Technical Information
- %TEMP%\nsm8749.tmp
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dismprov.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dmiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\folderprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\intlprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\logprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\msiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\osprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\smiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\transmogprovider.dll.mui
- %TEMP%\nsc875a.tmp\activsrv.cmd
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\unattendprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\folderprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\intlprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\logprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\msiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\osprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\smiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\transmogprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\unattendprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\wimprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\compatprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dismcore.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\cbsprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dmiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismprov.dll
- %TEMP%\nsc875a.tmp\core.bin
- %TEMP%\nsc875a.tmp\aes.dll
- %TEMP%\nsc875a.tmp\nsprocess.dll
- %TEMP%\nsc875a.tmp\execdos.dll
- %TEMP%\nsc875a.tmp\nsexec.dll
- %TEMP%\nsc875a.tmp\md5dll.dll
- %TEMP%\nsc875a.tmp\0
- %TEMP%\nsc875a.tmp\nsisunz.dll
- %TEMP%\nsc875a.tmp\activ.cmd
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\wdscore.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\wimprovider.dll.mui
- %TEMP%\nsc875a.tmp\activ11.cmd
- %TEMP%\nsc875a.tmp\del.vbe
- %TEMP%\nsc875a.tmp\helper.vbe
- %TEMP%\nsc875a.tmp\main.cmd
- nul
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\cbsprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\compatprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismcore.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismcoreps.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismhost.exe
- %TEMP%\nsc875a.tmp\system.dll
- %TEMP%\nsc875a.tmp\arg.cmd
- %WINDIR%\logs\dism\dism.log
- %TEMP%\nsc875a.tmp\core.bin
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\unattendprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\transmogprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\smiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\osprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\msiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\logprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\intlprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\folderprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\wimprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\unattendprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\transmogprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\smiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\osprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\msiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\wdscore.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\logprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\folderprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dmiprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dismprov.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\dismcore.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\compatprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\cbsprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dmiprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismprov.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismhost.exe
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismcoreps.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismcore.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\compatprovider.dll
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\cbsprovider.dll
- %TEMP%\nsc875a.tmp\0
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\en-us\intlprovider.dll.mui
- %TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\wimprovider.dll
- DNS ASK ex##ple.com
- '%TEMP%\nsc875a.tmp\aes.dll' -d VmpKc2RWcEhPVE5qZVVKQ1dUTlNjR1J0UmpCaFZ6bDFTVVpTZG1JeWQyZGtha2wxVFdrME1B core.bin 0
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command Start-Process cmd.exe -Wait -Argumentlist '/c "%TEMP%\nsc875A.tmp\main.cmd" /pass ' -Verb RunAs
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command Start-Process %WINDIR%\sysnative\cmd.exe -Wait -Argumentlist '/c "%TEMP%\nsc875A.tmp\main.cmd" /pass /x64'
- '%TEMP%\c7bd2ea1-d5b2-4327-bc3f-8b1076157ad3\dismhost.exe' {1FE7DF97-C8C6-45F9-87A9-117862B01F11}
- '%WINDIR%\syswow64\cmd.exe' /c start /w /min compact.exe /c /f /i /q' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /w /min aes.dll -d VmpKc2RWcEhPVE5qZVVKQ1dUTlNjR1J0UmpCaFZ6bDFTVVpTZG1JeWQyZGtha2wxVFdrME1B core.bin 0' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Windowstyle Hidden -Command Start-Process cmd.exe -Wait -Argumentlist '/c start /w arg.cmd /launch ' -Windowstyle Hidden' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /w arg.cmd /launch' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /w /min compact.exe /c /f /i /q
- '<SYSTEM32>\cmd.exe' /c wmic Path Win32_LocalTime Get /Format:value
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v EditionID
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v EditionID
- '<SYSTEM32>\dism.exe' /online /get-currentedition
- '<SYSTEM32>\cscript.exe' /nologo <SYSTEM32>\slmgr.vbs /dli
- '<SYSTEM32>\find.exe' /i "Licensed"
- '<SYSTEM32>\find.exe' /i "Windows 11"
- '<SYSTEM32>\find.exe' /i "Windows 10"
- '<SYSTEM32>\find.exe' /i "Windows 8.1"
- '<SYSTEM32>\find.exe' /i "Windows 8"
- '<SYSTEM32>\find.exe' /i "Windows 7"
- '<SYSTEM32>\wbem\wmic.exe' os
- '<SYSTEM32>\find.exe' /i "64-bit"
- '<SYSTEM32>\find.exe' /i "32-bit"
- '<SYSTEM32>\wbem\wmic.exe' os get osarchitecture
- '<SYSTEM32>\find.exe' /i "Elevated"
- '<SYSTEM32>\dism.exe'
- '<SYSTEM32>\find.exe' /i "could not"
- '<SYSTEM32>\ping.exe' example.com -n 2
- '<SYSTEM32>\cmd.exe' /c %TEMP%\nsc875A.tmp\main.cmd /pass /x64
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\nsc875A.tmp\main.cmd /pass
- '%WINDIR%\syswow64\find.exe' /i "error"
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\nsc875A.tmp\\main.cmd /runas
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -command Start-Process cmd.exe -wait -argumentlist '/c "%TEMP%\nsc875A.tmp\\main.cmd" /runas'
- '%WINDIR%\syswow64\cmd.exe' /K arg.cmd /launch
- '%WINDIR%\syswow64\cmd.exe' /c start /w arg.cmd /launch
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Windowstyle Hidden -Command Start-Process cmd.exe -Wait -Argumentlist '/c start /w arg.cmd /launch ' -Windowstyle Hidden
- '%WINDIR%\syswow64\cmd.exe' /c start /w /min aes.dll -d VmpKc2RWcEhPVE5qZVVKQ1dUTlNjR1J0UmpCaFZ6bDFTVVpTZG1JeWQyZGtha2wxVFdrME1B core.bin 0
- '%WINDIR%\syswow64\compact.exe' /c /f /i /q
- '<SYSTEM32>\wbem\wmic.exe' Path Win32_LocalTime Get /Format:value
- '<SYSTEM32>\choice.exe' /c 0abcdefrhix /n /t 60 /d 0 /m "Your Choice=>"