Technical Information
- 'C:\users\public\calc.exe'
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\hg32j.bat
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\kjh4ek\ndj34h.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1348
- <SYSTEM32>\wermgr.exe
- C:\users\public\hg32j.bat
- C:\users\public\calc.exe
- C:\users\public\kjh4ek\ndj34h.bat
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\927847.cvr
- %TEMP%\log4f57.tmp
- %TEMP%\log4f57.tmp
- '<SYSTEM32>\cmd.exe' /c mkdir C:\Users\Public\kjh4ek
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 1
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 1
- '<SYSTEM32>\wermgr.exe'
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\hg32j.bat' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\kjh4ek\ndj34h.bat' (with hidden window)