Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37c01be8-533d-4143-9f36-3c27372cabfd}]
- %TEMP%\31a9083a\JT2iHKPgWoOng3v.dat
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.dll
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.tlb
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.x64.dll
- %ProgramFiles%\GGoSave\ZS2yekbTIpsRb6.dll
- %ProgramFiles%\GGoSave\ZS2yekbTIpsRb6.tlb
- %ProgramFiles%\GGoSave\ZS2yekbTIpsRb6.dat
- %ProgramFiles%\GGoSave\ZS2yekbTIpsRb6.x64.dll
- %ALLUSERSPROFILE%\Application Data\GGoSave\JT2iHKPgWoOng3v.exe
- %ALLUSERSPROFILE%\Application Data\GGoSave\JT2iHKPgWoOng3v.dat
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{C87834EB-A2A0-B9D4-AA9A-C263D1191051}.20180517195518
- %TEMP%\31a9083a\JT2iHKPgWoOng3v.dat
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.dll
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.tlb
- %TEMP%\31a9083a\ZS2yekbTIpsRb6.x64.dll
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\GGoSave\ZS2yekbTIpsRb6.x64.dll"