Техническая информация
- '<LS_APPDATA>\25922\buildcrx-v1.0.exe' Chrome.zip toolbar.pem "newl.crx"
- '<LS_APPDATA>\25922\7z.exe' x newl.crx -o"addon"
- '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\newl Toolbar\pluginaddon.dll"
- firefox.exe
- chrome.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\down.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\up.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\normal\top.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\normal\bottom.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\normal\middle.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\button.css
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\converter.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\dbwrapper.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\statanalyzer.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\chevron.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\toolbar.css
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\hover\top.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\layout.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\apis\clientapi.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\config.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\search.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\rubar-search.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\apis\webapi.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\hover\bottom.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\hover\middle.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\active\top.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\active\bottom.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\chevron\images\active\middle.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\domhelper.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\addon.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\addon.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\popup\popupHtmlDlg.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\observers\uninstall.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\popup\popupHtmlDlg.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\rubar.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\install.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\install.rdf
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\components\pkgProtocol.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\rubar.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome.manifest
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\observers\Navigate.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\registry.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\serfer.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\prefservice.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\io.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\packagesapi.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\settings.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\rlibrary.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\observers\responses.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\xmlhelper.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\statlogger.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\modules\urls.jsm
- %PROGRAM_FILES%\newl Toolbar\PluginAddon.dll
- %PROGRAM_FILES%\newl Toolbar\Uninstall.exe
- %PROGRAM_FILES%\newl Toolbar\config.xml
- <LS_APPDATA>\newl\Packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\loader.dll
- %TEMP%\nso2.tmp\nsProcess.dll
- %APPDATA%\pluginaddonEngine\PluginAddonEngine.exe
- %TEMP%\nso2.tmp\KillProcDLL.dll
- <LS_APPDATA>\25922\toolbar.pem
- %TEMP%\nso2.tmp\FindProcDLL.dll
- %TEMP%\msihelper.dll
- %APPDATA%\__VENDOR__-Toolbar\MsiHelper.log.log
- <LS_APPDATA>\newl\Packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\config.xml
- <LS_APPDATA>\newl\clids.xml
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\ba069440-8256-4280-90e1-73d0b721b46e.zip
- <LS_APPDATA>\newl\layout.xml
- %TEMP%\nso2.tmp\System.dll
- %TEMP%\nso2.tmp\UAC.dll
- %TEMP%\nso2.tmp\nsisunz.dll
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\loader.dll
- <LS_APPDATA>\newl\Packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\d29f6063-5a9a-43ca-921e-c15cd5358dfd.zip
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\images\yandex.ico
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\config.xml
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\images\mc_search.png
- <LS_APPDATA>\25922\7z.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\ACSearch.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\config.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\searchcontrol.xbl
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\modules\StatAnalyzer.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\modules\DOMHelper.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\loader.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\config.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\clids.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\loader.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\images\mc_search.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\images\yandex.ico
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\locale\ru\search.dtd
- <LS_APPDATA>\25922\newl.crx
- %TEMP%\newl.xpi
- <LS_APPDATA>\25922\buildcrx-v1.0.exe
- <LS_APPDATA>\25922\7z.exe
- <LS_APPDATA>\25922\Chrome.zip
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\searchplugins\search.xml
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\c9a595ba-e555-45f5-9d62-4abd8a2810a0\images\logo.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\ba069440-8256-4280-90e1-73d0b721b46e\locale\en\search.dtd
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\c9a595ba-e555-45f5-9d62-4abd8a2810a0\loader.jsm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\c9a595ba-e555-45f5-9d62-4abd8a2810a0\button.xbl
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\{fc45bcd8-664c-4e0a-8cc6-ebf5be4299ee}\chrome\content\data\packages\c9a595ba-e555-45f5-9d62-4abd8a2810a0\config.xml
- %TEMP%\nso2.tmp\KillProcDLL.dll
- %TEMP%\nso2.tmp\FindProcDLL.dll
- %TEMP%\newl.xpi
- %TEMP%\nso2.tmp\nsisunz.dll
- %TEMP%\nso2.tmp\UAC.dll
- %TEMP%\nso2.tmp\System.dll
- %TEMP%\nso2.tmp\nsProcess.dll
- <LS_APPDATA>\25922\buildcrx-v1.0.exe
- %TEMP%\msihelper.dll
- <LS_APPDATA>\newl\Packages\d29f6063-5a9a-43ca-921e-c15cd5358dfd\d29f6063-5a9a-43ca-921e-c15cd5358dfd.zip
- <LS_APPDATA>\newl\Packages\ba069440-8256-4280-90e1-73d0b721b46e\ba069440-8256-4280-90e1-73d0b721b46e.zip
- <LS_APPDATA>\25922\7z.exe
- <LS_APPDATA>\25922\Chrome.zip
- <LS_APPDATA>\25922\toolbar.pem
- <LS_APPDATA>\25922\7z.dll