Creates and executes the following:
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\run.vbs"
Executes the following:
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\svchost.exe' -k LocalService
- '<SYSTEM32>\cmd.exe' /S /D /c" VER "
- '<SYSTEM32>\attrib.exe' +s +h C:\AppCache\x86
- '<SYSTEM32>\findstr.exe' /L "5."
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\installer.bat" "
- '%TEMP%\heramhesluliolruxqutd.exe' -p17622821125216577122667136616131185622569850811423517294207314116274152607151671012525521619973592100711739663916185
- '<SYSTEM32>\chcp.com' 1252
- '<SYSTEM32>\svchost.exe' -k rpcss
- '<SYSTEM32>\taskkill.exe' /f /im svchost.exe
Terminates or attempts to terminate
the following system processes:
Attempts to shut down the Windows operating system.