Technical Information
- https://gop2p.hb.bizmrg.com/go.zip as %localappdata%\go.zip
- <Current directory>\md5\data\@advancedkeysettingsnotification.png
- <Current directory>\md5\data\msprivs.dll
- <Current directory>\md5\data\msiwer.dll
- <Current directory>\md5\data\msimg32.dll
- <Current directory>\md5\data\msidntld.dll
- <Current directory>\md5\data\msidle.dll
- <Current directory>\md5\data\msidcrl40.dll
- <Current directory>\md5\data\msdxm.ocx
- <Current directory>\md5\data\msdtcspoffln.dll
- <Current directory>\md5\data\msdatsrc.tlb
- <Current directory>\md5\data\msctfime.ime
- <Current directory>\md5\data\mscat32.dll
- <Current directory>\md5\data\msafd.dll
- <Current directory>\md5\data\msrating.dll
- <Current directory>\md5\data\msralegacy.tlb
- <Current directory>\md5\data\mmres.dll
- <Current directory>\md5\data\mmc.exe.config
- <Current directory>\md5\data\microsoft.uev.syncconditions.dll
- <Current directory>\md5\data\microsoft.uev.smbsyncprovider.dll
- <Current directory>\md5\data\microsoft.uev.monitorsyncprovider.dll
- <Current directory>\md5\data\microsoft.uev.modernsync.dll
- <Current directory>\md5\data\microsoft.uev.agentdriverevents.dll
- <Current directory>\md5\data\microsoft-windowsphone-semanagementprovider.dll
- <Current directory>\md5\data\microsoft-windows-storage-tiering-events.dll
- <Current directory>\md5\data\microsoft-windows-processor-aggregator-events.dll
- <Current directory>\md5\data\microsoft-windows-power-cad-events.dll
- <Current directory>\md5\data\microsoft-windows-moshost.dll
- <Current directory>\md5\data\mprext.dll
- <Current directory>\md5\data\kbdturme.dll
- <Current directory>\md5\data\mssip32.dll
- <Current directory>\md5\data\rdpsaps.dll
- <Current directory>\md5\data\rdpcfgex.dll
- <Current directory>\md5\data\qedwipes.dll
- <Current directory>\md5\data\pstorec.dll
- <Current directory>\md5\data\pstask.dll
- <Current directory>\md5\data\psmodulediscoveryprovider.mof
- <Current directory>\md5\data\prflbmsg.dll
- <Current directory>\md5\data\pnpts.dll
- <Current directory>\md5\data\phoneutilres.dll
- <Current directory>\md5\data\phoneserviceres.dll
- <Current directory>\md5\data\perceptionsimulation.proxystubs.dll
- <Current directory>\md5\data\pcbp.rs
- <Current directory>\md5\data\pcaevts.dll
- <Current directory>\md5\data\panmap.dll
- <Current directory>\md5\data\osuninst.dll
- <Current directory>\md5\data\osksupport.dll
- <Current directory>\md5\data\onnxruntime.dll
- <Current directory>\md5\data\oleaccrc.dll
- <Current directory>\md5\data\oleacchooks.dll
- <Current directory>\md5\data\normaliz.dll
- <Current directory>\md5\data\nlsdl.dll
- <Current directory>\md5\data\netmsg.dll
- <Current directory>\md5\data\neth.dll
- <Current directory>\md5\data\nddeapi.dll
- <Current directory>\md5\data\muilanguagecleanup.dll
- <Current directory>\md5\data\mtxex.dll
- <Current directory>\md5\data\msxml6r.dll
- <Current directory>\md5\data\microsoft-windows-hal-events.dll
- <Current directory>\md5\data\moricons.dll
- <Current directory>\md5\data\mapsbtsvcproxy.dll
- <Current directory>\md5\data\mapcontrolstringsres.dll
- <Current directory>\md5\data\l_intl.nls
- <Current directory>\md5\data\kbdsyr2.dll
- <Current directory>\md5\data\kbdtiprd.dll
- <Current directory>\md5\data\kbdtiprc.dll
- <Current directory>\md5\data\kbdtifi2.dll
- <Current directory>\md5\data\kbdtifi.dll
- <Current directory>\md5\data\kbdth3.dll
- <Current directory>\md5\data\kbdth2.dll
- <Current directory>\md5\data\kbdth1.dll
- <Current directory>\md5\data\kbdth0.dll
- <Current directory>\md5\data\kbdtat.dll
- <Current directory>\md5\data\kbdtam99.dll
- <Current directory>\md5\data\kbdtajik.dll
- <Current directory>\md5\data\kbdtaile.dll
- <Current directory>\md5\data\kbdsyr1.dll
- <Current directory>\md5\data\kbdtuf.dll
- <Current directory>\md5\data\kbdsw09.dll
- <Current directory>\md5\data\kbdsw.dll
- <Current directory>\md5\data\kbdsp.dll
- <Current directory>\md5\data\kbdsorst.dll
- <Current directory>\md5\data\kbdsors1.dll
- <Current directory>\md5\data\kbdsorex.dll
- <Current directory>\md5\data\kbdsora.dll
- <Current directory>\md5\data\kbdsn1.dll
- <Current directory>\md5\data\kbdsmsno.dll
- <Current directory>\md5\data\kbdsmsfi.dll
- <Current directory>\md5\data\kbdsl1.dll
- <Current directory>\md5\data\kbdsl.dll
- <Current directory>\md5\data\reagenttask.dll
- <Current directory>\md5\data\msxml3r.dll
- <Current directory>\md5\data\kbdtuq.dll
- <Current directory>\md5\data\kbdughr.dll
- <Current directory>\md5\data\kbdtt102.dll
- <Current directory>\md5\data\lz32.dll
- <Current directory>\md5\data\lpksetupproxyserv.dll
- <Current directory>\md5\data\lpk.dll
- <Current directory>\md5\data\lltdres.dll
- <Current directory>\md5\data\laprxy.dll
- <Current directory>\md5\data\langcleanupsysprepaction.dll
- <Current directory>\md5\data\korean.uce
- <Current directory>\md5\data\kd.dll
- <Current directory>\md5\data\kbdycl.dll
- <Current directory>\md5\data\kbdycc.dll
- <Current directory>\md5\data\kbdyba.dll
- <Current directory>\md5\data\kbdyak.dll
- <Current directory>\md5\data\kbdwol.dll
- <Current directory>\md5\data\kbdvntc.dll
- <Current directory>\md5\data\kbduzb.dll
- <Current directory>\md5\data\kbdusx.dll
- <Current directory>\md5\data\kbdusr.dll
- <Current directory>\md5\data\kbdusl.dll
- <Current directory>\md5\data\kbdusa.dll
- <Current directory>\md5\data\kbdus.dll
- <Current directory>\md5\data\kbdurdu.dll
- <Current directory>\md5\data\kbdur1.dll
- <Current directory>\md5\data\kbdur.dll
- <Current directory>\md5\data\kbdukx.dll
- <Current directory>\md5\data\kbduk.dll
- <Current directory>\md5\data\kbdughr1.dll
- <Current directory>\md5\data\kbdtzm.dll
- <Current directory>\md5\data\regidle.dll
- <Current directory>\md5\data\remoteapplifetimemanagerproxystub.dll
- <Current directory>\md5\data\removedeviceelevated.dll
- <Current directory>\md5\data\ypl.exe
- <Current directory>\md5\data\xwizard.dtd
- <Current directory>\md5\data\xinput9_1_0.dll
- <Current directory>\md5\data\xaudio2_8.dll
- <Current directory>\md5\data\x3daudio1_0.dll
- <Current directory>\md5\data\wsmplpxy.dll
- <Current directory>\md5\data\wsmanconfig_schema.xml
- <Current directory>\md5\data\wshtcpip.dll
- <Current directory>\md5\data\wship6.dll
- <Current directory>\md5\data\wsclient.dll
- <Current directory>\md5\data\ws2help.dll
- <Current directory>\md5\data\wpprecorderum.dll
- <Current directory>\md5\data\wpportinglibrary.dll
- <Current directory>\md5\data\wpcmon.png
- <Current directory>\md5\data\wpcatltoast.png
- <Current directory>\md5\data\wmploc.dll
- <Current directory>\md5\data\wmi.dll
- <Current directory>\md5\data\wmerror.dll
- <Current directory>\md5\data\wmdrmsdk.dll
- <Current directory>\md5\data\wmcodecdspps.dll
- <Current directory>\md5\data\wlanutil.dll
- <Current directory>\md5\data\wlanhlp.dll
- <Current directory>\md5\data\winrssrv.dll
- <Current directory>\md5\data\windows.management.secureassessment.diagnostics.dll
- <Current directory>\md5\data\wiaextensionhost64.dll
- <Current directory>\md5\data\web.rs
- <Current directory>\md5\data\walletbackgroundserviceproxy.dll
- <Current directory>\bin.exe
- %TEMP%\557f.tmp\launch.exe
- <Current directory>\md5\data\kbdsg.dll
- %TEMP%\7f4987fb1a6e43d69e3e94b29eb75926\seed.txt
- %TEMP%\etilqs_gg4wi5d3a8fbokf
- %TEMP%\etilqs_rutdhmm3pqv66il
- %TEMP%\etilqs_zz5ps3ulj8mxer1
- %TEMP%\etilqs_qonkta9su0nhgww
- %TEMP%\etilqs_2sb61itb310kesy
- %TEMP%\etilqs_4mpsqmdw1rykw9o
- %TEMP%\7f4987fb1a6e43d69e3e94b29eb75926\stat.2908.log
- nul
- %TEMP%\7f4987fb1a6e43d69e3e94b29eb75926\yandexpacksetup.exe
- %TEMP%\is-uui9l.tmp\tile1_icon1.png
- %TEMP%\is-uui9l.tmp\tile1_background.jpg
- %TEMP%\is-uui9l.tmp\uninstall.png
- %TEMP%\is-uui9l.tmp\install.png
- %TEMP%\is-uui9l.tmp\exit.png
- %TEMP%\is-uui9l.tmp\autorun1.jpg
- %TEMP%\is-uui9l.tmp\setup1.jpg
- %TEMP%\is-uui9l.tmp\lockscreen.jpg
- %TEMP%\is-uui9l.tmp\light.png
- %TEMP%\is-uui9l.tmp\dark.png
- %TEMP%\is-uui9l.tmp\lockscreen_overlay.png
- %TEMP%\is-uui9l.tmp\logo.png
- %TEMP%\is-uui9l.tmp\botva2.dll
- %TEMP%\is-uui9l.tmp\isdone.dll
- %TEMP%\is-uui9l.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-uui9l.tmp\_isetup\_setup64.tmp
- %TEMP%\is-k8soe.tmp\launch.tmp
- %TEMP%\7f4987fb1a6e43d69e3e94b29eb75926\downloader.2304.log
- <Current directory>\md5\data\vpnsohdesktop.dll
- <Current directory>\md5\data\spwmp.dll
- <Current directory>\md5\data\uxlibres.dll
- <Current directory>\md5\data\spwizres.dll
- <Current directory>\md5\data\spnet.dll
- <Current directory>\md5\data\spmpm.dll
- <Current directory>\md5\data\softpub.dll
- <Current directory>\md5\data\simpdata.tlb
- <Current directory>\md5\data\shimeng.dll
- <Current directory>\md5\data\shiftjis.uce
- <Current directory>\md5\data\shfolder.dll
- <Current directory>\md5\data\sfc.dll
- <Current directory>\md5\data\settings.dat
- <Current directory>\md5\data\sensorscpl.dll
- <Current directory>\md5\data\sensapi.dll
- <Current directory>\md5\data\securityandmaintenance_error.png
- <Current directory>\md5\data\securityandmaintenance_alert.png
- <Current directory>\md5\data\securityandmaintenance.png
- <Current directory>\md5\data\security.dll
- <Current directory>\md5\data\scg726.acm
- <Current directory>\md5\data\scavengespace.xml
- <Current directory>\md5\data\sas.dll
- <Current directory>\md5\data\rpcns4.dll
- <Current directory>\md5\data\rootporterr.mof
- <Current directory>\md5\data\rnr20.dll
- <Current directory>\md5\data\riched32.dll
- <Current directory>\md5\data\respriimagelistlowcost
- <Current directory>\md5\data\respriimagelist
- <Current directory>\md5\data\resprihmimagelistlowcost
- <Current directory>\md5\data\resprihmimagelist
- <Current directory>\md5\data\rendezvoussession.tlb
- <Current directory>\md5\data\spwinsat.dll
- %TEMP%\etilqs_qebr5iwtbqhgjjb
- <Current directory>\md5\data\usbperf.dll
- <Current directory>\md5\data\srevents.dll
- <Current directory>\md5\data\uimanagerbrokerps.dll
- <Current directory>\md5\data\uevcustomactiontypes.tlb
- <Current directory>\md5\data\tzsyncres.dll
- <Current directory>\md5\data\tzres.dll
- <Current directory>\md5\data\txfw32.dll
- <Current directory>\md5\data\ttdloader.dll
- <Current directory>\md5\data\tsusbredirectiongrouppolicyextension.dll
- <Current directory>\md5\data\tserrredir.dll
- <Current directory>\md5\data\tsbyuv.dll
- <Current directory>\md5\data\transformppstowlan.xslt
- <Current directory>\md5\data\tpmcertresources.dll
- <Current directory>\md5\data\timesynctask.dll
- <Current directory>\md5\data\timedatemuicallback.dll
- <Current directory>\md5\data\tier2punctuations.dll
- <Current directory>\md5\data\tetheringieprovider.dll
- <Current directory>\md5\data\telephonyinteractiveuserres.dll
- <Current directory>\md5\data\tapiui.dll
- <Current directory>\md5\data\tapisysprep.dll
- <Current directory>\md5\data\tapiperf.dll
- <Current directory>\md5\data\sysprtj.sep
- <Current directory>\md5\data\sysprint.sep
- <Current directory>\md5\data\syncres.dll
- <Current directory>\md5\data\synchostps.dll
- <Current directory>\md5\data\svsvc.dll
- <Current directory>\md5\data\stdole32.tlb
- <Current directory>\md5\data\sscoreext.dll
- <Current directory>\md5\data\srms-apr-v.dat
- <Current directory>\md5\data\userdataaccessres.dll
- %TEMP%\557f.tmp\5580.tmp\5581.bat
- <Current directory>\md5\data\kbdsf.dll
- <Current directory>\md5\data\kbdmlt48.dll
- <Current directory>\md5\data\iumdll.dll
- <Current directory>\md5\data\iscsied.dll
- <Current directory>\md5\data\iprtprio.dll
- <Current directory>\md5\data\iologmsg.dll
- <Current directory>\md5\data\imagesp1.dll
- <Current directory>\md5\data\imageres.dll
- <Current directory>\md5\data\idndl.dll
- <Current directory>\md5\data\iconcodecservice.dll
- <Current directory>\md5\data\icmp.dll
- <Current directory>\md5\data\hostguardianserviceclientresources.dll
- <Current directory>\md5\data\hnsproxy.dll
- <Current directory>\md5\data\hgclientserviceps.dll
- <Current directory>\md5\data\kanji_2.uce
- <Current directory>\md5\data\kanji_1.uce
- <Current directory>\md5\data\gamechatoverlayext.dll
- <Current directory>\md5\data\gamebarpresencewriter.proxy.dll
- <Current directory>\md5\data\fxsevent.dll
- <Current directory>\md5\data\firewall.cpl
- <Current directory>\md5\data\fdbthproxy.dll
- <Current directory>\md5\data\familysafetyext.dll
- <Current directory>\md5\data\f989b52d-f928-44a3-9bf1-bf0c1da6a0d6_hyperv-devicevirtualization.dll
- <Current directory>\md5\data\f3ahvoas.dll
- <Current directory>\md5\data\f1db7d81-95be-4911-935a-8ab71629112a_vmsvcext_sys.dll
- <Current directory>\md5\data\etwcoreuicomponentsresources.dll
- <Current directory>\md5\data\easpolicymanagerbrokerps.dll
- <Current directory>\md5\data\dxmasf.dll
- <Current directory>\md5\data\getuname.dll
- <Current directory>\md5\data\clrhost.dll
- <Current directory>\md5\data\kbd101.dll
- <Current directory>\md5\data\kbdbu.dll
- <Current directory>\md5\data\kbdbr.dll
- <Current directory>\md5\data\kbdblr.dll
- <Current directory>\md5\data\kbdbhc.dll
- <Current directory>\md5\data\kbdbgph1.dll
- <Current directory>\md5\data\kbdbgph.dll
- <Current directory>\md5\data\kbdbene.dll
- <Current directory>\md5\data\kbdbe.dll
- <Current directory>\md5\data\kbdbash.dll
- <Current directory>\md5\data\kbdazst.dll
- <Current directory>\md5\data\kbdazel.dll
- <Current directory>\md5\data\kbdaze.dll
- <Current directory>\md5\data\kbdax2.dll
- <Current directory>\md5\data\kbdarmw.dll
- <Current directory>\md5\data\kbdarmty.dll
- <Current directory>\md5\data\kbdarmph.dll
- <Current directory>\md5\data\kbdarme.dll
- <Current directory>\md5\data\kbdal.dll
- <Current directory>\md5\data\kbdadlm.dll
- <Current directory>\md5\data\kbda3.dll
- <Current directory>\md5\data\kbda2.dll
- <Current directory>\md5\data\kbda1.dll
- <Current directory>\md5\data\kbd106n.dll
- <Current directory>\md5\data\kbd106.dll
- <Current directory>\md5\data\kbd103.dll
- <Current directory>\md5\data\kbd101c.dll
- <Current directory>\md5\data\kbd101b.dll
- <Current directory>\md5\data\drtmauthtxt.wim
- <Current directory>\md5\data\gamestreamingext.dll
- <Current directory>\md5\data\dpnlobby.dll
- <Current directory>\md5\data\dpnhupnp.dll
- <Current directory>\md5\data\dpnhpast.dll
- <Current directory>\md5\data\asferror.dll
- <Current directory>\md5\data\c4d66f00-b6f0-4439-ac9b-c5ea13fe54d7_hyperv-computecore.dll
- <Current directory>\md5\data\browseui.dll
- <Current directory>\md5\data\bridgeres.dll
- <Current directory>\md5\data\bootstr.dll
- <Current directory>\md5\data\bluetoothpairingsystemtoasticon.png
- <Current directory>\md5\data\bluetoothpairingsystemtoasticon.contrast-white.png
- <Current directory>\md5\data\bluetoothpairingsystemtoasticon.contrast-high.png
- <Current directory>\md5\data\bluetoothpairingsystemtoasticon.contrast-black.png
- <Current directory>\md5\data\blbres.dll
- <Current directory>\md5\data\bdesysprep.dll
- <Current directory>\md5\data\bamsettingsclient.dll
- <Current directory>\md5\data\assignedaccessproviderevents.dll
- <Current directory>\md5\data\appxprovisioning.xml
- <Current directory>\md5\data\chxreadingstringime.dll
- <Current directory>\md5\data\appvsentinel.dll
- <Current directory>\md5\data\appvetwstreamingux.dll
- <Current directory>\md5\data\apprepapi.dll
- <Current directory>\md5\data\appinfoext.dll
- <Current directory>\md5\data\aphostres.dll
- <Current directory>\md5\data\amsiproxy.dll
- <Current directory>\md5\data\advapi32res.dll
- <Current directory>\md5\data\acxtrnal.dll
- <Current directory>\md5\data\activehours.png
- <Current directory>\md5\data\acproxy.dll
- <Current directory>\md5\data\acledit.dll
- <Current directory>\md5\data\@edptoastimage.png
- <Current directory>\md5\data\kbdbug.dll
- <Current directory>\md5\data\kbd101a.dll
- <Current directory>\md5\data\circoinst.dll
- <Current directory>\md5\data\computelibeventlog.dll
- <Current directory>\md5\data\cfmifsproxy.dll
- <Current directory>\md5\data\dpnet.dll
- <Current directory>\md5\data\dpnathlp.dll
- <Current directory>\md5\data\dpnaddr.dll
- <Current directory>\md5\data\dpapi.dll
- <Current directory>\md5\data\dockinterface.proxystub.dll
- <Current directory>\md5\data\dnsext.dll
- <Current directory>\md5\data\dmiso8601utils.dll
- <Current directory>\md5\data\dmdskres2.dll
- <Current directory>\md5\data\dmdskres.dll
- <Current directory>\md5\data\dmcommandlineutils.dll
- <Current directory>\md5\data\dmappsres.dll
- <Current directory>\md5\data\dmalertlistener.proxystub.dll
- <Current directory>\md5\data\djctq.rs
- <Current directory>\md5\data\dhcpcmonitor.dll
- <Current directory>\md5\data\deviceuxres.dll
- <Current directory>\md5\data\detailedreading-default.xml
- <Current directory>\md5\data\desktopview.internal.broker.proxystub.dll
- <Current directory>\md5\data\deliveryoptimizationmiprov.mof
- <Current directory>\md5\data\defragres.dll
- <Current directory>\md5\data\dciman32.dll
- <Current directory>\md5\data\d4d78066-e6db-44b7-b5cd-2eb82dce620c_hyperv-computelegacy.dll
- <Current directory>\md5\data\d3d8thk.dll
- <Current directory>\md5\data\c_iscii.dll
- <Current directory>\md5\data\c_gsm7.dll
- <Current directory>\md5\data\coreaudiopolicymanagerext.dll
- <Current directory>\md5\data\comres.dll
- <Current directory>\md5\data\comcat.dll
- <Current directory>\md5\data\kbdbulg.dll
- <Current directory>\md5\data\kbdca.dll
- <Current directory>\md5\data\kbdcan.dll
- <Current directory>\md5\data\kbdmaori.dll
- <Current directory>\md5\data\kbdmacst.dll
- <Current directory>\md5\data\kbdmac.dll
- <Current directory>\md5\data\kbdlvst.dll
- <Current directory>\md5\data\kbdlv1.dll
- <Current directory>\md5\data\kbdlv.dll
- <Current directory>\md5\data\kbdlt2.dll
- <Current directory>\md5\data\kbdlt1.dll
- <Current directory>\md5\data\kbdlt.dll
- <Current directory>\md5\data\kbdlk41a.dll
- <Current directory>\md5\data\kbdlisus.dll
- <Current directory>\md5\data\kbdlisub.dll
- <Current directory>\md5\data\kbdlao.dll
- <Current directory>\md5\data\kbdla.dll
- <Current directory>\md5\data\kbdkyr.dll
- <Current directory>\md5\data\kbdkurd.dll
- <Current directory>\md5\data\kbdkor.dll
- <Current directory>\md5\data\kbdkni.dll
- <Current directory>\md5\data\kbdkhmr.dll
- <Current directory>\md5\data\kbdkaz.dll
- <Current directory>\md5\data\kbdjpn.dll
- <Current directory>\md5\data\kbdjav.dll
- <Current directory>\md5\data\kbdiulat.dll
- <Current directory>\md5\data\kbdit142.dll
- <Current directory>\md5\data\kbdit.dll
- <Current directory>\md5\data\kbdir.dll
- <Current directory>\md5\data\kbdinuk2.dll
- <Current directory>\md5\data\kbdmlt47.dll
- <Current directory>\md5\data\kbdmon.dll
- <Current directory>\md5\data\kbdrum.dll
- <Current directory>\md5\data\kbdmonmo.dll
- <Current directory>\md5\data\kbdru.dll
- <Current directory>\md5\data\kbdrost.dll
- <Current directory>\md5\data\kbdropr.dll
- <Current directory>\md5\data\kbdro.dll
- <Current directory>\md5\data\kbdpo.dll
- <Current directory>\md5\data\kbdpl1.dll
- <Current directory>\md5\data\kbdpl.dll
- <Current directory>\md5\data\kbdphags.dll
- <Current directory>\md5\data\kbdpash.dll
- <Current directory>\md5\data\kbdosm.dll
- <Current directory>\md5\data\kbdosa.dll
- <Current directory>\md5\data\kbdoldit.dll
- <Current directory>\md5\data\kbdolch.dll
- <Current directory>\md5\data\kbdogham.dll
- <Current directory>\md5\data\kbdntl.dll
- <Current directory>\md5\data\kbdnso.dll
- <Current directory>\md5\data\kbdno1.dll
- <Current directory>\md5\data\kbdno.dll
- <Current directory>\md5\data\kbdnko.dll
- <Current directory>\md5\data\kbdnepr.dll
- <Current directory>\md5\data\kbdnecnt.dll
- <Current directory>\md5\data\kbdnecat.dll
- <Current directory>\md5\data\kbdnec95.dll
- <Current directory>\md5\data\kbdnec.dll
- <Current directory>\md5\data\kbdne.dll
- <Current directory>\md5\data\kbdmyan.dll
- <Current directory>\md5\data\kbdmonst.dll
- <Current directory>\md5\data\kbdintel.dll
- <Current directory>\md5\data\kbdgr1.dll
- <Current directory>\md5\data\kbdintam.dll
- <Current directory>\md5\data\kbdgr.dll
- <Current directory>\md5\data\kbdgkl.dll
- <Current directory>\md5\data\kbdgeoqw.dll
- <Current directory>\md5\data\kbdgeooa.dll
- <Current directory>\md5\data\kbdgeome.dll
- <Current directory>\md5\data\kbdgeoer.dll
- <Current directory>\md5\data\kbdgeo.dll
- <Current directory>\md5\data\kbdgae.dll
- <Current directory>\md5\data\kbdfthrk.dll
- <Current directory>\md5\data\kbdfr.dll
- <Current directory>\md5\data\kbdfo.dll
- <Current directory>\md5\data\kbdfi1.dll
- <Current directory>\md5\data\kbdfi.dll
- <Current directory>\md5\data\kbdfc.dll
- <Current directory>\md5\data\kbdfar.dll
- <Current directory>\md5\data\kbdfa.dll
- <Current directory>\md5\data\kbdest.dll
- <Current directory>\md5\data\kbdes.dll
- <Current directory>\md5\data\kbddzo.dll
- <Current directory>\md5\data\kbddv.dll
- <Current directory>\md5\data\kbddiv2.dll
- <Current directory>\md5\data\kbddiv1.dll
- <Current directory>\md5\data\kbdda.dll
- <Current directory>\md5\data\kbdcz2.dll
- <Current directory>\md5\data\kbdcz1.dll
- <Current directory>\md5\data\kbdcz.dll
- <Current directory>\md5\data\kbdcr.dll
- <Current directory>\md5\data\kbdcher.dll
- <Current directory>\md5\data\kbdgn.dll
- <Current directory>\md5\data\kbdru1.dll
- <Current directory>\md5\data\kbdinori.dll
- <Current directory>\md5\data\kbdgrlnd.dll
- <Current directory>\md5\data\kbdinmar.dll
- <Current directory>\md5\data\kbdinmal.dll
- <Current directory>\md5\data\kbdinkan.dll
- <Current directory>\md5\data\kbdinhin.dll
- <Current directory>\md5\data\kbdinguj.dll
- <Current directory>\md5\data\kbdinen.dll
- <Current directory>\md5\data\kbdindev.dll
- <Current directory>\md5\data\kbdinben.dll
- <Current directory>\md5\data\kbdinbe2.dll
- <Current directory>\md5\data\kbdinbe1.dll
- <Current directory>\md5\data\kbdinasa.dll
- <Current directory>\md5\data\kbdic.dll
- <Current directory>\md5\data\kbdibo.dll
- <Current directory>\md5\data\kbdibm02.dll
- <Current directory>\md5\data\kbdhu1.dll
- <Current directory>\md5\data\kbdhu.dll
- <Current directory>\md5\data\kbdhept.dll
- <Current directory>\md5\data\kbdhela3.dll
- <Current directory>\md5\data\kbdhela2.dll
- <Current directory>\md5\data\kbdhebl3.dll
- <Current directory>\md5\data\kbdheb.dll
- <Current directory>\md5\data\kbdhe319.dll
- <Current directory>\md5\data\kbdhe220.dll
- <Current directory>\md5\data\kbdhe.dll
- <Current directory>\md5\data\kbdhaw.dll
- <Current directory>\md5\data\kbdhau.dll
- <Current directory>\md5\data\kbdgthc.dll
- <Current directory>\md5\data\kbdinpun.dll
- %TEMP%\etilqs_feagqdxafxt99ep
- 'do#####der.yandex.net':80
- 'ca######m9-6.cdn.yandex.net':80
- 'ca######m9-1.cdn.yandex.net':80
- 'go###.hb.bizmrg.com':443
- 'ca#######9-11.cdn.yandex.net':80
- 'clck.yandex.ru':80
- 'au######te.geo.opera.com':80
- 'au######te.geo.opera.com':443
- 'google.com':80
- 'se####.yahoo.com':80
- 'du###uckgo.com':443
- 'am##on.com':80
- 'bing.com':80
- http://do#####der.yandex.net/yandex-pack/downloader/info.rss
- http://ca######m9-6.cdn.yandex.net/downloader.yandex.net/yandex-pack/downloader/info.rss?li#####
- http://do#####der.yandex.net/yandex-pack/87838/YandexPackSetup.exe
- http://ca######m9-1.cdn.yandex.net/downloader.yandex.net/yandex-pack/87838/YandexPackSetup.exe?li#####
- http://ca#######9-11.cdn.yandex.net/downloader.yandex.net/yandex-pack/87838/YandexPackSetup.exe?li#####
- http://ca######m9-6.cdn.yandex.net/downloader.yandex.net/yandex-pack/87838/YandexPackSetup.exe?li#####
- http://clck.yandex.ru/click/dtype=stred/pid=12/cid=72435/path=dwnldr/p=87838/fail=1/imp=0/*
- http://au######te.geo.opera.com/geolocation/
- http://www.google.com/favicon.ico
- http://www.am##on.com/favicon.ico
- http://www.bing.com/s/a/bing_p.ico
- http://se####.yahoo.com/favicon.ico
- 'go###.hb.bizmrg.com':443
- 'au######te.geo.opera.com':443
- 'du###uckgo.com':443
- DNS ASK do#####der.yandex.net
- DNS ASK ca######m9-6.cdn.yandex.net
- DNS ASK ca######m9-1.cdn.yandex.net
- DNS ASK go###.hb.bizmrg.com
- DNS ASK ca#######9-11.cdn.yandex.net
- DNS ASK clck.yandex.ru
- DNS ASK google.com
- DNS ASK au######te.geo.opera.com
- DNS ASK se####.yahoo.com
- DNS ASK du###uckgo.com
- DNS ASK am##on.com
- DNS ASK bing.com
- DNS ASK bi##.#ikimedia.org
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Opera Software\Opera Stable'
- '<Current directory>\md5\data\ypl.exe'
- '<Current directory>\bin.exe'
- '%TEMP%\557f.tmp\launch.exe'
- '%TEMP%\is-k8soe.tmp\launch.tmp' /SL5="$B027A,6801652,227840,%TEMP%\557F.tmp\Launch.exe"
- '<Current directory>\md5\data\ypl.exe' --stat dwnldr/p=87838/fail=1
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\557F.tmp\5580.tmp\5581.bat <Current directory>\bin.exe"' (with hidden window)
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect/OTExNTI1"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="584.0.1265553155\1887133639" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="1100.0.105695884\12477357" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-d...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --disable-client-side-phishing-...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --extension-process --enable-we...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.4.1625895211\178397020" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.5.949994099\1168634469" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.6.1154919370\973691629" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-4
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.7.258890472\592554580" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.8.1494979117\1640613383" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.9.1882035542\2053064359" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.10.988903905\1516083902" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.11.517932320\1636940217" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.12.1290945587\2078139044" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.13.163911379\1723186285" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.14.866975619\1639818545" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="1412.0.1594158094\547020290" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="3252.0.1693966641\1998478200" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gp...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="1772.0.2113255662\600741656" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="324.0.508675780\1343262061" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-...
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 127.0.0.1
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect-2"
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect-3"
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect-4"
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect-5"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\557F.tmp\5580.tmp\5581.bat <Current directory>\bin.exe"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-5
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-1
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1412.15.1430078406\627699148" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' --type=utility --channel="1412.4.1625895211\178397020" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001 /crash-reporter-parent-id=4000
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-2
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect/OTExNTI1
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-5 /crash-reporter-parent-id=324
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect/OTExNTI1 /crash-reporter-parent-id=3252
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-4 /crash-reporter-parent-id=1100
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-1 /crash-reporter-parent-id=1772
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-3 /crash-reporter-parent-id=1412
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-2 /crash-reporter-parent-id=584
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://amazingwonderful.com/redirect-1"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://amazingwonderful.com/redirect-3
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -n 1 -w 1000 127.0.0.1