Technical Information
- %TEMP%\nse11fb.tmp
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossriderapi.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.xul
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossrider.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\browser.xul
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\dialog.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\background.html
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\lib\faye-browser-min.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\manage-apps.html
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\messaging.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\manage-apps-style.css
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\push.html
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\search_dialog.xul
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\install.rdf
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\prefs.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\locale\en-us\translations.dtd
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\defaults\preferences\prefs.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\button1.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\update.css
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\icon128.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\icon16.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\button2.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome\content\update.html
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\button4.png
- %TEMP%\nst1d02.tmp\cleanchromeprefs.vbs
- %TEMP%\nsz7db9.tmp
- %TEMP%\nst1d02.tmp\removefromlist.vbs
- %LOCALAPPDATA%\i want this\chrome\i want this.crx
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\locale\en-us\translations.dtd
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\defaults\preferences\prefs.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\button1.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\update.css
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\icon128.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\icon16.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\crossrider.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\crossrider_statusbar.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\icon48.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\popup.css
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\button5.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\skin.css
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\panelarrow-up.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\popup.html
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\icon24.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\button3.png
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\popup_binding.xml
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\crossrider_statusbar.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\icon48.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\popup.css
- %ProgramFiles(x86)%\i want this\i want this.ico
- %ProgramFiles(x86)%\i want this\i want this.dll
- %ProgramFiles(x86)%\i want this\json.js
- %ProgramFiles(x86)%\i want this\jquery.js
- %ProgramFiles(x86)%\i want this\fb.js
- %ProgramFiles(x86)%\i want this\appapiinternalwrapper.js
- %ProgramFiles(x86)%\i want this\i want thisgui.exe
- %ProgramFiles(x86)%\i want this\i want this.exe
- %TEMP%\nst1d02.tmp\processes.dll
- %TEMP%\nst1d02.tmp\i want this_tmp
- %TEMP%\nst1d02.tmp\inetc.dll
- %TEMP%\nst1d02.tmp\userinfo.dll
- %TEMP%\nst1d02.tmp\md5dll.dll
- %TEMP%\nst1d02.tmp\nsisos.dll
- %TEMP%\nst1d02.tmp\dialer.dll
- %TEMP%\i want thisinstaller_1738215439.log
- %TEMP%\nst1d02.tmp\nsislog.dll
- %TEMP%\nst1d02.tmp\system.dll
- %TEMP%\nst1d02.tmp\stdutils.dll
- %TEMP%\iwantthis-us.exe
- %TEMP%\nst1d02.tmp\execdos.dll
- %TEMP%\nst1d02.tmp\i want this.xpi
- %ProgramFiles(x86)%\i want this\uninstall.exe
- %TEMP%\nst1d02.tmp\zipdll.dll
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\button5.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\install.rdf
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\skin.css
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\panelarrow-up.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\popup.html
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\icon24.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\button3.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\popup_binding.xml
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\skin\button4.png
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\update.html
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\crossriderapi.js
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\extensions\crossriderapp2258@crossrider.com\skin\button2.png
- %TEMP%\nsu8845.tmp
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\browser.xul
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\dialog.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\background.html
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\lib\faye-browser-min.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\manage-apps.html
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\messaging.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\options.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\manage-apps-style.css
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\push.html
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\search_dialog.xul
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\extensions\crossriderapp2258@crossrider.com\chrome\content\options.xul
- %TEMP%\nszc727.tmp\inetc.dll
- %TEMP%\nst1d02.tmp\removefromlist.vbs
- %TEMP%\nst1d02.tmp\zipdll.dll
- %TEMP%\nst1d02.tmp\userinfo.dll
- %TEMP%\nst1d02.tmp\system.dll
- %TEMP%\nst1d02.tmp\stdutils.dll
- %TEMP%\nst1d02.tmp\processes.dll
- %TEMP%\nst1d02.tmp\nsisos.dll
- %TEMP%\iwantthis-us.exe
- %TEMP%\nst1d02.tmp\nsislog.dll
- %TEMP%\nst1d02.tmp\inetc.dll
- %TEMP%\nst1d02.tmp\i want this_tmp
- %TEMP%\nst1d02.tmp\i want this.xpi
- %TEMP%\nst1d02.tmp\execdos.dll
- %TEMP%\nst1d02.tmp\dialer.dll
- %TEMP%\nst1d02.tmp\cleanchromeprefs.vbs
- %TEMP%\nst1d02.tmp\md5dll.dll
- %TEMP%\nszc727.tmp\inetc.dll
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- %TEMP%\nst1d02.tmp\removefromlist.vbs
- %TEMP%\nst1d02.tmp\cleanchromeprefs.vbs
- 'ga####aylabs.com':80
- http://www.ga####aylabs.com/installer-run/5A7B60CA5F3445F4B77CB26DB0E67D97/59b247c4dfa5a19baa97578a0f2c247e/xriderexe/4caa425a93dbdb1f6d0IS11/?pi################################################
- http://www.ga####aylabs.com/tbi-ping/5A7B60CA5F3445F4B77CB26DB0E67D97/59b247c4dfa5a19baa97578a0f2c247e/xriderexe/4caa425a93dbdb1f6d0IS11/?pi################################################
- http://www.ga####aylabs.com/newuser-ping/5A7B60CA5F3445F4B77CB26DB0E67D97/59b247c4dfa5a19baa97578a0f2c247e/0/xriderexe/4caa425a93dbdb1f6d0IS11/1/?pi#############################################...
- DNS ASK st###.#rossrider.com
- DNS ASK ga####aylabs.com
- DNS ASK co####.crossrider.com
- DNS ASK fr####staller.net
- ClassName: '#32770' WindowName: ''
- '%TEMP%\iwantthis-us.exe'
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\nst1D02.tmp\RemoveFromList.vbs
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\nst1D02.tmp\CleanChromePrefs.vbs
- '%ProgramFiles(x86)%\i want this\i want this.exe' /installapp=2258
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\I Want This\I Want This.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\I Want This\I Want This.dll"' (with hidden window)
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\nst1D02.tmp\RemoveFromList.vbs' (with hidden window)
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\nst1D02.tmp\CleanChromePrefs.vbs' (with hidden window)
- '%ProgramFiles(x86)%\i want this\i want this.exe' /installapp=2258' (with hidden window)