Technical Information
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\Microsoft.exe" "Microsoft.exe" ENABLE
- %APPDATA%\5.vbs
- %APPDATA%\play top ping.bat
- %LOCALAPPDATA%\tempwinlogon.exe
- %APPDATA%\microsoft.exe
- 'ha####066.ddns.net':5552
- DNS ASK ha####066.ddns.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\5.vbs"
- '%LOCALAPPDATA%\tempwinlogon.exe'
- '%APPDATA%\microsoft.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\Microsoft.exe" "Microsoft.exe" ENABLE' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Play TOP Ping.bat" "