Is the file {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI located on your computer? Then your computer is infected.
We do suggest you should remove {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI from your computer as soon as possible.
{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI is Trojan/Backdoor.
Kill the process {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI and remove {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI from the Windows startup.
Malware Analysis of {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI
Full path on a computer: %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI
Detected by UnHackMe:
{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI
Default location: %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI
Removal Results: Success
Number of reboot: 1
{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI is known as:
Trojan AVKill
How to quickly detect {3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI presence?
Files:
- %PROGRAMFILES%\MYAPP\CONFIG2.DAT
- %TEMP%\NSY6.TMP\PROCESSES.DLL
- %PROGRAMFILES%\SMART SUGGESTOR\RESTARTIE.EXE
- %PROGRAMFILES%\SMART SUGGESTOR\SMBARBROKER.EXE
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI