Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{434ae6ef-0977-471f-b3e8-23411e6d6952}]
- %TEMP%\5065618e\gGvcI9RgDuF2TC1.dat
- %TEMP%\5065618e\TFjlaCppyhYxAa.dll
- %TEMP%\5065618e\TFjlaCppyhYxAa.tlb
- %TEMP%\5065618e\TFjlaCppyhYxAa.x64.dll
- %ProgramFiles%\ppriceChoP\TFjlaCppyhYxAa.dll
- %ProgramFiles%\ppriceChoP\TFjlaCppyhYxAa.tlb
- %ProgramFiles%\ppriceChoP\TFjlaCppyhYxAa.dat
- %ProgramFiles%\ppriceChoP\TFjlaCppyhYxAa.x64.dll
- %ALLUSERSPROFILE%\Application Data\ppriceChoP\gGvcI9RgDuF2TC1.exe
- %ALLUSERSPROFILE%\Application Data\ppriceChoP\gGvcI9RgDuF2TC1.dat
- %ALLUSERSPROFILE%\Application Data\6e958a80feb239af\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20181114165122
- %TEMP%\5065618e\gGvcI9RgDuF2TC1.dat
- %TEMP%\5065618e\TFjlaCppyhYxAa.dll
- %TEMP%\5065618e\TFjlaCppyhYxAa.tlb
- %TEMP%\5065618e\TFjlaCppyhYxAa.x64.dll
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\ppriceChoP\TFjlaCppyhYxAa.x64.dll"