Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a6b88fba-3469-4d57-8c6d-fa574dce5260}]
- %TEMP%\28bd095d\7ob7u3xwhbullk6.dat
- %TEMP%\28bd095d\tmsmxpl9dcbeve.dll
- %TEMP%\28bd095d\tmsmxpl9dcbeve.tlb
- %TEMP%\28bd095d\tmsmxpl9dcbeve.x64.dll
- %TEMP%\28bd095d\ap@bg86o.org\content\bg.js
- %TEMP%\28bd095d\ap@bg86o.org\bootstrap.js
- %TEMP%\28bd095d\ap@bg86o.org\chrome.manifest
- %TEMP%\28bd095d\ap@bg86o.org\install.rdf
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\rs.js
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\background.html
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\manifest.json
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\content.js
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\google\chrome\user data\default\preferences__.tmp
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\administrator\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\administrator\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- %LOCALAPPDATA%\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- %LOCALAPPDATA%\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- %LOCALAPPDATA%\torch\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\background.html
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\content.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\lsdb.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\manifest.json
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\bmfojihefgokhggoplhfjpfhmeljnbjc\1.0\rs.js
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\ap@bg86o.org\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\ap@bg86o.org\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\ap@bg86o.org\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\staged\ap@bg86o.org\install.rdf
- %ALLUSERSPROFILE%\ntuser.pol
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\ap@bg86o.org\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\ap@bg86o.org\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\ap@bg86o.org\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\staged\ap@bg86o.org\install.rdf
- %ProgramFiles(x86)%\nextcoup\tmsmxpl9dcbeve.dll
- %ProgramFiles(x86)%\nextcoup\tmsmxpl9dcbeve.tlb
- %ProgramFiles(x86)%\nextcoup\tmsmxpl9dcbeve.dat
- %ProgramFiles(x86)%\nextcoup\tmsmxpl9dcbeve.x64.dll
- %ALLUSERSPROFILE%\nextcoup\7ob7u3xwhbullk6.exe
- %ALLUSERSPROFILE%\nextcoup\7ob7u3xwhbullk6.dat
- %ALLUSERSPROFILE%\c8d5e1ba74fe2a63\{3d0f43d9-c1d7-733c-01f8-4a3001bf8cc3}.20250709075344
- %TEMP%\28bd095d\7ob7u3xwhbullk6.dat
- %TEMP%\28bd095d\tmsmxpl9dcbeve.dll
- %TEMP%\28bd095d\tmsmxpl9dcbeve.tlb
- %TEMP%\28bd095d\tmsmxpl9dcbeve.x64.dll
- %TEMP%\28bd095d\ap@bg86o.org\content\bg.js
- %TEMP%\28bd095d\ap@bg86o.org\bootstrap.js
- %TEMP%\28bd095d\ap@bg86o.org\chrome.manifest
- %TEMP%\28bd095d\ap@bg86o.org\install.rdf
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\rs.js
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\background.html
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\manifest.json
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\content.js
- %TEMP%\28bd095d\bmfojihefgokhggoplhfjpfhmeljnbjc\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\local state
- %LOCALAPPDATA%\google\chrome\user data\default\preferences__.tmp
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\NextCoup\TMSmXPL9DcBeVE.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\NextCoup\TMSmXPL9DcBeVE.x64.dll"
- '<SYSTEM32>\raserver.exe' /offerraupdate