Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6bac0825-8945-4408-8556-a7ca1c74ba8f}]
- %TEMP%\15597274\8jbj0gd7poyihgw.dat
- %TEMP%\15597274\q5zs9njem8vrhh.dll
- %TEMP%\15597274\q5zs9njem8vrhh.tlb
- %TEMP%\15597274\q5zs9njem8vrhh.x64.dll
- %ProgramFiles(x86)%\gosave\q5zs9njem8vrhh.dll
- %ProgramFiles(x86)%\gosave\q5zs9njem8vrhh.tlb
- %ProgramFiles(x86)%\gosave\q5zs9njem8vrhh.dat
- %ProgramFiles(x86)%\gosave\q5zs9njem8vrhh.x64.dll
- %ALLUSERSPROFILE%\gosave\8jbj0gd7poyihgw.exe
- %ALLUSERSPROFILE%\gosave\8jbj0gd7poyihgw.dat
- %ALLUSERSPROFILE%\835fa0985649862d\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20220814130912
- %TEMP%\15597274\8jbj0gd7poyihgw.dat
- %TEMP%\15597274\q5zs9njem8vrhh.dll
- %TEMP%\15597274\q5zs9njem8vrhh.tlb
- %TEMP%\15597274\q5zs9njem8vrhh.x64.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\q5zS9Njem8VRhh.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\q5zS9Njem8VRhh.x64.dll"