Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.x64.dll"
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4dd43ca6-a1d1-467c-9b16-a76522826b94}']
- [<HKLM>\SOFTWARE\Classes\CLSID\{4dd43ca6-a1d1-467c-9b16-a76522826b94}\InprocServer32] '' = '%ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.dll'
- %ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.x64.dll
- %ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.dat
- %ALLUSERSPROFILE%\Application Data\GoSeaeve\kk6X2tBzNCX4kd3.exe
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{C87834EB-A2A0-B9D4-AA9A-C263D1191051}.20170323120421
- %ALLUSERSPROFILE%\Application Data\GoSeaeve\kk6X2tBzNCX4kd3.dat
- %ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.tlb
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.dll
- %TEMP%\4f724ffc\kk6X2tBzNCX4kd3.dat
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.tlb
- %ProgramFiles%\GoSeaeve\oEbfl0j4cJML1d.dll
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.x64.dll
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.tlb
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.x64.dll
- %TEMP%\4f724ffc\kk6X2tBzNCX4kd3.dat
- %TEMP%\4f724ffc\oEbfl0j4cJML1d.dll