Creates the following files
- %TEMP%\app1.exe
- %TEMP%\rarsfx0\system.io.compression.dll
- %TEMP%\rarsfx0\system.memory.dll
- %TEMP%\rarsfx0\system.memory.xml
- %TEMP%\rarsfx0\system.numerics.vectors.dll
- %TEMP%\rarsfx0\system.numerics.vectors.xml
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.dll
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.xml
- %TEMP%\rarsfx0\x64\sqlite.interop.dll
- %APPDATA%\factoryprotectionsolution\mercurys.dll
- %TEMP%\rarsfx0\x86\sqlite.interop.dll
- %TEMP%\rarsfx0\bouncycastle.crypto.xml
- %TEMP%\rarsfx0\newtonsoft.json.dll
- %TEMP%\rarsfx0\newtonsoft.json.xml
- %APPDATA%\stealer\desktop\docs\february_catalogue__2015.doc
- %APPDATA%\stealer\desktop\docs\lisp_success.doc
- %APPDATA%\stealer\desktop\docs\nwfieldnotes1966.docx
- %APPDATA%\stealer\desktop\docs\weeklysheet1215.doc
- %APPDATA%\stealer\pcinfo.txt
- %TEMP%\rarsfx0\system.data.sqlite.dll
- %TEMP%\rarsfx0\system.data.sqlite.xml
- %TEMP%\rarsfx0\system.buffers.xml
- %TEMP%\rarsfx0\system.buffers.dll
- %TEMP%\rarsfx0\svc_host.pdb
- %APPDATA%\factoryprotectionsolution\factoryprotectiontool.exe
- %APPDATA%\factoryprotectionsolution\png.xs.dll
- %APPDATA%\factoryprotectionsolution\zlib.xs.dll
- %APPDATA%\factoryprotectionsolution\config.xml
- %APPDATA%\factoryprotectionsolution\freeglut.dll
- %APPDATA%\factoryprotectionsolution\libgraph23.dll
- %APPDATA%\factoryprotectionsolution\libopennas2.dll
- %APPDATA%\factoryprotectionsolution\license.txt
- %APPDATA%\stealer\screenshot.png
- %TEMP%\rarsfx0\bouncycastle.crypto.dll
- %APPDATA%\factoryprotectionsolution\lua52.dll
- %APPDATA%\factoryprotectionsolution\msvcp140_2.dll
- %APPDATA%\factoryprotectionsolution\php_sodium.dll
- %APPDATA%\factoryprotectionsolution\zlib1.dll
- %TEMP%\steam.exe
- %HOMEPATH%\09368f65836
- %TEMP%\sbvc.exe
- %TEMP%\rarsfx0\svc_host.exe
- %TEMP%\rarsfx0\svc_host.exe.config
- %TEMP%\app2.exe
- %APPDATA%\factoryprotectionsolution\msvcm90.dll
- %APPDATA%\95.211.190.198.zip
Sets the 'hidden' attribute to the following files
- %TEMP%\app1.exe
- %TEMP%\steam.exe
Deletes the following files
- %APPDATA%\95.211.190.198.zip
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.xml
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.dll
- %TEMP%\rarsfx0\system.numerics.vectors.xml
- %TEMP%\rarsfx0\system.numerics.vectors.dll
- %TEMP%\rarsfx0\system.memory.xml
- %TEMP%\rarsfx0\system.memory.dll
- %TEMP%\rarsfx0\system.io.compression.dll
- %TEMP%\rarsfx0\system.data.sqlite.xml
- %TEMP%\rarsfx0\system.data.sqlite.dll
- %TEMP%\rarsfx0\system.buffers.xml
- %TEMP%\rarsfx0\system.buffers.dll
- %TEMP%\rarsfx0\x64\sqlite.interop.dll
- %TEMP%\rarsfx0\svc_host.pdb
- %TEMP%\rarsfx0\svc_host.exe
- %TEMP%\rarsfx0\newtonsoft.json.xml
- %TEMP%\rarsfx0\newtonsoft.json.dll
- %TEMP%\rarsfx0\bouncycastle.crypto.xml
- %TEMP%\rarsfx0\bouncycastle.crypto.dll
- %APPDATA%\stealer\screenshot.png
- %APPDATA%\stealer\pcinfo.txt
- %APPDATA%\stealer\desktop\docs\weeklysheet1215.doc
- %APPDATA%\stealer\desktop\docs\nwfieldnotes1966.docx
- %APPDATA%\stealer\desktop\docs\lisp_success.doc
- %APPDATA%\stealer\desktop\docs\february_catalogue__2015.doc
- %TEMP%\rarsfx0\svc_host.exe.config
- %TEMP%\rarsfx0\x86\sqlite.interop.dll