Technical Information
- %ALLUSERSPROFILE%\installer.exe
- <Current directory>\setup.exe
- %LOCALAPPDATA%\pdf_viewer\chrome\manifest.json
- %LOCALAPPDATA%\pdf_viewer\chrome\bg.js
- %LOCALAPPDATA%\pdf_viewer\chrome\icon.png
- %LOCALAPPDATA%\pdf_viewer\edge\manifest.json
- %LOCALAPPDATA%\pdf_viewer\edge\bg.js
- %LOCALAPPDATA%\pdf_viewer\edge\icon.png
- %LOCALAPPDATA%\pdf_viewer\opera_stable\manifest.json
- %LOCALAPPDATA%\pdf_viewer\opera_stable\bg.js
- %LOCALAPPDATA%\pdf_viewer\opera_stable\icon.png
- %TEMP%\is-hfah9.tmp\setup.tmp
- %LOCALAPPDATA%\google\chrome\user data\default\secure preferences
- %LOCALAPPDATA%\microsoft\edge\user data\default\secure preferences
- 'st####zzer.online':443
- DNS ASK st####zzer.online
- '%ALLUSERSPROFILE%\installer.exe'
- '<Current directory>\setup.exe'
- '%TEMP%\is-hfah9.tmp\setup.tmp' /SL5="$9016E,6726017,527360,<Current directory>\Setup.exe"
- '%ALLUSERSPROFILE%\installer.exe' ' (with hidden window)