"GoogleUpdateSetup_1.3.21.169.exe" wrote 32 bytes to a remote process "C:\Program Files\GUMF036.tmp\GoogleUpdate.exe" (Handle: 148)
"GoogleUpdateSetup_1.3.21.169.exe" wrote 4 bytes to a remote process "C:\Program Files\GUMF036.tmp\GoogleUpdate.exe" (Handle: 148) "GoogleUpdateSetup_1.3.21.169.exe" wrote 1500 bytes to a remote process "C:\Program Files\GUMF036.tmp\GoogleUpdate.exe" (Handle: 148) "PF-Toolbar-2016.exe" wrote 52 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe" (Handle: 340) "PF-Toolbar-2016.exe" wrote 32 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe" (Handle: 340) "PF-Toolbar-2016.exe" wrote 4 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe" (Handle: 340) "PF-Toolbar-2016.exe" wrote 1500 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe" (Handle: 340) "nsCFB8.tmp" wrote 4 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "nsCFB8.tmp" wrote 52 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "nsCFB8.tmp" wrote 32 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "ns5890.tmp" wrote 4 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "ns5890.tmp" wrote 52 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "ns5890.tmp" wrote 32 bytes to a remote process "C:\Windows\System32\PING.EXE" (Handle: 68) "" wrote 52 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\g\PF-Toolbar-2016.exe" (Handle: 972) "" wrote 32 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\g\PF-Toolbar-2016.exe" (Handle: 972)
"" wrote 4 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\g\PF-Toolbar-2016.exe" (Handle: 972) "" wrote 1500 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\g\PF-Toolbar-2016.exe" (Handle: 972) "" wrote 4 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\nsCFB8.tmp" (Handle: 980) "" wrote 52 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\nsCFB8.tmp" (Handle: 980) "" wrote 32 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\nsCFB8.tmp" (Handle: 980) "" wrote 4 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\ns5890.tmp" (Handle: 536) "" wrote 52 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\nsn4899.tmp\ns5890.tmp" (Handle: 536) " Piriform Ltd true true ConsoleDisconnect S-1-5-11 -> HighestAvailable IgnoreNew false false true false false true