Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6e15390-0a4b-4d24-b50b-d8b0291549a8}]
- %TEMP%\22f65255\knch2py8i5ctajk.dat
- %TEMP%\22f65255\ymrjwqmkx5cj1s.dll
- %TEMP%\22f65255\ymrjwqmkx5cj1s.tlb
- %TEMP%\22f65255\ymrjwqmkx5cj1s.x64.dll
- %ProgramFiles(x86)%\gosave\ymrjwqmkx5cj1s.dll
- %ProgramFiles(x86)%\gosave\ymrjwqmkx5cj1s.tlb
- %ProgramFiles(x86)%\gosave\ymrjwqmkx5cj1s.dat
- %ProgramFiles(x86)%\gosave\ymrjwqmkx5cj1s.x64.dll
- %ALLUSERSPROFILE%\gosave\knch2py8i5ctajk.exe
- %ALLUSERSPROFILE%\gosave\knch2py8i5ctajk.dat
- %ALLUSERSPROFILE%\62014baecb94d2f0\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20220620124612
- %TEMP%\22f65255\knch2py8i5ctajk.dat
- %TEMP%\22f65255\ymrjwqmkx5cj1s.dll
- %TEMP%\22f65255\ymrjwqmkx5cj1s.tlb
- %TEMP%\22f65255\ymrjwqmkx5cj1s.x64.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSaVe\ymRjWQmKX5cJ1s.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSaVe\ymRjWQmKX5cJ1s.x64.dll"