Gen.Variant.Adware.Dropper.105_56a4a4ed98
Gen:Variant.Adware.Dropper.105 (BitDefender), Trojan.Win32.Generic!BT (VIPRE), Trojan.Crossrider.26651 (DrWeb), Gen:Variant.Adware.Dropper.105 (B) (Emsisoft), PUP-FMU (McAfee), WS.Reputation.1 (Symantec), AdWare.EzDownloader (Ikarus), Gen:Variant.Adware.Dropper.105 (FSecure), Generic_r.QP (AVG), Win32:Adware-gen [Adw] (Avast), Gen:Variant.Adware.Dropper.105 (AdAware)
Behaviour: Trojan, PUP, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
The sample has been submitted by Lavasoft customers.
| Requires JavaScript enabled! |
|---|
MD5: 56a4a4ed981e92c322cd7d48b653238c
SHA1: 6141c1aa2833f0fbc109cdaf1f631b6d49e4332b
SHA256: 13344492697f6fe1121aebe27f31641a0f5d2bf455c02d2ce875609f73ead5ac
SSDeep: 24576:y/j1Df4s77ksQGLI6l4ATwVEqy9JXEYRYObf1T30TrKhc :Ej1r4wSGLII4OwVy9JXfrrOKJ
Size: 1015296 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: SafeInstall, LLC
Created at: 2014-07-24 17:49:01
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
Tbg3n2vkBD.exe:1276
%original file name%.exe:1736
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process Tbg3n2vkBD.exe:1276 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%System%\GroupPolicy\Machine\Registry.pol (264 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\All Users\Application Data\f362fc35c4a3dbfb\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140805145418 (180 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%System%\GroupPolicy\gpt.ini (315 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
The process %original file name%.exe:1736 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected] (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\bootstrap.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\content\bg.js (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\chrome.manifest (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47 (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\install.rdf (606 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\pzzpW6yB1_K.js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\lsdb.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\content.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.exe (3807 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\manifest.json (502 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\bootstrap.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\content\bg.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\chrome.manifest (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\background.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\install.rdf (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.dat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\pzzpW6yB1_K.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\lsdb.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\content (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\content.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\manifest.json (0 bytes)
Registry activity
The process Tbg3n2vkBD.exe:1276 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2C 9D 2B C7 A7 59 AE 30 61 3B CF 56 65 E4 2B 9F"
[HKLM\SOFTWARE\Policies\Google\Update]
"UpdateDefault" = "0"
[HKLM\SOFTWARE\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"ap" = "-dev-multi-chrome"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}]
"{FDB962F0-B5B8-9460-D12F-7966E97BAA43}" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"ap" = "2.0-dev-multi-chrome"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine\Software\Policies\Google\Chrome]
"MetricsReportingEnabled" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The Trojan deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{FC0266D1-27B8-4DBA-87DD-C0F5F0ECFBC9}Machine]
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: The use
Product Name: tools control professional the
Product Version: 0.1.0.0
Legal Copyright: Copyright (c) 2014
Legal Trademarks:
Original Filename: tool
Internal Name: tool
File Version: 0.1.0.0
File Description: tools control professional the
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 140574 | 140800 | 4.58101 | 9f5070c3db8215f81336781330645c0c |
| .rdata | 147456 | 43730 | 44032 | 3.15469 | ea9123306312ca74fc4b7abb72ee8404 |
| .data | 192512 | 22264 | 12288 | 1.8677 | 1c0d5f6c2ebef03707e5dde6ae561859 |
| .rsrc | 217088 | 6834 | 817152 | 5.51491 | 3ba454e6aea8b48d81f3c54379983a65 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
No activity has been detected.
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Web Traffic was not found.
The Trojan connects to the servers at the folowing location(s):
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
Tbg3n2vkBD.exe:1276
%original file name%.exe:1736 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%System%\GroupPolicy\Machine\Registry.pol (264 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\All Users\Application Data\f362fc35c4a3dbfb\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140805145418 (180 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%System%\GroupPolicy\gpt.ini (315 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Chromatic Browser\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\content.js (262 bytes)
%Documents and Settings%\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\lsdb.js (263 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\pzzpW6yB1_K.js (1040 bytes)
%Documents and Settings%\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cdmcfibcendejaeogbidhpppfadghmcm\3.9\manifest.json (758 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected] (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\bootstrap.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\content\bg.js (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\chrome.manifest (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\background.html (148 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\[email protected]\install.rdf (606 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\pzzpW6yB1_K.js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\lsdb.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\content.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\Tbg3n2vkBD.exe (3807 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3bdd1b47\cdmcfibcendejaeogbidhpppfadghmcm\manifest.json (502 bytes)
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.