Technical Information
- '%TEMP%\1.tmp\nircmd.exe' win trans ititle "Opening Removable Disk" 1
- '<SYSTEM32>\cmd.exe' /c wmic logicaldisk get caption,description,drivetype 2>NUL
- '<SYSTEM32>\mode.com' con: cols=14 lines=1
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.bat" <Full path to file>"
- %TEMP%\1.tmp\nircmdc.exe
- %TEMP%\1.tmp\logger.dll
- %TEMP%\1.tmp\srvstart.dll
- %TEMP%\1.tmp\unrenet.ini
- %TEMP%\1.tmp\srvstart.exe
- %TEMP%\1.tmp\nircmd.exe
- %WINDIR%\nircmdc.exe
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\1.tmp\mainC.bat
- %TEMP%\1.tmp\serviceC.ini
- %WINDIR%\nircmd.exe
- %TEMP%\1.tmp\dwhatserve.ini
- %TEMP%\1.tmp\winolnet.ini
- %TEMP%\1.tmp\how_to_-recover_data.pdf
- %TEMP%\1.tmp\winend.bat
- %TEMP%\1.tmp\2.bat
- %TEMP%\1.tmp\whatserve.ini
- %TEMP%\1.tmp\winend.ini
- %TEMP%\1.tmp\recover_data.exe
- %TEMP%\1.tmp\unrenet.exe
- %TEMP%\1.tmp\winolnet.exe
- %TEMP%\1.tmp\dexect2.exe
- %TEMP%\1.tmp\exect2.exe
- %TEMP%\1.tmp\how_to_recover_data.exe
- %TEMP%\tmp6.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\tmp4.tmp