Technical Information
- %TEMP%\nsdccb2.tmp
- %TEMP%\popularity.accdb
- %TEMP%\orlando.accdb
- %TEMP%\su.accdb
- %TEMP%\value.accdb
- %TEMP%\nsncd8d.tmp\nsexec.dll
- %TEMP%\cattle
- %TEMP%\sic
- %TEMP%\finance
- %TEMP%\singh
- %TEMP%\millions
- %TEMP%\journalists
- %TEMP%\ev
- %TEMP%\cases
- %TEMP%\leonard
- %TEMP%\entities
- %TEMP%\535185\commodities.pif
- %TEMP%\535185\f
- %TEMP%\535185\f
- DNS ASK Wu#####JLj.WusOCuXJLj
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%TEMP%\535185\commodities.pif' f
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Value.accdb
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' "SophosHealth nsWscSvc ekrn bdservicehost AvastUI AVGUI & if not errorlevel 1 Set svLhnjAjHMvViQZZXOufeuARb=AutoIt3.exe & Set BtwxVCoeIB=.a3x & Set lAHQmUjJEoQjOqdVTADYyfsYAQTTenddZ=300
- '%WINDIR%\syswow64\extrac32.exe' /Y Popularity.accdb *.*
- '%WINDIR%\syswow64\findstr.exe' /V "turtle" Sic
- '%WINDIR%\syswow64\waitfor.exe' /T 5 lAHQmUjJEoQjOqdVTADYyfsYAQTTenddZ
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Value.accdb' (with hidden window)