Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /im chrome.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\mozilla\firefox\profiles.ini
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\icon.png
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\aes.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\background.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\content.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\jquery-3.3.1.min.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\mode-ecb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\pad-nopadding.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\manifest.json
- %TEMP%\cghjgasaaz99\local state
- %TEMP%\cghjgasaaz99\safe browsing cookies
- %TEMP%\cghjgasaaz99\default\chromedwritefontcache
- %TEMP%\cghjgasaaz99\default\cookies
- %TEMP%\cghjgasaaz99\default\current session
- %TEMP%\cghjgasaaz99\default\extension cookies
- %TEMP%\cghjgasaaz99\default\favicons
- %TEMP%\cghjgasaaz99\default\google profile.ico
- %TEMP%\cghjgasaaz99\default\history
- %TEMP%\cghjgasaaz99\default\history provider cache
- %TEMP%\cghjgasaaz99\default\history-journal
- %TEMP%\cghjgasaaz99\default\login data
- %TEMP%\cghjgasaaz99\default\network action predictor
- %TEMP%\cghjgasaaz99\default\preferences
- %TEMP%\cghjgasaaz99\default\quotamanager
- %TEMP%\cghjgasaaz99\default\readme
- %TEMP%\cghjgasaaz99\default\secure preferences
- %TEMP%\cghjgasaaz99\default\shortcuts
- %TEMP%\cghjgasaaz99\default\top sites
- %TEMP%\cghjgasaaz99\default\visited links
- %TEMP%\cghjgasaaz99\default\web data
- %TEMP%\cghjgasaaz99\default\cache\data_0
- %TEMP%\cghjgasaaz99\default\cache\data_1
- %TEMP%\cghjgasaaz99\default\cache\data_2
- %TEMP%\cghjgasaaz99\default\cache\data_3
- %TEMP%\cghjgasaaz99\default\cache\index
- %TEMP%\cghjgasaaz99\default\databases\databases.db
- %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\current
- %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\log
- %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\manifest-000001
- %TEMP%\cghjgasaaz99\default\extension rules\000003.log
- %TEMP%\cghjgasaaz99\default\extension rules\current
- %TEMP%\cghjgasaaz99\default\extension rules\log
- %TEMP%\cghjgasaaz99\default\extension rules\manifest-000001
- %TEMP%\cghjgasaaz99\default\extension state\000003.log
- %TEMP%\cghjgasaaz99\default\extension state\current
- %TEMP%\cghjgasaaz99\default\extension state\log
- %TEMP%\cghjgasaaz99\default\extension state\manifest-000001
- %TEMP%\cghjgasaaz99\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_128.png
- %TEMP%\cghjgasaaz99\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_16.png
- %TEMP%\cghjgasaaz99\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.html
- %TEMP%\cghjgasaaz99\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.js
- %TEMP%\cghjgasaaz99\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\128.png
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ar\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\bg\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ca\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\cs\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\da\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\de\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\el\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_gb\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_us\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es_419\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\et\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\eu\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fil\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\he\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hu\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\id\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\it\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ja\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ko\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ms\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\nl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\no\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_br\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_pt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ro\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ru\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\th\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\tr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\uk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\vi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_cn\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_tw\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\128.png
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ar\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\bg\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ca\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\cs\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\da\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\de\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\el\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\en\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\es\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fil\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\he\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hu\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\id\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\it\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ja\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ko\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\nl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\no\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_br\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_pt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ro\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ru\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\th\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\tr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\uk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\vi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_cn\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_tw\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\128.png
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\16.png
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\32.png
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\48.png
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ar\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\bg\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ca\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\cs\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\da\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\de\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\el\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_gb\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_us\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es_419\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\et\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fil\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\he\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hu\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\id\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\it\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ja\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ko\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\nl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\no\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_br\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_pt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ro\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ru\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\th\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\tr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\uk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\vi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_cn\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_tw\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\background.html
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\icon.png
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\aes.js
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\background.js
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\content.js
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\jquery-3.3.1.min.js
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\mode-ecb.js
- %TEMP%\cghjgasaaz99\default\extensions\hemlmgggokggmncimchkllhcjcaimcle\9.86.66_0\js\pad-nopadding.js
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\128.png
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\manifest.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ar\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\bg\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ca\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\cs\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\da\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hu\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\it\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ko\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\no\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_br\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_pt\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ro\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ru\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sl\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\th\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\tr\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\uk\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\vi\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_cn\messages.json
- %TEMP%\cghjgasaaz99\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_tw\messages.json
- %TEMP%\cghjgasaaz99\default\session storage\current
- %TEMP%\cghjgasaaz99\default\session storage\log
- %TEMP%\cghjgasaaz99\default\session storage\manifest-000001
- %TEMP%\932703.dat
- %TEMP%\932734.dat
- %TEMP%\932750.dat
- %TEMP%\cookies.sqlite
- %TEMP%\cookies.sqlite-shm
- %TEMP%\cghjgasaaz99\default\3c0b.tmp
- %TEMP%\cghjgasaaz99\default\shortcuts-journal
- %TEMP%\etilqs_nacy9uq4dvudgac
- %TEMP%\cghjgasaaz99\61e3.tmp
- %TEMP%\cghjgasaaz99\default\62a0.tmp
- %TEMP%\cghjgasaaz99\default\62b0.tmp
- %TEMP%\cghjgasaaz99\9d6a.tmp
- %TEMP%\cghjgasaaz99\default\bac7.tmp
- %TEMP%\cghjgasaaz99\ff74.tmp
- %TEMP%\cghjgasaaz99\4c9b.tmp
- %TEMP%\cghjgasaaz99\default\5799.tmp
- %TEMP%\cghjgasaaz99\8979.tmp
- %TEMP%\932734.dat
- %TEMP%\cookies.sqlite-shm
- %TEMP%\cookies.sqlite
- %TEMP%\cghjgasaaz99\default\3c0b.tmp
- %TEMP%\cghjgasaaz99\default\history provider cache
- %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\log в %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\log.old
- %TEMP%\cghjgasaaz99\default\current session в %TEMP%\cghjgasaaz99\default\last session
- %TEMP%\cghjgasaaz99\default\extension state\log в %TEMP%\cghjgasaaz99\default\extension state\log.old
- %TEMP%\cghjgasaaz99\61e3.tmp в %TEMP%\cghjgasaaz99\local state
- %TEMP%\cghjgasaaz99\default\62a0.tmp в %TEMP%\cghjgasaaz99\default\secure preferences
- %TEMP%\cghjgasaaz99\default\62b0.tmp в %TEMP%\cghjgasaaz99\default\preferences
- %TEMP%\cghjgasaaz99\9d6a.tmp в %TEMP%\cghjgasaaz99\local state
- %TEMP%\cghjgasaaz99\default\bac7.tmp в %TEMP%\cghjgasaaz99\default\secure preferences
- %TEMP%\cghjgasaaz99\ff74.tmp в %TEMP%\cghjgasaaz99\local state
- %TEMP%\cghjgasaaz99\default\session storage\log в %TEMP%\cghjgasaaz99\default\session storage\log.old
- %TEMP%\cghjgasaaz99\4c9b.tmp в %TEMP%\cghjgasaaz99\local state
- %TEMP%\cghjgasaaz99\default\5799.tmp в %TEMP%\cghjgasaaz99\default\preferences
- %TEMP%\cghjgasaaz99\8979.tmp в %TEMP%\cghjgasaaz99\local state
- %LOCALAPPDATA%\google\chrome\user data\default\secure preferences
- %TEMP%\cghjgasaaz99\default\data_reduction_proxy_leveldb\log
- %TEMP%\cghjgasaaz99\default\current session
- %TEMP%\cghjgasaaz99\default\extension state\log
- %TEMP%\cghjgasaaz99\default\session storage\log
- 'ip###ger.org':443
- '80.##0.113.62':80
- 'se####.facebook.com':443
- 'fa###ook.com':443
- 'clients2.google.com':443
- 'clients4.google.com':443
- 'tr######e.googleapis.com':443
- 'clients3.google.com':443
- 'ss#.#static.com':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2f##############
- 'ip###ger.org':443
- 'se####.facebook.com':443
- 'fa###ook.com':443
- 'clients2.google.com':443
- 'tr######e.googleapis.com':443
- 'ss#.#static.com':443
- 'gs##tic.com':443
- DNS ASK li###ncode.com
- DNS ASK ip###ger.org
- DNS ASK iy##ian.com
- DNS ASK google.com
- DNS ASK se####.facebook.com
- DNS ASK fa###ook.com
- DNS ASK clients2.google.com
- DNS ASK clients4.google.com
- DNS ASK tr######e.googleapis.com
- DNS ASK clients3.google.com
- DNS ASK ss#.#static.com
- DNS ASK gs##tic.com
- ClassName: '' WindowName: ''
- ClassName: 'Chrome_MessageWindow' WindowName: '%TEMP%\cghjgasaaz99'
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im chrome.exe (со скрытым окном)
- '%WINDIR%\syswow64\xcopy.exe' "%LOCALAPPDATA%\Google\Chrome\User Data" "%TEMP%\cghjgasaaz99\" /s /e /y