We received the file CT3286042.XPI and detected that CT3286042.XPI is not good.
CT3286042.XPI is Adware. You should remove the file CT3286042.XPI.
Kill the process CT3286042.XPI and remove CT3286042.XPI from Windows.
Malware Analysis of CT3286042.XPI
Full path on a computer: %TEMP%\CT3286042\CT3286042.XPI
Detected by UnHackMe:
CT3286042.XPI
Default location: %TEMP%\CT3286042\CT3286042.XPI
Removal Results: Success
Number of reboot: 1
CT3286042.XPI is known as:
Adware.Toolbar
How to quickly detect CT3286042.XPI presence?
Files:
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{9ED31F84-C8B3-4926-B950-DFF74047FF79}\CHROME\CT3286042\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\GADGET.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{9ED31F84-C8B3-4926-B950-DFF74047FF79}\CHROME\CT3286042\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\JQUERY.JSCROLLPANE.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{9ED31F84-C8B3-4926-B950-DFF74047FF79}\CHROME\CT3286042\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\RESET.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{9ED31F84-C8B3-4926-B950-DFF74047FF79}\CHROME\CT3286042\CONTENT\TB\AL\WA\PRICE_GONG\PG_OFFERS.JS
- %TEMP%\CT3286042\CT3286042.XPI