Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a91120dd-6ab3-4639-92f2-18ca4e057d4b}]
- %TEMP%\49202f7b\qluknmhehods7lc.dat
- %TEMP%\49202f7b\zftfibkwgy7mvg.dll
- %TEMP%\49202f7b\zftfibkwgy7mvg.tlb
- %TEMP%\49202f7b\zftfibkwgy7mvg.x64.dll
- %ProgramFiles(x86)%\ggoosavve\zftfibkwgy7mvg.dll
- %ProgramFiles(x86)%\ggoosavve\zftfibkwgy7mvg.tlb
- %ProgramFiles(x86)%\ggoosavve\zftfibkwgy7mvg.dat
- %ProgramFiles(x86)%\ggoosavve\zftfibkwgy7mvg.x64.dll
- %ALLUSERSPROFILE%\ggoosavve\qluknmhehods7lc.exe
- %ALLUSERSPROFILE%\ggoosavve\qluknmhehods7lc.dat
- %ALLUSERSPROFILE%\eb51433fd25f48c5\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20220420213555
- %TEMP%\49202f7b\qluknmhehods7lc.dat
- %TEMP%\49202f7b\zftfibkwgy7mvg.dll
- %TEMP%\49202f7b\zftfibkwgy7mvg.tlb
- %TEMP%\49202f7b\zftfibkwgy7mvg.x64.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GGooSavve\zftFIbkwgY7mvG.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GGooSavve\zftFIbkwgY7mvG.x64.dll"