt_smtyc_setup.exe:3588
    INS_IWEBAR.EXE:4644

  2. Delete the original Application file.
  3. Delete or disinfect the following files created/modified by the Application:

    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0dd4f150\Report.wer (239494 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_0b6b27ab\Report.wer (239478 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_biclient.exe_97ca2157dc4a9efbd1a44fda2aa67c3f797d_09b1efab\Report.wer (241156 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\5774 (3589 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\hmwmphigb.dll (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA795.tmp (595233 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\b31cdfed-0f00-400c-94a9-14f605306e7a-4.dll (38103 bytes)
    %Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-4.exe (9147 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (5 bytes)
    %Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a-5.exe (7433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\kvwinpd.dll (3730 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\gzxaaspvo.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\365718 (92733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\emfom.dll (23 bytes)
    %Program Files% (x86)\SensePlus\utils.exe (63821 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\wuogor.dll (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\lutouoko.dll (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\System.dll (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\eaxnwm.dll (13 bytes)
    %Program Files% (x86)\SensePlus\Uninstall.exe (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA7A6.tmp\bakxdyd.dll (31241 bytes)
    C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5_user.job (74 bytes)
    %Program Files% (x86)\SensePlus\b31cdfed-0f00-400c-94a9-14f605306e7a.xpi (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\ipgeoapi_com[1].json (40 bytes)
    C:\Windows\Tasks\b31cdfed-0f00-400c-94a9-14f605306e7a-5.job (74 bytes)
    C:\ProgramData\YTAHelper\config.json (269 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\overlay.xul (203 bytes)
    C:\ProgramData\YTAHelper\yta_database1_0_0.json (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (514 bytes)
    %Program Files% (x86)\YTAHelper\config.json (269 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\install.rdf (884 bytes)
    C:\ProgramData\YTAHelper\YTAHelper.dll (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\config.json (269 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\chrome.manifest (111 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\shopperpro_128.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\yta_database1_0_0.json (2 bytes)
    C:\ProgramData\YTAHelper\YTAHelper64.dll (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E}\content\YTAHelper_64.png (4 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000e.TMP (11493 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH001a.TMP (13284 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\blank.html (75 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000d.TMP (7861 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\YouTube Accelerator.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0006.TMP (115350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\updater.exe (14357 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAENG.LNG (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAuninstall.mht (9 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0011.TMP (34 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH001f.TMP (2461 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAIDN.LNG (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPOL.LNG (1166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAROM.LNG (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\sporder.Dll (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0001.TMP (2104 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\testlsp.exe (19739 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHelperSetup.exe (27818 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0004.TMP (16 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0009.TMP (2104 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\xmldb.dll (3048 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0016.TMP (6341 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0003.TMP (119 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0010.TMP (610 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\OK.gif (329 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
    %Program Files% (x86)\YouTube Accelerator\cabex.dll (98 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000c.TMP (941 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLG49E0.tmp (93076 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAPTB.LNG (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0002.TMP (2104 bytes)
    %Program Files% (x86)\YouTube Accelerator\temp.000 (51331 bytes)
    %Program Files% (x86)\YouTube Accelerator\res\~GLH0014.TMP (75 bytes)
    %Program Files% (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe (49 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VASRB.LNG (1184 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst2.exe (30222 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAESM.LNG (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytalsp.dll (3271 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000a.TMP (18940 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFRA.LNG (402 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ipc.dll (6691 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000f.TMP (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VANLD.LNG (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0007.TMP (1568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFIL.LNG (351 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\lspinst.exe (20746 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\engine.dll (34861 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Res.dll (7687 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLC41C0.tmp (3791 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLK43D5.tmp (1604 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YTAHUninstall.exe (3528 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe (20848 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLF49E1.tmp (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAJPN.LNG (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0005.TMP (65 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VADEU.LNG (18 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0012.TMP (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\helper.dll (4155 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page2.mht (1961 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH0015.TMP (4061 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~GLH0000.TMP (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\AniGIF.ocx (3175 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\varemove_page1.mht (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\Cancel.gif (610 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\unelevate.exe (2082 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cabex.dll (98 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAITA.LNG (1660 bytes)
    %Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe (146 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLJ41D1.tmp (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VATRK.LNG (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLM45D8.tmp (12 bytes)
    C:\Windows\SysWOW64\temp.000 (3624 bytes)
    %Program Files% (x86)\YouTube Accelerator\~GLH000b.TMP (11493 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\~GLH0021.TMP (65 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\comtest.gif (1817 bytes)
    %Program Files% (x86)\YouTube Accelerator\INSTALL.LOG (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LocalesU\VAFAR.LNG (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\progbar.gif (238 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\~GLH0020.TMP (1568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SAINST\ytauninstall.exe (10592 bytes)
    C:\ProgramData\WindowsMangerProtect\update\conf (5 bytes)
    C:\Windows\SysWOW64\AniGIF.ocx (172 bytes)
    %Program Files% (x86)\YouTube Accelerator\engine.dll (146 bytes)
    %Program Files% (x86)\YouTube Accelerator\ipc.dll (286 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\config.xml (60 bytes)
    %Program Files% (x86)\YouTube Accelerator\xmldb.dll (192 bytes)
    C:\Windows\Temp\SBCC0F0.tmp (98 bytes)
    C:\Windows\Temp\SBCE919.tmp (44 bytes)
    C:\Windows\Temp\SBCFD94.tmp (51193 bytes)
    C:\Windows\Temp\SBC72CE.tmp (98 bytes)
    %Program Files% (x86)\YouTube Accelerator\helper.dll (200 bytes)
    C:\Windows\Temp\SBC14AD.tmp (547 bytes)
    C:\Windows\Temp\SBCBBC1.tmp (44 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log (591 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log (261752 bytes)
    C:\ProgramData\TEMP:56E2E879 (240 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[4].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[3].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[3].gif (35 bytes)
    %Program Files% (x86)\XTab\msvcp110.dll (536 bytes)
    %Program Files% (x86)\XTab\msvcr110.dll (876 bytes)
    C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
    %Program Files% (x86)\XTab\CmdShell.exe (49 bytes)
    %Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
    %Program Files% (x86)\XTab\skin\btn.png (2 bytes)
    %Program Files% (x86)\XTab\install.data (68 bytes)
    %Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
    %Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
    %Program Files% (x86)\XTab\HPNotify.exe (17941 bytes)
    %Program Files% (x86)\XTab\conf (1594 bytes)
    %Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
    %Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
    %Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
    %Program Files% (x86)\XTab\web\indexIE8.html (1794 bytes)
    %Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
    %Program Files% (x86)\XTab\web\ver.txt (47 bytes)
    %Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
    %Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
    %Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
    %Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
    %Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
    %Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
    %Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
    %Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
    %Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
    %Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
    %Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
    %Program Files% (x86)\XTab\web\js\xagainit-ie8.js (4 bytes)
    %Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
    %Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
    %Program Files% (x86)\XTab\skin\main.xml (4 bytes)
    %Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
    %Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
    %Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
    %Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
    %Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
    %Program Files% (x86)\XTab\ProtectService.exe (5468 bytes)
    %Program Files% (x86)\XTab\web\js\js.js (18 bytes)
    %Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1028.xpi (15 bytes)
    %Program Files% (x86)\XTab\skin\logo.png (5 bytes)
    %Program Files% (x86)\XTab\web\js\xagainit2.0.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn143C.tmp\System.dll (23 bytes)
    %Program Files% (x86)\XTab\web\main.css (19 bytes)
    %Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
    %Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
    %Program Files% (x86)\XTab\skin\close.png (3 bytes)
    %Program Files% (x86)\XTab\web\data.html (20 bytes)
    %Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
    %Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
    %Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
    %Program Files% (x86)\XTab\skin\about.png (4 bytes)
    %Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
    %Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
    %Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
    %Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
    %Program Files% (x86)\XTab\skin\settings.png (5 bytes)
    %Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
    %Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
    %Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
    %Program Files% (x86)\XTab\web\js\common.js (2 bytes)
    %Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
    %Program Files% (x86)\XTab\SupTab.dll (15946 bytes)
    %Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
    %Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
    %Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
    %Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
    %Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
    %Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.bak_tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\SMALLTEST[1].htm (70 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9171.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_684.log_tmp (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9148.tmp (682 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4468_testlsp.log_tmp (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90D6.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk901F.tmp (242 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\helper_4468_testlsp.log_tmp (300 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90A0.tmp (50 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916D.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90C5.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_4260_DCytaiesmt_smtyc_setup.log_tmp (3 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (408785 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9136.tmp (242 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B1.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\ipc_4468_testlsp.log_tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk907E.tmp (682 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk90B3.tmp (1 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\testlsp_4468.log_tmp (758 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\engine_2932_YouTubeAcceleratorService.log_tmp (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk9159.tmp (50 bytes)
    C:\Users\Public\Documents\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2932.log_tmp (493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk915B.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\wbk916F.tmp (1 bytes)
    C:\Users\Public\Documents\ShopperPro\JsDriver\Config.xml (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\WmiInspector.dll (3137 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsJSON.dll (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\nsExec.dll (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\lm (128 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\UserInfo.dll (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\mj (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\NSISEncrypt.dll (3342 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\IpConfig.dll (4254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Swift Record\tlg (41 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\System.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd1FD0.tmp\inetc.dll (44 bytes)
    C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (3568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IZSMH2G7.txt (286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\vlc_48[1].png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp (34243 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A0GU0ZSM.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[1].png (1276 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe (195820 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\C7DICHCP.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0BISIEEE.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ga[1].js (25835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.3 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.2 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.1 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.0 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.7 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9GM47V2A.txt (116 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.5 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[1].jpg (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[1].htm (4339 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-istartsurf[1].htm (1054 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.6 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\eula-youtubeaccelerator[1].htm (2713 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\247cff67b7ccf545bc359dea5d4fdcca[1].htm (35176 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XBFPV72L.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe (1482965 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_istartsurf.exe (43024 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe (71240 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.exe.4 (23608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VWCSVYJT.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Z4XAPYNG.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CAECMN2Q.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.6 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.7 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.4 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.5 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.2 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.3 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.0 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vlc-2.0.2-win32.exe.1 (173869 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.4 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.5 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.6 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.7 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.0 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.1 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.2 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E252.tmp.3 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.2 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.3 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.0 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.1 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VSU9UM32.txt (548 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.7 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.4 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.5 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe.6 (10864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9WGP90AI.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L7G4BE9A.txt (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[1].htm (1059 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Y2YQ0ZN9.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.7 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.4 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.5 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.2 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.3 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.0 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.1 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BFIYZCSM.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyo_sprite_full[1].png (1276 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp (34243 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\40da6fd4d86af64fa44c08b317ad86e7[1].htm (36028 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UpdateCheckerSetup.exe.6 (1928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.3 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.2 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.1 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.0 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.7 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.6 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.5 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\E3E8.tmp.4 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8IZK4DIW.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XRSM1SYU.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[5].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\tokyoLightGrayStripesBG[1].jpg (439 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0ZXSMBUT.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\G4EMRU6A.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[3].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2YAKCMQE.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp (34243 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\11H1CVWK.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F8VDJPMY.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[3].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MCEUOC87.txt (777 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.3 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.2 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.1 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.0 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.7 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.6 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.5 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6650.tmp.4 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ARAVBC6Q.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XT3O6SY5.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\__utm[2].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\5ee27ba0e055bb4684b8648858d31d9a[1].htm (34716 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FFA3HBHT.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\BDVF95Q7.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3KR1O1W4.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[2].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\N3J3D9ZZ.txt (325 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\tokyoLightGrayStripesBG[2].jpg (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IWHOVB19.txt (777 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\__utm[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.4 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.5 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.6 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.7 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.0 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.1 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.2 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1F52.tmp.3 (4152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\tokyo_sprite_full[2].png (1277 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\8b685dcf684f214ea8b00dc2c916e842[1].htm (34823 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TE7T15RC.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FNHOZK1G.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UEDY9YTQ.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\32X7O7GH.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Q8XWSLCR.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\YK3867F1.txt (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\eula[1].htm (1058 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0982L053.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8SWC09PC.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\eula-youtubeaccelerator[1].htm (2713 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\__utm[2].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula[2].htm (1061 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\TZJ60FG3.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROWYV75Q\eula-swiftrecord[2].htm (4391 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\1K9S4IKF.txt (613 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2I762JJ4.txt (777 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LEX2PBNZ.txt (775 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L4B69UQE.txt (129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (663 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\334.js (973 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\dd664ae6f5b9fff9189830efc4277c1f.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e8bf7602a41c0cdd14ad3540f08069cf.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\d0ac5e3ab61d9c9d036ca53d47b29da9.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\cf410972f8f7d9ce4b77ee942f1466ad.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\e0aa67c698a956adcab1a009989465d9.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\a212c1cc5036af14d61114d057025057.js (947 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d7a9ef674b92bd799ec4bb2c4ad621ef.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\9c5116558c43d87c3a32571c768872c8.js (28 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\be649c4e3a3e93d8a40243a4b8fc8344.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b7b54f267e564c72cde2760d1dbd8ba2.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e5f493e4f10da2ac3e336eaebbe86097.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\b4bb02edd36de53e69ba6b93fbbaf546.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (506 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d3f76309e3ba67b37724cd13c2a877ab.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\0177f7adb3a7120281e3dc4ad27672bd.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\192.js (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\7bded2a2506031aee5561ee8095bfcda.js (357 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\cd42e843c315396a255ec90674730514.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\337.js (413 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (969 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\281.js (461 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\f533812f59e22810ff3bc56548ce46a5.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\527d5f3becaec0408e1ef15ac8f13bb8.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\491bb26de8d74c88f4ef82985489e2a7.js (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\f15d508ac04f84271fdf78b6cd665aeb.js (134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\390.js (829 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\162678864fe0dce10da8913dbd7ae511.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (682 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ef5f49cce70bb46b02b28579a3bd464b.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\3d33016b291b0f7bcfe763a02760e8c7.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (949 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a4216ae64b11870b51e4b6ddf906205d.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\399.js (525 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\fc95591e3359f30c3025d78dffef3f08.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\23ee7c2ff74dde91e4fef185b27fc94c.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\1d8df16ea3f4be636f5817d37d006df5.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (617 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\193.js (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\391.js (801 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\57897893dc3d4deec228a28f1d8f10b2.js (964 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\376.js (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e38361e1c88892cbd641c1625e826699.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0d3c7da494fcbab7f37c0e38eed8654c.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d599fcb25ec9c785d2c1d66a72962be4.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\83bbdd4a0fff63d909d0a0d0e0e6bd38.js (26 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\0f728b47f95c6ce7ef2de6868fd3ac67.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\3c15b1a00edb4ad7a7b6ea0c2f029e60.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\356.js (413 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b23a8e0fe71c1dea24c69cf3bfa392b4.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\c0f52d7d6baeb5125934e7f4ae3aaaff.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\7fb62ef1207bd6500db94456a32fafff.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\34b8f82350c85955993d9f02d0941792.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b33ac672edd3e152a7f18f3bbccca9ef.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\a6bfe546fc476bf6efa27bce866a3a5f.js (618 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a3dd82821479da5accbcad4543805ae5.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\447b6d228c0833ca1c3560e0acb7ff93.js (659 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GLB4191.tmp (144 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\fvd.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\misc.js (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code1.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\last_tab.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code2.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\google_trends.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\it\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\474.json (512 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox_select.png (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\MessageBox.xml (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code5.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg1.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bk_shadow.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\addonmanager.js (531 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\newtab.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_bg.png (159 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\scrollbar.bmp (37 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code4.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code3.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\misc.js (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\button.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\es-419\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\code6.jpg (5 bytes)
    C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\loading.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\search.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\style.css (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\min.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5D5.tmp (110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\googlelogo.png (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\install.rdf (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.xul (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\close.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\js.js (660 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\logo.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\uninstallDlg2.xml (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\default_logo.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\icon.png (628 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checked.png (222 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\settings.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\common.js (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en-US\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\checkbox.png (545 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\aes.js (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\en\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\index.html (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\bg.png (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\defaults\preferences\preferences.js (379 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\loading_light.png (139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowserFrame.dll (110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\skin\simple.css (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\pack\ga.js (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\module\stat.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\unchecked.png (135 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome.manifest (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\properties.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\remoterequest.js (2 bytes)
    C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\UninstallManager.exe (14022 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\modules\restoreprefs.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\code\Thumbs.db (42 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\speed_dial.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
    %Program Files% (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml (553 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\tr\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\quick_start.js (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\istartsurf\images\Thumbs.db (27 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\D5C5.tmp (110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\pl\locale.properties (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1429596649_xpi\chrome\locale\vi\locale.properties (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\474.db (155 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\wpm_v20.0.0.1953_0302.exe (988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\tmp\XTab_Setup2121.exe (148 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (40 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\ctmpua.exe (49 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\__utm[2].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1GTL8DZTBO258N0GHLR0.temp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7O3W63F2E3I22BLN6TOW.temp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D34R02L3N7OKWC8P2R3J.temp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XZNWAHWP4KMSA08GUC3P.temp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZG7QQZ7AW1JD8CDIB6CZ.temp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L0DHHN7AY5J5O0FAV13K.temp (196 bytes)
    %Program Files%\Common Files\ShopperPro\spbii64.exe (17848 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\MoreInfo.dll (15 bytes)
    %Program Files%\Common Files\ShopperPro\spbia.exe (11344 bytes)
    %Program Files% (x86)\ShopperPro\ShopperPro.exe (33633 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\AccDownload.dll (11659 bytes)
    %Program Files%\Common Files\ShopperPro\spbiw.sys (1552 bytes)
    %Program Files%\Common Files\ShopperPro\spbii32.exe (13368 bytes)
    %Program Files% (x86)\ShopperPro\Updater.exe (25112 bytes)
    %Program Files%\Common Files\ShopperPro\spbiu.exe (69777 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\jsdrv.exe (100669 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn697C.tmp (360871 bytes)
    %Program Files% (x86)\ShopperPro\FireFox\chrome.manifest (113 bytes)
    %Program Files% (x86)\ShopperPro\FireFox\content\overlay.xul (203 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\System.dll (23 bytes)
    %Program Files%\Common Files\ShopperPro\spbici32.dll (37025 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsProcess.dll (12 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\jsdrv.sys (1856 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\jsdrv.exe (100378 bytes)
    %Program Files% (x86)\ShopperPro\FireFox\content\overlay.js (13 bytes)
    %Program Files% (x86)\ShopperPro\ShopperPro.dll (15168 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd698D.tmp\nsExec.dll (14 bytes)
    %Program Files% (x86)\ShopperPro\FireFox\install.rdf (828 bytes)
    %Program Files%\Common Files\ShopperPro\spbici64.dll (48241 bytes)
    %Program Files% (x86)\ShopperPro\database1_0_0.json (11 bytes)
    %Program Files% (x86)\ShopperPro\SPRemove.exe (20416 bytes)
    %Program Files% (x86)\ShopperPro\ShopperPro64.dll (18424 bytes)
    %Program Files% (x86)\ShopperPro\database1_0_0.ej (14 bytes)
    %Program Files% (x86)\ShopperPro\manifest.json (595 bytes)
    %Program Files% (x86)\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_60.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_65.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c5.png (744 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a5.png (693 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f349.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2935.png (454 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f648.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f429.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f637.png (903 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-active.png (498 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f682.png (976 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a3.png (631 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_72.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_62.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23eb.png (366 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f699.png (691 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute.png (445 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f453.png (867 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68e.png (711 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f1.png (326 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\uninstall.exe (877 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f472.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f645.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2601.png (626 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23e9.png (395 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44c.png (812 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f518.png (732 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f237.png (447 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40d.png (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23-20e3.png (559 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b9.png (720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f476.png (836 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings.html (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f501.png (572 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f608.png (843 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f511.png (550 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a3.png (750 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2139.png (347 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f301.png (756 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26bd.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe (21399 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40b.png (910 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f521.png (741 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus-active.png (149 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68b.png (681 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a7.png (849 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f308.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f406.png (683 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ac.png (524 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ec.png (773 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cb.png (395 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50a.png (708 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264d.png (597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\30-20e3.png (547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25c0.png (320 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\LICENSE-GRAPHICS (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_02.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a0.png (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a9.png (392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_20.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f506.png (567 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_49.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7.png (487 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4af.png (920 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f196.png (678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f564.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f631.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_78.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\settings_test.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f485.png (602 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fc.png (740 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53b.png (343 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ba.png (517 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-mute-none-blue.png (755 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f602.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f539.png (308 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f380.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f558.png (704 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31b.png (826 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55b.png (835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f416.png (569 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21a9.png (476 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2734.png (591 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\send_message.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_44.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264b.png (701 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_56.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fe.png (472 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f6.png (242 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f335.png (610 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274e.png (442 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2665.png (530 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f0.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\21aa.png (483 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f364.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_55.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fb.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2648.png (652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f400.png (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\message_test.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f561.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f303.png (548 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f425.png (831 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f694.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d3.png (590 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2716.png (443 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f459.png (978 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f508.png (293 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2615.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60f.png (728 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c3.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fb.png (199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f467.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f427.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60c.png (733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f487.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52e.png (633 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44e.png (830 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f305.png (905 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40a.png (736 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f341.png (634 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f615.png (623 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2194.png (422 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f373.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31d.png (878 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f5.png (418 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f194.png (506 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f629.png (973 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a8.png (583 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f497.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f310.png (684 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f626.png (625 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2049.png (516 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f408.png (849 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f343.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\260e.png (963 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b4.png (974 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c1.png (475 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f451.png (740 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b50.png (552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61b.png (848 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f523.png (778 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f647.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f517.png (723 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_57.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3f0.png (511 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4be.png (359 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb-1f1f7.png (245 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f236.png (497 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_11.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f316.png (981 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_73.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a9.png (835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b6.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\35-20e3.png (519 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f352.png (792 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\libs.js (4316 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c5.png (476 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49c.png (563 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69f.png (567 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f525.png (991 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f414.png (935 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f613.png (845 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f515.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c9.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64d.png (802 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-active.png (410 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c9.png (699 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_71.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f693.png (743 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2796.png (184 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2753.png (480 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63c.png (973 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f442.png (928 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69d.png (662 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f371.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f620.png (715 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e4.png (495 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f004.png (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f498.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f376.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62f.png (759 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f684.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f493.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_38.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2693.png (628 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\default_photo.jpg (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a4.png (390 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a2.png (767 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68f.png (363 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49d.png (927 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit-active.png (444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f457.png (845 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b3.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31f.png (900 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_59.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f407.png (908 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ab.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_48.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f624.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45c.png (897 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f423.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f509.png (440 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a6.png (671 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f354.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f384.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f567.png (629 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f7-1f1fa.png (238 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b1.png (947 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f649.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fc.png (659 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ac.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45e.png (639 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ed.png (420 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60a.png (839 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f379.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f606.png (934 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4de.png (583 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b6.png (446 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f535.png (429 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25aa.png (138 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5ff.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\24c2.png (924 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f402.png (617 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52b.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a2.png (792 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f553.png (806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f234.png (526 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_25.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2795.png (248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3eb.png (541 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f504.png (643 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_37.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e6.png (578 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48d.png (690 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f5.png (652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_47.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36b.png (938 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a9.png (897 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c4.png (345 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f696.png (986 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50c.png (534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f2.png (398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f340.png (739 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_26.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f500.png (542 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f21a.png (596 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fd.png (172 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f455.png (716 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34f.png (802 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f348.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2195.png (416 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f519.png (730 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f304.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25b6.png (320 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f356.png (916 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_28.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f2.png (709 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c3.png (449 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27bf.png (725 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\263a.png (870 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\36-20e3.png (532 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f412.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61f.png (736 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f639.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f690.png (774 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ba.png (789 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f681.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f198.png (729 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f382.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_14.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2708.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ea.png (665 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62a.png (997 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52f.png (820 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55a.png (889 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f446.png (504 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33b.png (892 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e9.png (718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\gcadapter.dll (8406 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e0.png (358 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f410.png (897 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_77.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f495.png (624 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f435.png (997 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47b.png (877 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b8.png (718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\261d.png (585 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\settings.js (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_69.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b4.png (432 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55c.png (863 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2714.png (347 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f502.png (625 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c7.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61d.png (969 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f622.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ae.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51b.png (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2649.png (565 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ea.png (632 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a1.png (525 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f390.png (690 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c5.png (769 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42a.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f625.png (957 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\main.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_30.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f560.png (782 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53a.png (350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ca.png (414 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e8.png (325 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_41.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6aa.png (470 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\203c.png (210 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_13.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51d.png (651 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31a.png (887 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-out.png (720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea-1f1f8.png (372 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42c.png (709 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f4.png (578 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec-1f1e7.png (747 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f195.png (678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60b.png (931 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f300.png (904 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2705.png (390 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dc.png (435 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1eb.png (362 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0.png (484 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f470.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f358.png (823 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\33-20e3.png (554 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35e.png (493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-close.png (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ac.png (556 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44a.png (816 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f342.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_53.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f503.png (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f437.png (958 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f202.png (452 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b05.png (382 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ed.png (286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49f.png (531 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f338.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\index.html (614 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f566.png (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2733.png (431 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fd.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53c.png (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2728.png (865 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f418.png (859 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f491.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f344.png (988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4db.png (632 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_16.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fd.png (809 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2652.png (430 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49b.png (564 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_32.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_22.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c7.png (422 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f636.png (525 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e7.png (662 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34b.png (937 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2663.png (453 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50e.png (649 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f232.png (689 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f484.png (574 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f555.png (647 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d2.png (901 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_43.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50b.png (344 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f346.png (663 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f551.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f529.png (679 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ab.png (624 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51f.png (619 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231b.png (653 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f452.png (742 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fc.png (199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_67.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_35.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64e.png (772 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\ae.png (761 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2755.png (199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\logo.ico (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f623.png (879 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_19.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f557.png (806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f431.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d5.png (599 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_76.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f482.png (782 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f357.png (605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f4.png (603 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31c.png (845 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17e.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f632.png (846 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b0.png (829 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f0cf.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e6.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ab.png (433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e2.png (262 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f685.png (575 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_54.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f355.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_34.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_63.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f351.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-minus.png (149 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f251.png (658 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26c4.png (868 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f462.png (696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_03.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f687.png (927 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f426.png (965 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f627.png (744 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37c.png (621 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f413.png (944 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ee.png (475 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2712.png (612 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\34-20e3.png (453 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b06.png (398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b5.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f605.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48b.png (631 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f319.png (703 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ef.png (481 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f403.png (756 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47d.png (879 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\32-20e3.png (518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f448.png (471 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_08.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f640.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f530.png (382 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f363.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f454.png (992 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25fe.png (172 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ba.png (491 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50f.png (710 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f680.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f314.png (976 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61e.png (683 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\37-20e3.png (460 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270b.png (496 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f450.png (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f527.png (522 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3299.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a6.png (503 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a0.png (833 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f309.png (733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e2.png (852 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27b0.png (665 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ee.png (557 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bb.png (862 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f538.png (307 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f393.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bf.png (630 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bc.png (435 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f374.png (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e7.png (656 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f405.png (926 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f60e.png (924 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f460.png (765 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f638.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4aa.png (742 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47f.png (724 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_80.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f633.png (988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2744.png (698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f8.png (524 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-exit.png (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f479.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_66.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f520.png (801 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2122.png (612 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f365.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2934.png (453 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e3.png (678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f171.png (468 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36a.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa.png (451 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f683.png (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f490.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f522.png (733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f0.png (530 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41c.png (734 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c0.png (939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1b.png (201 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264f.png (462 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f439.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f510.png (709 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38f.png (999 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2754.png (481 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264c.png (658 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ff.png (474 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f607.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f528.png (403 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f18e.png (693 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b8.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_79.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b0.png (584 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\25ab.png (138 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f466.png (947 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38d.png (865 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3aa.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f603.png (850 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26be.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d9.png (567 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ad.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f61a.png (923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f440.png (446 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69b.png (648 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26fa.png (940 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2660.png (500 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4eb.png (561 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f562.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f192.png (614 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main_test.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ec.png (587 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b9.png (458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\hatter.js (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f19a.png (792 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2600.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4df.png (586 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a7.png (337 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f616.png (885 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f359.png (825 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f367.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f197.png (651 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f239.png (540 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f514.png (486 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f312.png (956 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_64.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f692.png (652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f3.png (814 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48e.png (858 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f475.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b7.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f532.png (247 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_33.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c3.png (543 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c6.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log-none.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37a.png (653 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f191.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f494.png (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f315.png (713 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f618.png (999 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_15.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f334.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c2.png (571 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f444.png (766 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30e.png (942 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fc.png (539 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270c.png (685 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f604.png (836 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f63d.png (968 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f370.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f695.png (718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fd.png (613 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a7.png (522 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ea.png (378 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26d4.png (458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\scripts\message.js (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f306.png (431 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f507.png (882 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b0.png (432 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f609.png (788 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f307.png (954 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a2.png (452 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b1c.png (201 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f619.png (672 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8.png (510 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44d.png (840 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef-1f1f5.png (345 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ea.png (424 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f391.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f458.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267f.png (660 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bd.png (616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2651.png (606 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f443.png (857 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f688.png (849 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f534.png (429 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f461.png (734 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ae.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2197.png (358 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e3.png (389 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bd.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45a.png (920 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f409.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bb.png (607 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3297.png (918 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f332.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52a.png (530 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264e.png (561 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f23a.png (549 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68c.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43e.png (573 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48c.png (801 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c1.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f438.png (862 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f3.png (651 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f415.png (923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_50.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_45.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45f.png (532 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ce.png (624 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f1.png (251 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\303d.png (605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f353.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ef.png (597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus-active.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f6.png (611 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_17.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4dd.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f0-1f1f7.png (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_04.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f464.png (503 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f302.png (918 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52c.png (811 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f317.png (887 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f697.png (684 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f449.png (471 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a5.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f7.png (667 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2797.png (284 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f250.png (909 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b6.png (425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55e.png (831 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2198.png (355 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d4.png (607 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e5.png (315 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f377.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c0.png (705 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f401.png (692 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f488.png (492 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34a.png (816 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f68d.png (514 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bf.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26f2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f492.png (905 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f516.png (283 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f383.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b9.png (222 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f526.png (589 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f536.png (350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f193.png (528 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f411.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f233.png (533 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23f3.png (680 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f422.png (934 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51a.png (666 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f330.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f478.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_75.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f385.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f360.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f477.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_31.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2614.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f691.png (791 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2199.png (353 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f433.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f480.png (694 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f235.png (635 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_12.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f40f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_24.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f378.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69a.png (593 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e6.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\3030.png (427 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f31e.png (902 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b2.png (578 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f22f.png (575 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9-1f1ea.png (267 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fb.png (642 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c6.png (876 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f552.png (702 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45d.png (765 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\267b.png (951 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ec.png (350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a0.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49e.png (971 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42b.png (792 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f524.png (608 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4fa.png (578 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f686.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f468.png (930 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bb.png (320 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2747.png (473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f612.png (732 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f559.png (809 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_58.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_18.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b4.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b5.png (447 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f471.png (939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e4.png (494 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62b.png (974 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d8.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web2mob\web\scripts\jquery.min.js (4267 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fb.png (577 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47e.png (154 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cc.png (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f420.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c8.png (696 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f698.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26ce.png (583 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f387.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b5.png (437 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f617.png (648 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f366.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f238.png (393 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f614.png (688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f550.png (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cd.png (559 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f9.png (541 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f47c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1fa-1f1f8.png (310 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-plus.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6af.png (995 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f611.png (475 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f362.png (780 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f456.png (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a4.png (813 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c0.png (781 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f5fe.png (580 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f428.png (870 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f50d.png (611 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\Data\Config.xml (227 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f434.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f199.png (565 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f419.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f347.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26a0.png (655 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoDB13.tmp\nsisFirewall.dll (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_68.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6c2.png (607 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f646.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\a9.png (745 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\e50a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d6.png (694 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ad.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f44f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2653.png (516 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\23ec.png (383 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ea.png (551 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\27a1.png (372 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f339.png (959 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f445.png (620 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f473.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d1.png (559 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c1.png (223 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f34e.png (764 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f489.png (779 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6b2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f311.png (712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f170.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f486.png (909 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e9.png (524 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f52d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6ae.png (474 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f41d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f531.png (642 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2650.png (416 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f512.png (464 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ad.png (519 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_42.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-icon.png (660 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2196.png (356 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_46.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f556.png (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\264a.png (364 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_52.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f481.png (972 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6bc.png (628 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f331.png (504 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f350.png (595 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a8.png (859 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55f.png (905 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_21.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f49a.png (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35d.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f635.png (770 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c4.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e9.png (458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bd.png (959 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_10.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4cf.png (572 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f333.png (697 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\274c.png (421 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f345.png (881 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f337.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee.png (302 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270f.png (648 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e8-1f1f3.png (411 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f43d.png (466 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f447.png (498 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4da.png (863 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e8.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3e1.png (713 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\26aa.png (433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_05.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_51.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f313.png (887 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f424.png (927 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_40.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_27.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f381.png (477 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_29.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f42f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f17f.png (413 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2757.png (199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\270a.png (665 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2611.png (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f465.png (720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_09.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f45b.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a5.png (393 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b8.png (750 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62e.png (666 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f3.png (489 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b7.png (871 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2764.png (513 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f537.png (357 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d0.png (383 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4d7.png (570 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f634.png (999 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a3.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f51c.png (733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f392.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f386.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2668.png (693 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4f5.png (911 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_61.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f533.png (247 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f389.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4c4.png (425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f372.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\tray-log.png (670 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_23.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f35f.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f496.png (937 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4bf.png (943 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ab.png (735 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e0.png (652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f483.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_39.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3ca.png (954 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f554.png (806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b07.png (394 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ef.png (368 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b7.png (418 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f621.png (715 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f388.png (558 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2666.png (407 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f369.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f463.png (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f33a.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f565.png (801 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2709.png (599 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3c8.png (871 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2702.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f37b.png (875 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f436.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4e5.png (537 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f201.png (366 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f30a.png (806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f689.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4a1.png (715 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b3.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f375.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_74.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b3.png (498 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3b1.png (741 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\31-20e3.png (326 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f318.png (955 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4ed.png (470 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f38e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3be.png (832 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f432.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36c.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f368.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_70.png (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\231a.png (754 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f601.png (679 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f474.png (997 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f64b.png (945 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f600.png (815 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f69e.png (729 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f62c.png (678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f513.png (463 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f417.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f630.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_01.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f499.png (564 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f430.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f36d.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f53d.png (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f421.png (859 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3bc.png (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\38-20e3.png (545 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f55d.png (900 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a6.png (458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\2b55.png (546 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f48a.png (512 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\39-20e3.png (527 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a1.png (738 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a4.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f563.png (787 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f469.png (873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\main.html (734 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f610.png (547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_36.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1f9.png (342 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6a8.png (555 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f46e.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3a1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f505.png (543 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_06.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f4b1.png (840 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f404.png (927 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\smileys\smiley_07.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1e7.png (468 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f628.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f361.png (806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f6be.png (736 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f1ee-1f1f9.png (245 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f320.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\web\media\72x72\1f3af.png (1 bytes)
    C:\ProgramData\ShopperPro\config.json (487 bytes)
    C:\ProgramData\ShopperPro\ShopperPro.dll (2321 bytes)
    %Program Files% (x86)\ShopperPro\config.json (1254 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\database1_0_0.ej (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\config.json (487 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\database1_0_0.json (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\install.rdf (828 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe (22786 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.sys (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\overlay.xul (203 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\content\shopperpro_128.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}\chrome.manifest (113 bytes)
    C:\ProgramData\ShopperPro\database1_0_0.ej (14 bytes)
    C:\ProgramData\ShopperPro\ShopperPro64.dll (3361 bytes)
    %Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\config.json (767 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\gzxaaspvo.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\System.dll (808 bytes)
    C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5.job (74 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\125b6778-a7b3-42de-b39a-7082dbd6c683-4.dll (38103 bytes)
    %Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-5.exe (7433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\lutouoko.dll (13 bytes)
    %Program Files% (x86)\iWebar\utils.exe (63821 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\wuogor.dll (8 bytes)
    C:\Windows\Tasks\125b6778-a7b3-42de-b39a-7082dbd6c683-5_user.job (74 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\133 (3589 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\emfom.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\340584 (92733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\kvwinpd.dll (3730 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyA60F.tmp (601872 bytes)
    %Program Files% (x86)\iWebar\Uninstall.exe (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\ipgeoapi_com[1].json (40 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\hmwmphigb.dll (14 bytes)
    %Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683.xpi (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\bakxdyd.dll (31241 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdA62F.tmp\eaxnwm.dll (13 bytes)
    %Program Files% (x86)\iWebar\125b6778-a7b3-42de-b39a-7082dbd6c683-4.exe (9147 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\08698225a6048f6e460097f16e02e704.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\71d4611ff095ba11d5170e66cbcb1f99.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\242.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e495468dafb76cfdaf72e5fa8d28a349.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\64e8d4e87627d5c1948a0bcef5d8bddf.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\27cf8aa127aac261d305fe9089529830.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\376.js (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\3d80de7fb266005117ceaafcc80fdce9.js (357 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\cd81bdfb69d0d25218ce67718be563af.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\399.js (525 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\385.js (805 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (506 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\1780bb19c407d25583ce46e040481d99.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\85ea74e5af2c1af63fce579c5ab50f9f.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (622 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b25ebd4eb2e834fb9cccdc10bb148863.js (947 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\fbbdb0f74062a849bda57f6fe11fcf32.js (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f769131cae2813ce580e9e94c4e96f9c.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\e7c458df68b2cf4608fc221688ae08ca.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ebf33cc6f061080861c3e83c583756dc.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\290.js (897 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\fd27a2fb33b55a5f18ab50f4ba936cd4.js (964 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0bec9e6b7afcc4c4516f35378da8e8f9.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\af5a57f759bd1cf2e294bcfccaf931fb.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\686b2fd98f5ea3e56eaaef1af8491492.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\3e381797919b94e2bb615148f7e47028.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\56d8099de7f917a05ebc946e4ff23a90.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffb8884740ec4a25e7613eb834ca1913.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\79f3c8aab387a44396d3dacdadf581ca.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0034b573374c522556781d729432c887.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\525208f03fe2d8bef8b7bb6b8ef4fce1.js (649 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\287fabae0a36fcfbc8d77dcdaaaad216.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\8c01eaa93fd0bc0662848c840cae8041.js (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (663 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b790483a12fb1b0b6cd3863184729b25.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\633a77e2ae00bb6d6d2e3abbbbe03912.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\269585125e1cb71c5dfc6f15d18aba48.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\01b19a2e32d1a93bc2187a399e31eb51.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\edc254d662db048aede80d03ff95a848.js (28 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\5647e30e6af0add68690b1d263429c43.js (618 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\eca39140ee956f1f06527fb9ad62e501.js (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b7c3eebfc78cf0199ff6ad83ec7241bf.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\e83df05e1cf9ce178c9205b266814e5e.js (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\69a7dc8ac94d415bb9c821991dc88c28.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (899 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\29d9a644a93fb36aff415aeea5c35684.js (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\8c47021875b6fd49edb959b301d1c49a.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\437c9512ae40f6cf2212e22d83fc0762.js (134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\6aacfc15412fb43d4bcd12a55d84a7ac.js (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\391.js (801 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\1358a6937d07734cf85a79aaec52d489.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (969 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\a48b2e165ded142e4fd41c767365d414.js (26 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\MessageBox.xml (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\474.json (512 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\Thumbs.db (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code6.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\unchecked.png (135 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bk_shadow.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\QQBrowser.exe (5199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\sweetsearch!1.0.0.1031.xpi (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\Thumbs.db (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code5.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checked.png (222 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox_select.png (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg1.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code4.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\close.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_bg.png (159 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg2.zip (259958 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\bg.png (5064 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code1.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\loading_light.png (139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code3.jpg (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\DataBase (26688 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\conf (79 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\quick_searchff#5.4.10.xpi (6360 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\button.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\UninstallManager.exe (60186 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\scrollbar.bmp (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\min.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\uninstallDlg2.xml (784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\eg1.zip (172558 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\code\code2.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xtmp443682\images\checkbox.png (545 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\NK.lky (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup1.exe (144456 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61CF.tmp (155198 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\setup.exe (1606835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy61D0.tmp\D1958.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe (8409 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nshCF02.tmp (7098 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\config.ini (113 bytes)
    %Program Files% (x86)\YouTube Accelerator\instlsp.log (295 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\content\YTAHelper_64.png (4 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\chrome.manifest (111 bytes)
    %Program Files% (x86)\YTAHelper\YTAHelper.exe (32784 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsExec.dll (14 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\install.rdf (884 bytes)
    %Program Files% (x86)\YTAHelper\JSDriver\jsdrv.sys (1856 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\content\overlay.js (13 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\content\overlay.xul (203 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\jsdrv.exe (100669 bytes)
    %Program Files% (x86)\YTAHelper\JSDriver\jsdrv.exe (100378 bytes)
    C:\Users\Public\Documents\YTAHelper\JsDriver\Config.xml (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B02.tmp (118586 bytes)
    %Program Files% (x86)\YTAHelper\yta_database1_0_0.json (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\nsProcess.dll (12 bytes)
    %Program Files% (x86)\YTAHelper\YTAHelper.dll (13584 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\AccDownload.dll (11667 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\System.dll (23 bytes)
    %Program Files% (x86)\YTAHelper\YTAHelper64.dll (16424 bytes)
    %Program Files% (x86)\YTAHelper\FireFox\content\shopperpro_128.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn6B03.tmp\MoreInfo.dll (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_17690\DCytaiesmt_smtyc_setup.exe (7726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_sense.exe (48375 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_yta.exe (31105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_shopperpro.exe (18619 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Installer\Install_24323\DCytaiesmt_smtyc_setup.exe (7726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Install_28610\ins_iwebar.exe (50552 bytes)
    C:\ProgramData\ShopperPro\spbihe.js (435 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsExec.dll (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\UserInfo.dll (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\IpConfig.dll (4254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\System.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\WmiInspector.dll (3137 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\NSISEncrypt.dll (3342 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\nsJSON.dll (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoC091.tmp\inetc.dll (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Sgfzhi.tmp (390774 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\Npjwb.exe (1335155 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\emfom.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\gzxaaspvo.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA499.tmp\pvgykk.dll (2121 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\4D90EAE405E9E2FF (34773 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\NK.lky (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\D1989.dll (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\DCytaiesmt_smtyc_setup.exe (379403 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3248.tmp\System.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy3247.tmp (35697 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\pvgykk.dll (2121 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\emfom.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Ussgbdqdxxc.exe (1340508 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\Rtmrbzobbxy.tmp (392398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nstA380.tmp\gzxaaspvo.dll (30 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "GOOBZOYouTubeAccelerator" = "%Program Files% (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "DesktopMessenger" = "C:\Users\"%CurrentUserName%"\AppData\Local\DesktopMessenger\DesktopMessenger.exe"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "SPDriver" = "%Program Files% (x86)\ShopperPro\JSDriver\1.42.0.1773\jsdrv.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now