Adware.CloudGuard
* Registry path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F281C29C-8BF6-4C4D-8984-B28ECD661AF5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GTFPOQUOTT
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\oaocmnfllndpbbmjmniielgaanaifehp
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.oaocmnfllndpbbmjmniielgaanaifehp.uid
HKEY_LOCAL_MACHINE\SOFTWARE\GTFPOQUOTT Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GTFPOQUOTT Updater_is1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GTFPOQUOTT Updater
* Files path
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\_metadata\verified_contents.json
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\manifest.json
C\Program Files\GTFPOQUOTT\gtfpoquott.exe
C\Windows\System32\Tasks\GTFPOQUOTT
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 48pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 16pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 128pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\back.js
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\_metadata
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0
|
|