We received the file CT3289847.XPI and detected that CT3289847.XPI is not good.
CT3289847.XPI is Adware. You should remove the file CT3289847.XPI.
Kill the process CT3289847.XPI and remove CT3289847.XPI from Windows.
Malware Analysis of CT3289847.XPI
Full path on a computer: %TEMP%\CT3289847\CT3289847.XPI
Detected by UnHackMe:
CT3289847.XPI
Default location: %TEMP%\CT3289847\CT3289847.XPI
Removal Results: Success
Number of reboot: 1
CT3289847.XPI is known as:
Adware.Toolbar
How to quickly detect CT3289847.XPI presence?
Files:
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}\CHROME\CT3289847\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\GADGET.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}\CHROME\CT3289847\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\JQUERY.JSCROLLPANE.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}\CHROME\CT3289847\CONTENT\TB\AL\WA\RADIO_PLAYER\CSS\RESET.CSS
- %APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}\CHROME\CT3289847\CONTENT\TB\AL\WA\PRICE_GONG\PG_OFFERS.JS
- %TEMP%\CT3289847\CT3289847.XPI