Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\jgwADG.lnk
- '<SYSTEM32>\taskkill.exe' /F /IM cmd.exe
- '<SYSTEM32>\taskkill.exe' /F /IM wscript.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- <SYSTEM32>\cmd.exe
- <Current directory>\qvcf.hM
- %APPDATA%\dllhost.exe
- %APPDATA%uoCN.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut1.tmp
- ClassName: '' WindowName: 'AngarCl'
- ClassName: '' WindowName: ''
- '%APPDATA%\dllhost.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'