Техническая информация
- Процесс gkwu.exe, модуль KERNELBASE.dll
- Процесс gkwu.exe, модуль KERNEL32.dll
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f1315ffe-5d2e-4925-bce4-4dfbdd88aa48}]
- %TEMP%\3b5b73cb\qgdfjhafe4asjiu.dat
- %TEMP%\3b5b73cb\z0qoyxa2papcom.dll
- %TEMP%\3b5b73cb\z0qoyxa2papcom.tlb
- %TEMP%\3b5b73cb\z0qoyxa2papcom.x64.dll
- %TEMP%\3b5b73cb\rj@qe.net\content\bg.js
- %TEMP%\3b5b73cb\rj@qe.net\bootstrap.js
- %TEMP%\3b5b73cb\rj@qe.net\chrome.manifest
- %TEMP%\3b5b73cb\rj@qe.net\install.rdf
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\nsuytmp.js
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\background.html
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\manifest.json
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\content.js
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\defaultaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\defaultaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\defaultaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\defaultaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\defaultaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\wdagutilityaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\wdagutilityaccount\appdata\local\google\chrome\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\defaultaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\defaultaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\defaultaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\defaultaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\defaultaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\wdagutilityaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\wdagutilityaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\wdagutilityaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\wdagutilityaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\wdagutilityaccount\appdata\local\comodo\dragon\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\defaultaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\defaultaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\defaultaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\defaultaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\defaultaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\wdagutilityaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\wdagutilityaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\wdagutilityaccount\appdata\local\google\chrome sxs\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\administrator\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\administrator\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\defaultaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\defaultaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\defaultaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\defaultaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\defaultaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %LOCALAPPDATA%\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- %LOCALAPPDATA%\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- %LOCALAPPDATA%\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- %LOCALAPPDATA%\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\wdagutilityaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\wdagutilityaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\wdagutilityaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\wdagutilityaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\wdagutilityaccount\appdata\local\torch\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\defaultaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\defaultaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\defaultaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\defaultaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\defaultaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- C:\users\wdagutilityaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\background.html
- C:\users\wdagutilityaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\content.js
- C:\users\wdagutilityaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\lsdb.js
- C:\users\wdagutilityaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\manifest.json
- C:\users\wdagutilityaccount\appdata\local\chromatic browser\user data\default\extensions\jepmjmggmiffaofgmbbdnlikbkflbgnl\2.0\nsuytmp.js
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\extensions\staged\rj@qe.net\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\extensions\staged\rj@qe.net\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\extensions\staged\rj@qe.net\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\extensions\staged\rj@qe.net\install.rdf
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\extensions\staged\rj@qe.net\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\extensions\staged\rj@qe.net\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\extensions\staged\rj@qe.net\content\bg.js
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\extensions\staged\rj@qe.net\install.rdf
- %ProgramFiles(x86)%\ggoosaavie\z0qoyxa2papcom.dll
- %ProgramFiles(x86)%\ggoosaavie\z0qoyxa2papcom.tlb
- %ProgramFiles(x86)%\ggoosaavie\z0qoyxa2papcom.dat
- %ProgramFiles(x86)%\ggoosaavie\z0qoyxa2papcom.x64.dll
- %ALLUSERSPROFILE%\ggoosaavie\qgdfjhafe4asjiu.exe
- %ALLUSERSPROFILE%\ggoosaavie\qgdfjhafe4asjiu.dat
- %ALLUSERSPROFILE%\bb53d5760f18fce2\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20260225152456
- %TEMP%\3b5b73cb\qgdfjhafe4asjiu.dat
- %TEMP%\3b5b73cb\z0qoyxa2papcom.dll
- %TEMP%\3b5b73cb\z0qoyxa2papcom.tlb
- %TEMP%\3b5b73cb\z0qoyxa2papcom.x64.dll
- %TEMP%\3b5b73cb\rj@qe.net\content\bg.js
- %TEMP%\3b5b73cb\rj@qe.net\bootstrap.js
- %TEMP%\3b5b73cb\rj@qe.net\chrome.manifest
- %TEMP%\3b5b73cb\rj@qe.net\install.rdf
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\nsuytmp.js
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\background.html
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\manifest.json
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\content.js
- %TEMP%\3b5b73cb\jepmjmggmiffaofgmbbdnlikbkflbgnl\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\local state
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -s WPDBusEnum
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s fhsvc
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GGooSAAvie\Z0QoyXA2papcom.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GGooSAAvie\Z0QoyXA2papcom.x64.dll"