Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28e27ee0-ea1d-454f-bf25-1c286e722367}]
- %ProgramFiles%\GoSavue\S1puovXDNrKQvw.x64.dll
- %ProgramFiles%\GoSavue\S1puovXDNrKQvw.dat
- %ALLUSERSPROFILE%\Application Data\GoSavue\OlOJeRNLeNF3wOP.exe
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{C87834EB-A2A0-B9D4-AA9A-C263D1191051}.20180216185120
- %ALLUSERSPROFILE%\Application Data\GoSavue\OlOJeRNLeNF3wOP.dat
- %ProgramFiles%\GoSavue\S1puovXDNrKQvw.tlb
- %TEMP%\3ed91c90\S1puovXDNrKQvw.dll
- %TEMP%\3ed91c90\OlOJeRNLeNF3wOP.dat
- %TEMP%\3ed91c90\S1puovXDNrKQvw.tlb
- %ProgramFiles%\GoSavue\S1puovXDNrKQvw.dll
- %TEMP%\3ed91c90\S1puovXDNrKQvw.x64.dll
- %TEMP%\3ed91c90\S1puovXDNrKQvw.tlb
- %TEMP%\3ed91c90\S1puovXDNrKQvw.x64.dll
- %TEMP%\3ed91c90\OlOJeRNLeNF3wOP.dat
- %TEMP%\3ed91c90\S1puovXDNrKQvw.dll
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\GoSavue\S1puovXDNrKQvw.x64.dll"