Technical Information
- <SYSTEM32>\tasks\mega\megacmd update task s-1-5-21-1960123792-2022915161-3775307078-1001
- %TEMP%\7zipsfx.000\images\ico.ico
- %TEMP%\7zipsfx.000\megacmd\_win_office_activators.bat
- %TEMP%\7zipsfx.000\megacmd\_win_office_activators.vbs
- %TEMP%\7zipsfx.000\megacmd\_win_spy_disabler.bat
- %TEMP%\7zipsfx.000\megacmd\_win_spy_disabler.vbs
- %TEMP%\7zipsfx.000\megacmd\_win_updates_disabler.bat
- %TEMP%\7zipsfx.000\megacmd\_win_updates_disabler.vbs
- %TEMP%\7zipsfx.000\megacmd\_x-meleon.bat
- %TEMP%\7zipsfx.000\megacmd\_x-meleon.vbs
- %TEMP%\7zipsfx.000\megacmd\_zemana_antimalware_portable.bat
- %TEMP%\7zipsfx.000\megacmd\_zemana_antimalware_portable.vbs
- %TEMP%\7zipsfx.000\sos.v2019.04.15.rbprj
- %TEMP%\7zipsfx.000\megacmd\_winrar.vbs
- %TEMP%\7zipsfx.000\wget\autologger.bat
- %TEMP%\7zipsfx.000\megacmd\_win_mtr.vbs
- %TEMP%\7zipsfx.000\wget\counter.bat
- %TEMP%\7zipsfx.000\wget\cureit.bat
- %TEMP%\7zipsfx.000\wget\cureit.bat.vbs
- %TEMP%\7zipsfx.000\wget\help.txt
- %TEMP%\7zipsfx.000\wget\kavremover.bat
- %TEMP%\7zipsfx.000\wget\kavremover.vbs
- %TEMP%\7zipsfx.000\wget\kvrt+.bat
- %TEMP%\7zipsfx.000\wget\kvrt+.vbs
- %TEMP%\7zipsfx.000\wget\kvrt.bat
- %TEMP%\7zipsfx.000\wget\kvrt.bat.vbs
- %TEMP%\7zipsfx.000\wget\smartfix+.bat
- %TEMP%\7zipsfx.000\wget\smartfix+.bat.vbs
- %TEMP%\7zipsfx.000\wget\autologger.bat.vbs
- %TEMP%\7zipsfx.000\wget\smartfix.bat
- %TEMP%\7zipsfx.000\wget\counter.vbs
- %TEMP%\7zipsfx.000\megacmd\_win_mtr.bat
- %TEMP%\7zipsfx.000\megacmd\_winrar.bat
- %TEMP%\7zipsfx.000\megacmd\_win10_security_plus.vbs
- %TEMP%\7zipsfx.000\megacmd\_tcp_view.vbs
- %TEMP%\7zipsfx.000\megacmd\_teamviewer.bat
- %TEMP%\7zipsfx.000\megacmd\_teamviewer.vbs
- %TEMP%\7zipsfx.000\megacmd\_tor_browser.bat
- %TEMP%\7zipsfx.000\megacmd\_tor_browser.vbs
- %TEMP%\7zipsfx.000\megacmd\_total_commander.bat
- %TEMP%\7zipsfx.000\megacmd\_total_commander.vbs
- %TEMP%\7zipsfx.000\megacmd\_tree_size_free.bat
- %TEMP%\7zipsfx.000\megacmd\_tree_size_free.vbs
- %TEMP%\7zipsfx.000\megacmd\_ultrasurf.bat
- %TEMP%\7zipsfx.000\megacmd\_ultrasurf.vbs
- %TEMP%\7zipsfx.000\megacmd\_ultra_iso.bat
- %TEMP%\7zipsfx.000\megacmd\_systracer.vbs
- %TEMP%\7zipsfx.000\megacmd\_ultra_iso.vbs
- %TEMP%\7zipsfx.000\megacmd\_uninstall_tool.vbs
- %TEMP%\7zipsfx.000\megacmd\_universal_virus_sniffer.bat
- %TEMP%\7zipsfx.000\megacmd\_universal_virus_sniffer.vbs
- %TEMP%\7zipsfx.000\megacmd\_update_look.bat
- %TEMP%\7zipsfx.000\megacmd\_update_look.vbs
- %TEMP%\7zipsfx.000\megacmd\_update_sos.bat
- %TEMP%\7zipsfx.000\megacmd\_update_sos.vbs
- %TEMP%\7zipsfx.000\megacmd\_usb_guard.bat
- %TEMP%\7zipsfx.000\megacmd\_usb_guard.vbs
- %TEMP%\7zipsfx.000\megacmd\_utorrent_pro.bat
- %TEMP%\7zipsfx.000\megacmd\_utorrent_pro.vbs
- %TEMP%\7zipsfx.000\megacmd\_virus_total_uploader.bat
- %TEMP%\7zipsfx.000\megacmd\_virus_total_uploader.vbs
- %TEMP%\7zipsfx.000\megacmd\_uninstall_tool.bat
- %TEMP%\7zipsfx.000\megacmd\_win10_security_plus.bat
- %TEMP%\7zipsfx.000\megacmd\_systracer.bat
- %TEMP%\7zipsfx.000\megacmd\_tcp_view.bat
- %TEMP%\7zipsfx.000\wget\smartfix.bat.vbs
- %TEMP%\7zipsfx.000\files\etyjune5ye5yunyu.txt
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-private-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\avcodec-57.dll
- %TEMP%\7zipsfx.000\megacmd\avformat-57.dll
- %TEMP%\7zipsfx.000\megacmd\avutil-55.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\cares.dll
- %TEMP%\7zipsfx.000\megacmd\libcurl.dll
- %TEMP%\7zipsfx.000\megacmd\libeay32.dll
- %TEMP%\7zipsfx.000\megacmd\libsodium.dll
- %TEMP%\7zipsfx.000\megacmd\megaclient.exe
- %TEMP%\7zipsfx.000\megacmd\megacmdserver.exe
- %TEMP%\7zipsfx.000\megacmd\msvcp140.dll
- %TEMP%\7zipsfx.000\megacmd\ssleay32.dll
- %TEMP%\7zipsfx.000\megacmd\swresample-2.dll
- %TEMP%\7zipsfx.000\megacmd\swscale-4.dll
- %TEMP%\7zipsfx.000\megacmd\ucrtbase.dll
- %TEMP%\7zipsfx.000\megacmd\vccorlib140.dll
- %TEMP%\7zipsfx.000\megacmd\vcruntime140.dll
- %TEMP%\7zipsfx.000\megacmd\concrt140.dll
- %TEMP%\7zipsfx.000\megacmd\freeimage.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\_notepad.bat
- %TEMP%\7zipsfx.000\files\setdefaultbrowser.exe
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\7zipsfx.000\wget\tdsskiller.bat
- %TEMP%\7zipsfx.000\wget\wget.html
- %TEMP%\7zipsfx.000\wget\tdsskiller.bat.vbs
- %TEMP%\7zipsfx.000\megacmd\_spystudio.vbs
- %TEMP%\7zipsfx.000\megacmd\_spystudio.bat
- %TEMP%\7zipsfx.000\megacmd\_shutup10.vbs
- %TEMP%\7zipsfx.000\megacmd\_change_dns_helper.bat
- %TEMP%\7zipsfx.000\megacmd\_change_dns_helper.vbs
- %TEMP%\7zipsfx.000\megacmd\_classic_shell.bat
- %TEMP%\7zipsfx.000\megacmd\_classic_shell.vbs
- %TEMP%\7zipsfx.000\megacmd\_current_release_name.bat
- %TEMP%\7zipsfx.000\megacmd\_current_release_name.vbs
- %TEMP%\7zipsfx.000\megacmd\_driver_magician.bat
- %TEMP%\7zipsfx.000\megacmd\_driver_magician.vbs
- %TEMP%\7zipsfx.000\megacmd\_everything.bat
- %TEMP%\7zipsfx.000\megacmd\_everything.vbs
- %TEMP%\7zipsfx.000\megacmd\_far_manager.bat
- %TEMP%\7zipsfx.000\megacmd\_avz.vbs
- %TEMP%\7zipsfx.000\megacmd\_far_manager.vbs
- %TEMP%\7zipsfx.000\megacmd\_av_uninstall_tools_pack.vbs
- %TEMP%\7zipsfx.000\megacmd\_fast_stone_capture.vbs
- %TEMP%\7zipsfx.000\megacmd\_foxit_reader.vbs
- %TEMP%\7zipsfx.000\megacmd\_hd_tune_pro.bat
- %TEMP%\7zipsfx.000\megacmd\_hd_tune_pro.vbs
- %TEMP%\7zipsfx.000\megacmd\_hijackthis.bat
- %TEMP%\7zipsfx.000\megacmd\_hijackthis.vbs
- %TEMP%\7zipsfx.000\megacmd\_hitmanpro.bat
- %TEMP%\7zipsfx.000\megacmd\_hitmanpro.vbs
- %TEMP%\7zipsfx.000\megacmd\_hostsman.bat
- %TEMP%\7zipsfx.000\megacmd\_hostsman.vbs
- %TEMP%\7zipsfx.000\megacmd\_k-meleon76_pro.bat
- %TEMP%\7zipsfx.000\megacmd\_k-meleon76_pro.vbs
- %TEMP%\7zipsfx.000\megacmd\_fast_stone_capture.bat
- %TEMP%\7zipsfx.000\megacmd\_avz.bat
- %TEMP%\7zipsfx.000\megacmd\_foxit_reader.bat
- %TEMP%\7zipsfx.000\megacmd\_autoruns.vbs
- %TEMP%\7zipsfx.000\megacmd\_autoruns.bat
- %TEMP%\7zipsfx.000\images\sos_label_jpg.jpg
- %TEMP%\7zipsfx.000\megacmd\.megacmd\megacmd.version
- %TEMP%\7zipsfx.000\megacmd\internet\ping_google.bat
- %TEMP%\7zipsfx.000\megacmd\internet\ping_google.vbs
- %TEMP%\7zipsfx.000\megacmd\mega-get.bat
- %TEMP%\7zipsfx.000\megacmd\new 5.txt
- %TEMP%\7zipsfx.000\megacmd\_7z.bat
- %TEMP%\7zipsfx.000\megacmd\_7z.vbs
- %TEMP%\7zipsfx.000\megacmd\_7z64.bat
- %TEMP%\7zipsfx.000\megacmd\_7z64.vbs
- %TEMP%\7zipsfx.000\megacmd\_7z_sfx_builder.bat
- %TEMP%\7zipsfx.000\megacmd\_7z_sfx_builder.vbs
- %TEMP%\7zipsfx.000\megacmd\_admuncher.bat
- %TEMP%\7zipsfx.000\megacmd\_admuncher.vbs
- %TEMP%\7zipsfx.000\megacmd\.megacmd\megacmd.cfg
- %TEMP%\7zipsfx.000\megacmd\_advanced_ip_scanner_1.5.bat
- %TEMP%\7zipsfx.000\megacmd\_advanced_ip_scanner_2.5.bat
- %TEMP%\7zipsfx.000\megacmd\_advanced_ip_scanner_2.5.vbs
- %TEMP%\7zipsfx.000\megacmd\_adwcleaner.7.3.bat
- %TEMP%\7zipsfx.000\megacmd\_adwcleaner.7.3.bat.vbs
- %TEMP%\7zipsfx.000\megacmd\_adwcleaner6.0.47.bat
- %TEMP%\7zipsfx.000\megacmd\_adwcleaner6.0.47.vbs
- %TEMP%\7zipsfx.000\megacmd\_aida64.bat
- %TEMP%\7zipsfx.000\megacmd\_aida64.vbs
- %TEMP%\7zipsfx.000\megacmd\_aitotal.bat
- %TEMP%\7zipsfx.000\megacmd\_aitotal.vbs
- %TEMP%\7zipsfx.000\megacmd\_ammy_admin.bat
- %TEMP%\7zipsfx.000\megacmd\_ammy_admin.vbs
- %TEMP%\7zipsfx.000\megacmd\_k-meleon_goanna.bat
- %TEMP%\7zipsfx.000\megacmd\_advanced_ip_scanner_1.5.vbs
- %TEMP%\7zipsfx.000\megacmd\_k-meleon_goanna.vbs
- %TEMP%\7zipsfx.000\megacmd\_av_uninstall_tools_pack.bat
- %TEMP%\7zipsfx.000\megacmd\_kaspersky_reset_trial.bat
- %TEMP%\7zipsfx.000\megacmd\_office_cleanup.vbs
- %TEMP%\7zipsfx.000\megacmd\_pause_5sec.vbs
- %TEMP%\7zipsfx.000\megacmd\_ports_monitor.bat
- %TEMP%\7zipsfx.000\megacmd\_ports_monitor.vbs
- %TEMP%\7zipsfx.000\megacmd\_power_data_recovery.bat
- %TEMP%\7zipsfx.000\megacmd\_power_data_recovery.vbs
- %TEMP%\7zipsfx.000\megacmd\_process_explorer.bat
- %TEMP%\7zipsfx.000\megacmd\_process_explorer.vbs
- %TEMP%\7zipsfx.000\megacmd\_pserv.bat
- %TEMP%\7zipsfx.000\megacmd\_pserv.vbs
- %TEMP%\7zipsfx.000\megacmd\_psiphon3.bat
- %TEMP%\7zipsfx.000\megacmd\_psiphon3.vbs
- %TEMP%\7zipsfx.000\megacmd\_recuva.bat
- %TEMP%\7zipsfx.000\megacmd\_recuva.vbs
- %TEMP%\7zipsfx.000\megacmd\_reg_organizer.bat
- %TEMP%\7zipsfx.000\megacmd\_reg_organizer.vbs
- %TEMP%\7zipsfx.000\megacmd\_revo_uninstaller.bat
- %TEMP%\7zipsfx.000\megacmd\_revo_uninstaller.vbs
- %TEMP%\7zipsfx.000\megacmd\_run_as_system.bat
- %TEMP%\7zipsfx.000\megacmd\_run_as_system.vbs
- %TEMP%\7zipsfx.000\megacmd\_run_mega-get_vbs.vbs
- %TEMP%\7zipsfx.000\megacmd\_run_megacmd.vbs
- %TEMP%\7zipsfx.000\megacmd\_run_megacmd_bat.bat
- %TEMP%\7zipsfx.000\megacmd\_run__admuncher.bat
- %TEMP%\7zipsfx.000\megacmd\_run__admuncher.vbs
- %TEMP%\7zipsfx.000\megacmd\_shadow_defender.bat
- %TEMP%\7zipsfx.000\megacmd\_shadow_defender.vbs
- %TEMP%\7zipsfx.000\megacmd\_shutup10.bat
- %TEMP%\7zipsfx.000\megacmd\_office_cleanup.bat
- %TEMP%\7zipsfx.000\megacmd\_kaspersky_reset_trial.vbs
- %TEMP%\7zipsfx.000\megacmd\_pause_5sec.bat
- %TEMP%\7zipsfx.000\megacmd\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\7zipsfx.000\sosv20190415.exe
- %TEMP%\7zipsfx.000\megacmd\_mega_sync.vbs
- %TEMP%\7zipsfx.000\megacmd\_kavremover.vbs
- %TEMP%\7zipsfx.000\megacmd\_keswin_11.0.1.90_ru_aes56.bat
- %TEMP%\7zipsfx.000\megacmd\_keswin_11.0.1.90_ru_aes56.vbs
- %TEMP%\7zipsfx.000\megacmd\_kes_10.2.5.3201_ru_key_2017-12-31_x17620.bat
- %TEMP%\7zipsfx.000\megacmd\_kes_10.2.5.3201_ru_key_2017-12-31_x17620.vbs
- %TEMP%\7zipsfx.000\megacmd\_kes_10.2.6.3733_win_sp1_mr4_ru_aes56.bat
- %TEMP%\7zipsfx.000\megacmd\_kes_10.2.6.3733_win_sp1_mr4_ru_aes56.vbs
- %TEMP%\7zipsfx.000\megacmd\_kes_keys.bat
- %TEMP%\7zipsfx.000\megacmd\_kes_keys.vbs
- %TEMP%\7zipsfx.000\megacmd\_keygen.mbam.corporate.bat
- %TEMP%\7zipsfx.000\megacmd\_keygen.mbam.corporate.vbs
- %TEMP%\7zipsfx.000\megacmd\_kill_all.bat
- %TEMP%\7zipsfx.000\megacmd\_kill_all.vbs
- %TEMP%\7zipsfx.000\megacmd\_kavremover.bat
- %TEMP%\7zipsfx.000\megacmd\_kill_megacmd.bat
- %TEMP%\7zipsfx.000\megacmd\_krt_club.bat
- %TEMP%\7zipsfx.000\megacmd\_krt_club.vbs
- %TEMP%\7zipsfx.000\megacmd\_longtion_radbuilder.bat
- %TEMP%\7zipsfx.000\megacmd\_longtion_radbuilder.vbs
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_anti_exploit_premium.bat
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_anti_exploit_premium.vbs
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_chameleon.bat
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_chameleon.vbs
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_clean_tool.bat
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_clean_tool.vbs
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_premium_3.bat
- %TEMP%\7zipsfx.000\megacmd\_malwarebytes_premium_3.vbs
- %TEMP%\7zipsfx.000\megacmd\_mega_sync.bat
- %TEMP%\7zipsfx.000\megacmd\_kill_megacmd.vbs
- %TEMP%\7zipsfx.000\megacmd\_notepad.vbs
- %TEMP%\7zipsfx.000\wget\wget.exe
- DNS ASK ho####gkartinok.com
- DNS ASK g.###.mega.co.nz
- '%TEMP%\7zipsfx.000\sosv20190415.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\7ZipSfx.000\wget\counter.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\7ZipSfx.000\MegaCmd\_run_MEGAcmd.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\7ZipSfx.000\MegaCmd\_Current_Release_Name.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\7ZipSfx.000\MegaCmd\Internet\ping_google.vbs"
- '%TEMP%\7zipsfx.000\wget\wget.exe' -np -nv --spider --no-check-certificate https://hostingkartinok.com/show-image.php?id=54881687aca8a559e297bc780bda91b0
- '%TEMP%\7zipsfx.000\megacmd\megacmdserver.exe'
- '%TEMP%\7zipsfx.000\megacmd\megaclient.exe' get https://mega.nz/#F!yNpElRxS!OaUe44aM4asp2bKnxPNMUQ ..\MegaCmd\
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\_Current_Release_Name.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\Internet\ping_google.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\_run_MEGAcmd_bat.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\wget\counter.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\_Current_Release_Name.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\Internet\ping_google.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\MegaCmd\_run_MEGAcmd_bat.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\wget\counter.bat" "
- '%WINDIR%\syswow64\ping.exe' -n 2 "8.8.8.8"
- '%WINDIR%\syswow64\find.exe' /i "TTL="
- '%WINDIR%\syswow64\mode.com' con lines=3 cols=80