Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\quzmuzwara.url
- %APPDATA%\microsoft\windows\start menu\programs\startupquzmuzwara.url
- jsc.exe
- %HOMEPATH%\documents\myadobeconfig\adobereader_82648.pif
- %HOMEPATH%\documents\myadobeconfig\lovepdfconverted
- %TEMP%\run.bat
- %LOCALAPPDATA%\wordgenius technologies\g
- %LOCALAPPDATA%\wordgenius technologies\swiftwrite.pif
- %LOCALAPPDATA%\wordgenius technologies\swiftwrite.js
- %HOMEPATH%\documents\myadobeconfig\jsc.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\jsc.exe.log
- '19#.#6.142.210':80
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- http://19#.#6.142.210/hts/KbHSX.html
- DNS ASK nb##############bvvLMhHdgigs.nbhkmKSQnaDrIkubbvvLMhHdgigs
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK mo#####.map.fastly.net
- '%HOMEPATH%\documents\myadobeconfig\adobereader_82648.pif' "%HOMEPATH%\Documents\MyAdobeConfig\LovePdfConverted"
- '%HOMEPATH%\documents\myadobeconfig\jsc.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\run.bat"" (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /k echo [InternetShortcut] > "%APPDATA%\Microsoft\Windows\Start Menu\Programs\StartupQuzMuzWara.url" & echo URL="%LOCALAPPDATA%\WordGenius Technologies\SwiftWrite.js" >> "%APPDATA%\Microsoft\Wi...