Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath '<Current directory>'
- <Current directory>\log\24-04-2026.log
- %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\uvou0lc3.newcfg
- %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\evycpnis.newcfg
- from %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\uvou0lc3.newcfg to %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\user.config
- from %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\evycpnis.newcfg to %LOCALAPPDATA%\futekВ®\<File name>.exe_url_ieyzy2npvagoclfgzlpefuz1nxhiz1zu\2025.0.0.0\user.config
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath '<Current directory>'' (with hidden window)