Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.x64.dll"
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{750cf53a-3cce-4ef2-ac2a-42d7bd3c52ea}']
- [<HKLM>\SOFTWARE\Classes\CLSID\{750cf53a-3cce-4ef2-ac2a-42d7bd3c52ea}\InprocServer32] '' = '%ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.dll'
- %ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.x64.dll
- %ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.dat
- %ALLUSERSPROFILE%\Application Data\GoSSave\sUjSmnaU71UxUxJ.exe
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{C87834EB-A2A0-B9D4-AA9A-C263D1191051}.20170218170216
- %ALLUSERSPROFILE%\Application Data\GoSSave\sUjSmnaU71UxUxJ.dat
- %ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.tlb
- %TEMP%\211f72df\DpVUCTFAim3QQJ.dll
- %TEMP%\211f72df\sUjSmnaU71UxUxJ.dat
- %TEMP%\211f72df\DpVUCTFAim3QQJ.tlb
- %ProgramFiles%\GoSSave\DpVUCTFAim3QQJ.dll
- %TEMP%\211f72df\DpVUCTFAim3QQJ.x64.dll
- %TEMP%\211f72df\DpVUCTFAim3QQJ.tlb
- %TEMP%\211f72df\DpVUCTFAim3QQJ.x64.dll
- %TEMP%\211f72df\sUjSmnaU71UxUxJ.dat
- %TEMP%\211f72df\DpVUCTFAim3QQJ.dll