Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63c56ffe-2752-4036-9b40-718a86f38962}]
- %TEMP%\0f1b6c73\yujcgp0oyw4a84q.dat
- %TEMP%\0f1b6c73\zdp23ccatopkwz.dll
- %TEMP%\0f1b6c73\zdp23ccatopkwz.tlb
- %TEMP%\0f1b6c73\zdp23ccatopkwz.x64.dll
- %ProgramFiles(x86)%\gosave\zdp23ccatopkwz.dll
- %ProgramFiles(x86)%\gosave\zdp23ccatopkwz.tlb
- %ProgramFiles(x86)%\gosave\zdp23ccatopkwz.dat
- %ProgramFiles(x86)%\gosave\zdp23ccatopkwz.x64.dll
- %ALLUSERSPROFILE%\gosave\yujcgp0oyw4a84q.exe
- %ALLUSERSPROFILE%\gosave\yujcgp0oyw4a84q.dat
- %ALLUSERSPROFILE%\6f2f4e461663bb85\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20221003113356
- %TEMP%\0f1b6c73\yujcgp0oyw4a84q.dat
- %TEMP%\0f1b6c73\zdp23ccatopkwz.dll
- %TEMP%\0f1b6c73\zdp23ccatopkwz.tlb
- %TEMP%\0f1b6c73\zdp23ccatopkwz.x64.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\zdP23ccAtOpKWZ.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\zdP23ccAtOpKWZ.x64.dll"