Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63C07E6A-1623-ACC2-4CC4-2CE9D0B7941D}]
- %TEMP%\7dc14f8d\rfoasjterf.dat
- %TEMP%\7dc14f8d\x57clrihc.x64.dll
- %TEMP%\7dc14f8d\x57clrihc.tlb
- %TEMP%\7dc14f8d\x57clrihc.dll
- %ProgramFiles(x86)%\gosave\x57clrihc.dll
- %ProgramFiles(x86)%\gosave\x57clrihc.tlb
- %ProgramFiles(x86)%\gosave\x57clrihc.dat
- %ProgramFiles(x86)%\gosave\x57clrihc.x64.dll
- %ALLUSERSPROFILE%\gosave\rfoasjterf.exe
- %ALLUSERSPROFILE%\gosave\rfoasjterf.dat
- %ALLUSERSPROFILE%\5e6818b986311eca\{c87834eb-a2a0-b9d4-aa9a-c263d1191051}.20221002154042
- %TEMP%\7dc14f8d\rfoasjterf.dat
- %TEMP%\7dc14f8d\x57clrihc.x64.dll
- %TEMP%\7dc14f8d\x57clrihc.tlb
- %TEMP%\7dc14f8d\x57clrihc.dll
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\X57CLrihC.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\GoSave\X57CLrihC.x64.dll"