Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.31814

Добавлен в вирусную базу Dr.Web: 2020-05-14

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\$regasm\_regasm.exe
  • <Drive name for removable media>:\garden.htm
  • <Drive name for removable media>:\csc54b7ded5312549b6a9aa96c20369950.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\trivial-merge.ico
  • <Drive name for removable media>:\trivial-merge.htm
  • <Drive name for removable media>:\csc69e213c757fe43dc88aaacd83c1a63ab.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\advice_process.ico
  • <Drive name for removable media>:\advice_process.htm
  • <Drive name for removable media>:\cscfb2a3a9049a4b76a22d6981a7865721.tmp
  • <Drive name for removable media>:\cscd1223637f3e6439981a8a832245c38ea.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\alert.ico
  • <Drive name for removable media>:\csc69f352d2d4e24766a6f3e19ddcf8ec32.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\about.ico
  • <Drive name for removable media>:\about.html
  • <Drive name for removable media>:\cscda2aa511ae246caa253e26e2c6a5f.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\browse.ico
  • <Drive name for removable media>:\browse.html
  • <Drive name for removable media>:\csc7ea37faa50d64337b1fa48e210b65e8f.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\3.ico
  • <Drive name for removable media>:\utorrent.exe.scr
  • <Drive name for removable media>:\$regasm\$limeicons\garden.ico
  • <Drive name for removable media>:\alert.html
  • <Drive name for removable media>:\3.jpeg
  • <Drive name for removable media>:\$regasm\$limeicons\utorrent.ico
  • <Drive name for removable media>:\winmine.exe.scr
  • <Drive name for removable media>:\$regasm\$limeicons\skypesetup.ico
  • <Drive name for removable media>:\skypesetup.exe
  • <Drive name for removable media>:\csc355e9e7b17304762a867e9c4acb4617.tmp
  • <Drive name for removable media>:\skypesetup.exe.scr
  • <Drive name for removable media>:\$regasm\$limeicons\tcm851ax32.ico
  • <Drive name for removable media>:\tcm851ax32.exe
  • <Drive name for removable media>:\csc56572ecefd5b4fffba4d6d2a7e2a958.tmp
  • <Drive name for removable media>:\tcm851ax32.exe.scr
  • <Drive name for removable media>:\$regasm\$limeicons\calc.ico
  • <Drive name for removable media>:\calc.exe
  • <Drive name for removable media>:\csce9b4bd79fbb94d2790a5d510556df0bc.tmp
  • <Drive name for removable media>:\calc.exe.scr
  • <Drive name for removable media>:\$regasm\$limeicons\jre-7u75-windows-i586-iftw.ico
  • <Drive name for removable media>:\jre-7u75-windows-i586-iftw.exe
  • <Drive name for removable media>:\cscbf48c47b8a9048639e81d2c8aa3733a9.tmp
  • <Drive name for removable media>:\jre-7u75-windows-i586-iftw.exe.scr
  • <Drive name for removable media>:\utorrent.exe
  • <Drive name for removable media>:\winmine.exe
  • <Drive name for removable media>:\csc7d0a86f4f5c442a289225199f47f4af.tmp
  • <Drive name for removable media>:\fi51.doc
  • <Drive name for removable media>:\$regasm\$limeicons\pushkin.ico
  • <Drive name for removable media>:\etc6_m_1.mov
  • <Drive name for removable media>:\dag2_panel1_320_ref.mov
  • <Drive name for removable media>:\firefly1.mov
  • <Drive name for removable media>:\clip_1080_5sec_10mbps_h264.mp4
  • <Drive name for removable media>:\51.mp4
  • <Drive name for removable media>:\spib_pima.pdf
  • <Drive name for removable media>:\fil_20060629111052.pdf
  • <Drive name for removable media>:\ff_ot_user_guide.pdf
  • <Drive name for removable media>:\2015-02-patients-topic-work-related-asthma-jobs.pdf
  • <Drive name for removable media>:\pushkin.jpeg
  • <Drive name for removable media>:\lom602.pdf
  • <Drive name for removable media>:\ck_ugo.pem
  • <Drive name for removable media>:\investmentbankca_ca8.pem
  • <Drive name for removable media>:\irgeek.pem
  • <Drive name for removable media>:\delongcacert.pem
  • <Drive name for removable media>:\hhhlcert.pem
  • <Drive name for removable media>:\cert.pem
  • <Drive name for removable media>:\asm.png
  • <Drive name for removable media>:\region-north-karelia.jpg
  • <Drive name for removable media>:\csc3747b07e58a64fa2a3363c1525f0abc.tmp
  • <Drive name for removable media>:\scan.mov
  • <Drive name for removable media>:\4f0bf7ff71f28.jpg
  • <Drive name for removable media>:\$regasm\$limeicons\4f0bf7ff71f28.ico
  • <Drive name for removable media>:\csc4397aaf54fe14ad7b630ade8828e4e70.tmp
  • <Drive name for removable media>:\region-north-karelia.jpeg
  • <Drive name for removable media>:\csccd4a281eb2d0472b9193de11ea80d988.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\1189.ico
  • <Drive name for removable media>:\1189.jpeg
  • <Drive name for removable media>:\csc9f6c97561c27449c8a8a97ed247be1c.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\2.ico
  • <Drive name for removable media>:\2.jpeg
  • <Drive name for removable media>:\$regasm\$limeicons\winmine.ico
  • <Drive name for removable media>:\cscf03ff74aa5834481a16caaded9e7872.tmp
  • <Drive name for removable media>:\csc204a28fe38b0439f804f1e3dface25f.tmp
  • <Drive name for removable media>:\cscddb74175974641f5bafa47f24fa06c.tmp
  • <Drive name for removable media>:\13.jpg
  • <Drive name for removable media>:\csc2af1c965ac9e45628b5a23f812e3e5df.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\210252809.ico
  • <Drive name for removable media>:\210252809.jpg
  • <Drive name for removable media>:\csc3022d59e8ef4d77955d1f83aa62794b.tmp
  • <Drive name for removable media>:\1189.jpg
  • <Drive name for removable media>:\cscac2a30c684ce4d2a9f86c2fe3d7da710.tmp
  • <Drive name for removable media>:\2.jpg
  • <Drive name for removable media>:\$regasm\$limeicons\region-north-karelia.ico
  • <Drive name for removable media>:\$regasm\$limeicons\13.ico
  • <Drive name for removable media>:\cscfd73b3c2d48942a691bcb2986d895ea4.tmp
  • <Drive name for removable media>:\hadac_newsletter_july_2010_final.docx
  • <Drive name for removable media>:\$regasm\$limeicons\hadac_newsletter_july_2010_final.ico
  • <Drive name for removable media>:\csc504cc1b3819c405db076f3996fa167f.tmp
  • <Drive name for removable media>:\contosoroot.cer.scr
  • <Drive name for removable media>:\$regasm\$limeicons\contoso_1.ico
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\csc53144ebfde8f4e1e97f419bd572b6e57.tmp
  • <Drive name for removable media>:\contoso_1.cer.scr
  • <Drive name for removable media>:\$regasm\$limeicons\sdkfailsafeemulator.ico
  • <Drive name for removable media>:\sdkfailsafeemulator.cer
  • <Drive name for removable media>:\csc3e654f0b25634eceb5b158e8208af126.tmp
  • <Drive name for removable media>:\sdkfailsafeemulator.cer.scr
  • <Drive name for removable media>:\$regasm\$limeicons\pmd.ico
  • <Drive name for removable media>:\pmd.cer
  • <Drive name for removable media>:\csc5accfb5e4c1446d499459603ee1c962.tmp
  • <Drive name for removable media>:\pmd.cer.scr
  • <Drive name for removable media>:\$regasm\$limeicons\sdksampleprivdeveloper.ico
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\csc2fe22994cd0e45039cc39a7d32ac93bf.tmp
  • <Drive name for removable media>:\dashborder_144.bmp.scr
  • <Drive name for removable media>:\dashborder_144.bmp
  • <Drive name for removable media>:\contosoroot.cer
  • <Drive name for removable media>:\csc2e65f4b0351849209165d0eb3351cf8.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\dashborder_144.ico
  • <Drive name for removable media>:\cscb5af6c20cd524857bcecd33952137e77.tmp
  • <Drive name for removable media>:\delete.avi
  • <Drive name for removable media>:\csc1568d7375294ec8bbdc3275adff01b.tmp
  • <Drive name for removable media>:\delete.avi.scr
  • <Drive name for removable media>:\$regasm\$limeicons\default.ico
  • <Drive name for removable media>:\default.bmp
  • <Drive name for removable media>:\csc52096dceb9714ac991ec734e684fbeae.tmp
  • <Drive name for removable media>:\default.bmp.scr
  • <Drive name for removable media>:\$regasm\$limeicons\dialmap.ico
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer.scr
  • <Drive name for removable media>:\bg_search_box.png
  • <Drive name for removable media>:\dialmap.bmp
  • <Drive name for removable media>:\$regasm\$limeicons\dashborder_192.ico
  • <Drive name for removable media>:\dashborder_192.bmp
  • <Drive name for removable media>:\csce29ce2a994214b029d3d87aea192ac70.tmp
  • <Drive name for removable media>:\dashborder_192.bmp.scr
  • <Drive name for removable media>:\$regasm\$limeicons\tileimage.ico
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\csc400af67636b94a8383be2f1832e7a2d5.tmp
  • <Drive name for removable media>:\tileimage.bmp.scr
  • <Drive name for removable media>:\$regasm\$limeicons\delete.ico
  • <Drive name for removable media>:\dialmap.bmp.scr
  • <Drive name for removable media>:\10thingscondoms.pdf
  • <Drive name for removable media>:\$regasm\$limeicons\testcertificate.ico
  • <Drive name for removable media>:\$regasm\$limeicons\testee.ico
  • <Drive name for removable media>:\lisp_success.doc
  • <Drive name for removable media>:\csc11af1eb6a474fcb83dba05fc327cbd.tmp
  • <Drive name for removable media>:\lisp_success.doc.scr
  • <Drive name for removable media>:\$regasm\$limeicons\508softwareandos.ico
  • <Drive name for removable media>:\508softwareandos.doc
  • <Drive name for removable media>:\csc6b08c0fb6d2483e9e2e336a177c7364.tmp
  • <Drive name for removable media>:\508softwareandos.doc.scr
  • <Drive name for removable media>:\$regasm\$limeicons\contosoroot.ico
  • <Drive name for removable media>:\$regasm\$limeicons\uep_form_786_bulletin_1726i602.ico
  • <Drive name for removable media>:\csc31cd1d6163741899e56e72c27905bee.tmp
  • <Drive name for removable media>:\uep_form_786_bulletin_1726i602.doc.scr
  • <Drive name for removable media>:\$regasm\$limeicons\issi2013_template_for_posters.ico
  • <Drive name for removable media>:\issi2013_template_for_posters.docx
  • <Drive name for removable media>:\csc3035d9f8ae0e42349bbdf295922e181.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\aoc_saq_d_v3_merchant.ico
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
  • <Drive name for removable media>:\csc8ba01f00caec4db6bd50754dbed4e43.tmp
  • <Drive name for removable media>:\csca4c5a58d1c3d49febb381c2978778e49.tmp
  • <Drive name for removable media>:\uep_form_786_bulletin_1726i602.doc
  • <Drive name for removable media>:\$regasm\$limeicons\lisp_success.ico
  • <Drive name for removable media>:\applicantform_en.doc.scr
  • <Drive name for removable media>:\applicantform_en.doc
  • <Drive name for removable media>:\$regasm\$limeicons\applicantform_en.ico
  • <Drive name for removable media>:\testee.cer
  • <Drive name for removable media>:\cscd6a10a8a8ad645879b9f2d6fcf46373a.tmp
  • <Drive name for removable media>:\testee.cer.scr
  • <Drive name for removable media>:\$regasm\$limeicons\sdksampleunprivdeveloper.ico
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer
  • <Drive name for removable media>:\csc956ac723614841a39df1aa51954a8178.tmp
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer.scr
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\$regasm\$limeicons\fi51.ico
  • <Drive name for removable media>:\cscab39895ef2b748a5a3f123e2ff4555dc.tmp
  • <Drive name for removable media>:\csc35dd798f61724cb2b339572b9d364651.tmp
  • <Drive name for removable media>:\$regasm\$limeicons\cveuropeo.ico
  • <Drive name for removable media>:\cveuropeo.doc
  • <Drive name for removable media>:\csc34cdb656a53a4c499b6a25423de6635f.tmp
  • <Drive name for removable media>:\cveuropeo.doc.scr
  • <Drive name for removable media>:\$regasm\$limeicons\february_catalogue__2015.ico
  • <Drive name for removable media>:\february_catalogue__2015.doc
  • <Drive name for removable media>:\csc544027a53c0b4a518c8c204ca7eef467.tmp
  • <Drive name for removable media>:\testcertificate.cer.scr
  • <Drive name for removable media>:\february_catalogue__2015.doc.scr
  • <Drive name for removable media>:\fi51.doc.scr
  • <Drive name for removable media>:\cleanlyrics.png
Malicious functions
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
  • file extensions
Injects code into
the following system processes:
  • %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
Modifies file system
Creates the following files
  • %TEMP%\b09bbaecf0\log.txt
  • %TEMP%\23xjzees.cmdline
  • %TEMP%\23xjzees.out
  • %TEMP%\res329.tmp
  • %TEMP%\ikqwa32w.0.cs
  • %TEMP%\ikqwa32w.cmdline
  • %TEMP%\ikqwa32w.out
  • %TEMP%\res54c.tmp
  • %TEMP%\tt4ylqvv.0.cs
  • %TEMP%\res126.tmp
  • %TEMP%\23xjzees.0.cs
  • %TEMP%\tt4ylqvv.cmdline
  • %TEMP%\njcxuein.0.cs
  • %TEMP%\njcxuein.cmdline
  • %TEMP%\njcxuein.out
  • %TEMP%\res9a2.tmp
  • %TEMP%\giik1o2m.0.cs
  • %TEMP%\giik1o2m.cmdline
  • %TEMP%\giik1o2m.out
  • %TEMP%\resbd4.tmp
  • %TEMP%\tt4ylqvv.out
  • %TEMP%\res77f.tmp
  • %TEMP%\dchigvat.cmdline
  • %TEMP%\dchigvat.0.cs
  • %TEMP%\gootnmdd.0.cs
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\d877f783d5d3ef8c\map0
  • %TEMP%\b09bbaecf0\dotnetzip-hlmbswbb.tmp
  • %TEMP%\2o0mmpvy.0.cs
  • %TEMP%\2o0mmpvy.cmdline
  • %TEMP%\2o0mmpvy.out
  • %TEMP%\resf86b.tmp
  • %TEMP%\2eqa31gp.0.cs
  • %TEMP%\gootnmdd.cmdline
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\shortcuts-default.json
  • %TEMP%\gootnmdd.out
  • %TEMP%\2eqa31gp.cmdline
  • %TEMP%\0sb1eslh.cmdline
  • %TEMP%\0sb1eslh.out
  • %TEMP%\resfcf0.tmp
  • %TEMP%\tqs1zeae.0.cs
  • %TEMP%\tqs1zeae.cmdline
  • %TEMP%\tqs1zeae.out
  • %TEMP%\resfee4.tmp
  • %TEMP%\2eqa31gp.out
  • %TEMP%\resfadc.tmp
  • %TEMP%\0sb1eslh.0.cs
  • %TEMP%\resdc58.tmp
  • %TEMP%\dchigvat.out
  • %TEMP%\1xijb4ih.cmdline
  • %TEMP%\res1c30.tmp
  • %TEMP%\ru31kgeb.0.cs
  • %TEMP%\ru31kgeb.cmdline
  • %TEMP%\ru31kgeb.out
  • %TEMP%\res1e43.tmp
  • %TEMP%\pubsjsp3.0.cs
  • %TEMP%\pubsjsp3.cmdline
  • %TEMP%\1xijb4ih.0.cs
  • %TEMP%\pubsjsp3.out
  • %TEMP%\1xijb4ih.out
  • %TEMP%\01qt01uy.0.cs
  • %TEMP%\01qt01uy.out
  • %TEMP%\res225a.tmp
  • %TEMP%\qreojnu3.0.cs
  • %TEMP%\qreojnu3.cmdline
  • %TEMP%\qreojnu3.out
  • %TEMP%\res247d.tmp
  • %TEMP%\0j2dx2sp.0.cs
  • %TEMP%\res2066.tmp
  • %TEMP%\res1a1c.tmp
  • %TEMP%\01qt01uy.cmdline
  • %TEMP%\fqj4ipzf.out
  • %TEMP%\fqj4ipzf.cmdline
  • %TEMP%\zr43fg0a.0.cs
  • %TEMP%\zr43fg0a.out
  • %TEMP%\resffb.tmp
  • %TEMP%\j21rqvig.0.cs
  • %TEMP%\j21rqvig.cmdline
  • %TEMP%\j21rqvig.out
  • %TEMP%\res11fe.tmp
  • %TEMP%\0f4ylewq.0.cs
  • %TEMP%\0f4ylewq.cmdline
  • %TEMP%\0f4ylewq.out
  • %TEMP%\zr43fg0a.cmdline
  • %TEMP%\res1412.tmp
  • %TEMP%\2ubhbbgu.cmdline
  • %TEMP%\2ubhbbgu.out
  • %TEMP%\res1625.tmp
  • %TEMP%\mwx1xc5i.0.cs
  • %TEMP%\mwx1xc5i.cmdline
  • %TEMP%\mwx1xc5i.out
  • %TEMP%\res1828.tmp
  • %TEMP%\fqj4ipzf.0.cs
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\shortcuts-custom.json
  • %TEMP%\2ubhbbgu.0.cs
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\usertag
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\settings0
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\prefix
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\d877f783d5d3ef8c1
  • %TEMP%\resd042.tmp
  • %TEMP%\0vexljrm.0.cs
  • %TEMP%\0vexljrm.cmdline
  • %TEMP%\0vexljrm.out
  • %TEMP%\resd2c3.tmp
  • %TEMP%\5wnthktu.0.cs
  • %TEMP%\5wnthktu.cmdline
  • %TEMP%\glu4ipfq.0.cs
  • %TEMP%\xfx42sgm.out
  • %TEMP%\glu4ipfq.out
  • %TEMP%\5wnthktu.out
  • %TEMP%\h5nhrhs4.out
  • %TEMP%\resd7a5.tmp
  • %TEMP%\1f3eb302.0.cs
  • %TEMP%\1f3eb302.cmdline
  • %TEMP%\1f3eb302.out
  • %TEMP%\resda16.tmp
  • %TEMP%\13u4beq5.0.cs
  • %TEMP%\resd553.tmp
  • %TEMP%\h5nhrhs4.0.cs
  • %TEMP%\h5nhrhs4.cmdline
  • %TEMP%\rescdf0.tmp
  • %TEMP%\xfx42sgm.cmdline
  • %TEMP%\13u4beq5.cmdline
  • %TEMP%\bunulmqd.cmdline
  • %TEMP%\bunulmqd.out
  • %TEMP%\resc19c.tmp
  • %TEMP%\dbp3unt4.0.cs
  • %TEMP%\dbp3unt4.cmdline
  • %TEMP%\dbp3unt4.out
  • %TEMP%\resc42c.tmp
  • %TEMP%\mse4hl0i.0.cs
  • %TEMP%\mse4hl0i.cmdline
  • %TEMP%\bunulmqd.0.cs
  • %TEMP%\mse4hl0i.out
  • %TEMP%\xxffkkzz.0.cs
  • %TEMP%\xxffkkzz.cmdline
  • %TEMP%\xxffkkzz.out
  • %TEMP%\resc9ab.tmp
  • %TEMP%\egdzlovs.0.cs
  • %TEMP%\egdzlovs.cmdline
  • %TEMP%\egdzlovs.out
  • %TEMP%\rescbce.tmp
  • %TEMP%\xfx42sgm.0.cs
  • %TEMP%\resc6fb.tmp
  • %TEMP%\0j2dx2sp.cmdline
  • %TEMP%\resdf7.tmp
  • %TEMP%\13u4beq5.out
  • %TEMP%\tpylr2fc.out
  • %TEMP%\cjpykfjh.0.cs
  • %TEMP%\cjpykfjh.cmdline
  • %TEMP%\cjpykfjh.out
  • %TEMP%\resee98.tmp
  • %TEMP%\jjj2qqrs.0.cs
  • %TEMP%\jjj2qqrs.cmdline
  • %TEMP%\jjj2qqrs.out
  • %TEMP%\xihjbsk0.cmdline
  • %TEMP%\resf0ab.tmp
  • %TEMP%\resec94.tmp
  • %TEMP%\1gvuwwmp.cmdline
  • %TEMP%\resf29f.tmp
  • %TEMP%\dlqjpzx3.0.cs
  • %TEMP%\dlqjpzx3.cmdline
  • %TEMP%\dlqjpzx3.out
  • %TEMP%\resf4b2.tmp
  • %TEMP%\b09bbaecf0\screenshot.jpeg
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\90ef50e22e92cb8c0
  • %TEMP%\1gvuwwmp.0.cs
  • %TEMP%\glu4ipfq.cmdline
  • %TEMP%\1gvuwwmp.out
  • %TEMP%\xihjbsk0.out
  • %TEMP%\xihjbsk0.0.cs
  • %TEMP%\resea14.tmp
  • %TEMP%\resde7b.tmp
  • %TEMP%\42cop5zn.0.cs
  • %TEMP%\42cop5zn.cmdline
  • %TEMP%\42cop5zn.out
  • %TEMP%\rese198.tmp
  • %TEMP%\ewe3mztp.0.cs
  • %TEMP%\ewe3mztp.cmdline
  • %TEMP%\ewe3mztp.out
  • %TEMP%\tpylr2fc.cmdline
  • %TEMP%\rese3ca.tmp
  • %TEMP%\nl2f5nfb.cmdline
  • %TEMP%\nl2f5nfb.out
  • %TEMP%\rese5ed.tmp
  • %TEMP%\1qvzds2t.0.cs
  • %TEMP%\1qvzds2t.cmdline
  • %TEMP%\1qvzds2t.out
  • %TEMP%\rese800.tmp
  • %TEMP%\zrccid45.0.cs
  • %TEMP%\zrccid45.cmdline
  • %TEMP%\nl2f5nfb.0.cs
  • %TEMP%\zrccid45.out
  • %TEMP%\tpylr2fc.0.cs
  • %TEMP%\0j2dx2sp.out
Deletes the following files
  • %TEMP%\resc19c.tmp
  • %TEMP%\23xjzees.out
  • %TEMP%\23xjzees.cmdline
  • %TEMP%\23xjzees.0.cs
  • %TEMP%\res54c.tmp
  • <Drive name for removable media>:\csc7d0a86f4f5c442a289225199f47f4af.tmp
  • %TEMP%\ikqwa32w.0.cs
  • %TEMP%\ikqwa32w.cmdline
  • %TEMP%\ikqwa32w.out
  • %TEMP%\res77f.tmp
  • <Drive name for removable media>:\csc54b7ded5312549b6a9aa96c20369950.tmp
  • %TEMP%\tt4ylqvv.cmdline
  • %TEMP%\dchigvat.cmdline
  • <Drive name for removable media>:\cscbf48c47b8a9048639e81d2c8aa3733a9.tmp
  • %TEMP%\res329.tmp
  • <Drive name for removable media>:\csc69e213c757fe43dc88aaacd83c1a63ab.tmp
  • %TEMP%\njcxuein.cmdline
  • %TEMP%\njcxuein.0.cs
  • %TEMP%\njcxuein.out
  • %TEMP%\resbd4.tmp
  • <Drive name for removable media>:\cscfb2a3a9049a4b76a22d6981a7865721.tmp
  • %TEMP%\giik1o2m.out
  • %TEMP%\giik1o2m.cmdline
  • %TEMP%\giik1o2m.0.cs
  • %TEMP%\resdf7.tmp
  • <Drive name for removable media>:\csc69f352d2d4e24766a6f3e19ddcf8ec32.tmp
  • %TEMP%\tt4ylqvv.0.cs
  • %TEMP%\res9a2.tmp
  • <Drive name for removable media>:\csc204a28fe38b0439f804f1e3dface25f.tmp
  • %TEMP%\tt4ylqvv.out
  • %TEMP%\b09bbaecf0\log.txt
  • %TEMP%\2eqa31gp.out
  • %TEMP%\2eqa31gp.0.cs
  • %TEMP%\resfcf0.tmp
  • <Drive name for removable media>:\csc355e9e7b17304762a867e9c4acb4617.tmp
  • %TEMP%\0sb1eslh.0.cs
  • %TEMP%\0sb1eslh.out
  • %TEMP%\0sb1eslh.cmdline
  • %TEMP%\resfee4.tmp
  • <Drive name for removable media>:\csc56572ecefd5b4fffba4d6d2a7e2a958.tmp
  • %TEMP%\tqs1zeae.out
  • %TEMP%\tqs1zeae.cmdline
  • %TEMP%\gootnmdd.cmdline
  • %TEMP%\gootnmdd.out
  • %TEMP%\gootnmdd.0.cs
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\90ef50e22e92cb8c0
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\d877f783d5d3ef8c\map0
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\d877f783d5d3ef8c1
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\prefix
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\settings0
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\shortcuts-custom.json
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\shortcuts-default.json
  • %TEMP%\b09bbaecf0\telegram desktop\tdata\usertag
  • %TEMP%\b09bbaecf0\user_united states_b09bbaecf0_05-14-2020 14.27.26.zip
  • %TEMP%\res126.tmp
  • <Drive name for removable media>:\csce9b4bd79fbb94d2790a5d510556df0bc.tmp
  • %TEMP%\tqs1zeae.0.cs
  • %TEMP%\b09bbaecf0\screenshot.jpeg
  • %TEMP%\2eqa31gp.cmdline
  • %TEMP%\dchigvat.out
  • %TEMP%\zr43fg0a.out
  • %TEMP%\1xijb4ih.cmdline
  • %TEMP%\1xijb4ih.out
  • %TEMP%\1xijb4ih.0.cs
  • %TEMP%\res1e43.tmp
  • <Drive name for removable media>:\cscddb74175974641f5bafa47f24fa06c.tmp
  • %TEMP%\ru31kgeb.0.cs
  • %TEMP%\ru31kgeb.cmdline
  • %TEMP%\ru31kgeb.out
  • %TEMP%\res2066.tmp
  • <Drive name for removable media>:\csc2af1c965ac9e45628b5a23f812e3e5df.tmp
  • %TEMP%\pubsjsp3.cmdline
  • %TEMP%\res1c30.tmp
  • <Drive name for removable media>:\cscf03ff74aa5834481a16caaded9e7872.tmp
  • %TEMP%\pubsjsp3.out
  • <Drive name for removable media>:\csc3022d59e8ef4d77955d1f83aa62794b.tmp
  • %TEMP%\01qt01uy.cmdline
  • %TEMP%\01qt01uy.0.cs
  • %TEMP%\01qt01uy.out
  • %TEMP%\res247d.tmp
  • <Drive name for removable media>:\cscac2a30c684ce4d2a9f86c2fe3d7da710.tmp
  • %TEMP%\qreojnu3.cmdline
  • %TEMP%\qreojnu3.0.cs
  • %TEMP%\qreojnu3.out
  • <Drive name for removable media>:\csc3747b07e58a64fa2a3363c1525f0abc.tmp
  • %TEMP%\0j2dx2sp.cmdline
  • %TEMP%\pubsjsp3.0.cs
  • %TEMP%\res225a.tmp
  • %TEMP%\resffb.tmp
  • %TEMP%\dchigvat.0.cs
  • %TEMP%\fqj4ipzf.0.cs
  • %TEMP%\zr43fg0a.cmdline
  • %TEMP%\zr43fg0a.0.cs
  • %TEMP%\res11fe.tmp
  • <Drive name for removable media>:\csc7ea37faa50d64337b1fa48e210b65e8f.tmp
  • %TEMP%\j21rqvig.out
  • %TEMP%\j21rqvig.cmdline
  • %TEMP%\j21rqvig.0.cs
  • %TEMP%\res1412.tmp
  • <Drive name for removable media>:\cscd1223637f3e6439981a8a832245c38ea.tmp
  • %TEMP%\0f4ylewq.out
  • %TEMP%\fqj4ipzf.cmdline
  • <Drive name for removable media>:\cscda2aa511ae246caa253e26e2c6a5f.tmp
  • %TEMP%\fqj4ipzf.out
  • %TEMP%\0f4ylewq.0.cs
  • %TEMP%\2ubhbbgu.cmdline
  • %TEMP%\2ubhbbgu.out
  • %TEMP%\2ubhbbgu.0.cs
  • %TEMP%\res1828.tmp
  • <Drive name for removable media>:\csccd4a281eb2d0472b9193de11ea80d988.tmp
  • %TEMP%\mwx1xc5i.cmdline
  • %TEMP%\mwx1xc5i.out
  • %TEMP%\mwx1xc5i.0.cs
  • %TEMP%\res1a1c.tmp
  • <Drive name for removable media>:\csc9f6c97561c27449c8a8a97ed247be1c.tmp
  • %TEMP%\0f4ylewq.cmdline
  • %TEMP%\res1625.tmp
  • <Drive name for removable media>:\csc4397aaf54fe14ad7b630ade8828e4e70.tmp
  • %TEMP%\resfadc.tmp
  • %TEMP%\2o0mmpvy.0.cs
  • %TEMP%\2o0mmpvy.cmdline
  • %TEMP%\glu4ipfq.0.cs
  • %TEMP%\glu4ipfq.cmdline
  • %TEMP%\glu4ipfq.out
  • %TEMP%\resd2c3.tmp
  • <Drive name for removable media>:\csc53144ebfde8f4e1e97f419bd572b6e57.tmp
  • %TEMP%\0vexljrm.out
  • %TEMP%\0vexljrm.0.cs
  • %TEMP%\0vexljrm.cmdline
  • %TEMP%\resd553.tmp
  • <Drive name for removable media>:\csc3e654f0b25634eceb5b158e8208af126.tmp
  • %TEMP%\5wnthktu.0.cs
  • %TEMP%\resd042.tmp
  • %TEMP%\13u4beq5.out
  • %TEMP%\xfx42sgm.cmdline
  • <Drive name for removable media>:\csc5accfb5e4c1446d499459603ee1c962.tmp
  • %TEMP%\h5nhrhs4.out
  • %TEMP%\h5nhrhs4.0.cs
  • %TEMP%\h5nhrhs4.cmdline
  • %TEMP%\resda16.tmp
  • <Drive name for removable media>:\csc2fe22994cd0e45039cc39a7d32ac93bf.tmp
  • %TEMP%\1f3eb302.0.cs
  • %TEMP%\1f3eb302.cmdline
  • %TEMP%\1f3eb302.out
  • %TEMP%\resdc58.tmp
  • <Drive name for removable media>:\cscab39895ef2b748a5a3f123e2ff4555dc.tmp
  • %TEMP%\5wnthktu.out
  • %TEMP%\5wnthktu.cmdline
  • %TEMP%\resd7a5.tmp
  • %TEMP%\xfx42sgm.0.cs
  • %TEMP%\resc9ab.tmp
  • %TEMP%\bunulmqd.0.cs
  • %TEMP%\bunulmqd.cmdline
  • %TEMP%\bunulmqd.out
  • %TEMP%\resc42c.tmp
  • <Drive name for removable media>:\csc52096dceb9714ac991ec734e684fbeae.tmp
  • %TEMP%\dbp3unt4.out
  • %TEMP%\dbp3unt4.cmdline
  • %TEMP%\dbp3unt4.0.cs
  • %TEMP%\resc6fb.tmp
  • <Drive name for removable media>:\cscb5af6c20cd524857bcecd33952137e77.tmp
  • %TEMP%\mse4hl0i.0.cs
  • %TEMP%\xfx42sgm.out
  • %TEMP%\13u4beq5.0.cs
  • <Drive name for removable media>:\csc1568d7375294ec8bbdc3275adff01b.tmp
  • <Drive name for removable media>:\csce29ce2a994214b029d3d87aea192ac70.tmp
  • %TEMP%\xxffkkzz.cmdline
  • %TEMP%\xxffkkzz.0.cs
  • %TEMP%\xxffkkzz.out
  • %TEMP%\rescbce.tmp
  • <Drive name for removable media>:\csc400af67636b94a8383be2f1832e7a2d5.tmp
  • %TEMP%\egdzlovs.out
  • %TEMP%\egdzlovs.cmdline
  • %TEMP%\egdzlovs.0.cs
  • %TEMP%\rescdf0.tmp
  • <Drive name for removable media>:\csc2e65f4b0351849209165d0eb3351cf8.tmp
  • %TEMP%\mse4hl0i.out
  • %TEMP%\mse4hl0i.cmdline
  • <Drive name for removable media>:\csc504cc1b3819c405db076f3996fa167f.tmp
  • %TEMP%\13u4beq5.cmdline
  • %TEMP%\xihjbsk0.out
  • %TEMP%\xihjbsk0.cmdline
  • %TEMP%\resee98.tmp
  • <Drive name for removable media>:\csc6b08c0fb6d2483e9e2e336a177c7364.tmp
  • %TEMP%\cjpykfjh.cmdline
  • %TEMP%\cjpykfjh.out
  • %TEMP%\cjpykfjh.0.cs
  • %TEMP%\resf0ab.tmp
  • <Drive name for removable media>:\csc31cd1d6163741899e56e72c27905bee.tmp
  • %TEMP%\jjj2qqrs.out
  • %TEMP%\jjj2qqrs.cmdline
  • <Drive name for removable media>:\csc11af1eb6a474fcb83dba05fc327cbd.tmp
  • %TEMP%\zrccid45.cmdline
  • %TEMP%\xihjbsk0.0.cs
  • %TEMP%\jjj2qqrs.0.cs
  • %TEMP%\1gvuwwmp.0.cs
  • %TEMP%\1gvuwwmp.cmdline
  • %TEMP%\resf4b2.tmp
  • <Drive name for removable media>:\csc8ba01f00caec4db6bd50754dbed4e43.tmp
  • %TEMP%\dlqjpzx3.out
  • %TEMP%\dlqjpzx3.cmdline
  • %TEMP%\dlqjpzx3.0.cs
  • %TEMP%\resf86b.tmp
  • <Drive name for removable media>:\cscfd73b3c2d48942a691bcb2986d895ea4.tmp
  • %TEMP%\2o0mmpvy.out
  • %TEMP%\resf29f.tmp
  • <Drive name for removable media>:\csc3035d9f8ae0e42349bbdf295922e181.tmp
  • %TEMP%\1gvuwwmp.out
  • %TEMP%\resec94.tmp
  • %TEMP%\zrccid45.0.cs
  • %TEMP%\resde7b.tmp
  • %TEMP%\tpylr2fc.cmdline
  • %TEMP%\tpylr2fc.0.cs
  • %TEMP%\tpylr2fc.out
  • %TEMP%\rese198.tmp
  • <Drive name for removable media>:\csc956ac723614841a39df1aa51954a8178.tmp
  • %TEMP%\42cop5zn.0.cs
  • %TEMP%\42cop5zn.cmdline
  • %TEMP%\42cop5zn.out
  • %TEMP%\rese3ca.tmp
  • <Drive name for removable media>:\csc35dd798f61724cb2b339572b9d364651.tmp
  • %TEMP%\ewe3mztp.out
  • %TEMP%\ewe3mztp.cmdline
  • <Drive name for removable media>:\cscd6a10a8a8ad645879b9f2d6fcf46373a.tmp
  • %TEMP%\ewe3mztp.0.cs
  • <Drive name for removable media>:\csc34cdb656a53a4c499b6a25423de6635f.tmp
  • %TEMP%\nl2f5nfb.cmdline
  • %TEMP%\nl2f5nfb.out
  • %TEMP%\nl2f5nfb.0.cs
  • %TEMP%\rese800.tmp
  • <Drive name for removable media>:\csc544027a53c0b4a518c8c204ca7eef467.tmp
  • %TEMP%\1qvzds2t.cmdline
  • %TEMP%\1qvzds2t.0.cs
  • %TEMP%\1qvzds2t.out
  • %TEMP%\resea14.tmp
  • <Drive name for removable media>:\csca4c5a58d1c3d49febb381c2978778e49.tmp
  • %TEMP%\zrccid45.out
  • %TEMP%\rese5ed.tmp
  • %TEMP%\0j2dx2sp.out
  • %TEMP%\0j2dx2sp.0.cs
Moves the following files
  • from %TEMP%\b09bbaecf0\dotnetzip-hlmbswbb.tmp to %TEMP%\b09bbaecf0\user_united states_b09bbaecf0_05-14-2020 14.27.26.zip
Changes user data files extensions (Trojan.Encoder).
Network activity
TCP
HTTP GET requests
  • http://ap#.#pify.org/
  • 'drive.google.com':443
  • 'do#########ocs.googleusercontent.com':443
  • 'sm##.gmail.com':587
  • UDP
    • DNS ASK drive.google.com
    • DNS ASK do#########ocs.googleusercontent.com
    • DNS ASK ap#.#pify.org
    • DNS ASK sm##.gmail.com
    Miscellaneous
    Creates and executes the following
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe' ' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\rz4zfhsr.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES564B.tmp" "<Drive name for removable media>:\CSC9B05F635F42E44A99F21BF021CEC44.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\33c41ygx.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54F3.tmp" "<Drive name for removable media>:\CSCF9F30BAB93CF4083876F9C7C615DA62E.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xni0vmu0.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES537C.tmp" "<Drive name for removable media>:\CSC37C1DACE3EF34937A5705F758CA55BA5.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\q0sn4y2n.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2680.tmp" "<Drive name for removable media>:\CSC3747B07E58A64FA2A3363C1525F0ABC.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0j2dx2sp.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES247D.tmp" "<Drive name for removable media>:\CSCAC2A30C684CE4D2A9F86C2FE3D7DA710.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\qreojnu3.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES225A.tmp" "<Drive name for removable media>:\CSC3022D59E8EF4D77955D1F83AA62794B.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\01qt01uy.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2066.tmp" "<Drive name for removable media>:\CSC2AF1C965AC9E45628B5A23F812E3E5DF.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES585E.tmp" "<Drive name for removable media>:\CSCC83B2EB6CE424907B7502CAAFCFA646B.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\pubsjsp3.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ru31kgeb.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1C30.tmp" "<Drive name for removable media>:\CSCF03FF74AA5834481A16CAADED9E7872.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1xijb4ih.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1A1C.tmp" "<Drive name for removable media>:\CSC9F6C97561C27449C8A8A97ED247BE1C.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\fqj4ipzf.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1828.tmp" "<Drive name for removable media>:\CSCCD4A281EB2D0472B9193DE11EA80D988.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\mwx1xc5i.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1625.tmp" "<Drive name for removable media>:\CSC4397AAF54FE14AD7B630ADE8828E4E70.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2ubhbbgu.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1412.tmp" "<Drive name for removable media>:\CSCD1223637F3E6439981A8A832245C38EA.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0f4ylewq.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES11FE.tmp" "<Drive name for removable media>:\CSC7EA37FAA50D64337B1FA48E210B65E8F.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\j21rqvig.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFFB.tmp" "<Drive name for removable media>:\CSCDA2AA511AE246CAA253E26E2C6A5F.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1E43.tmp" "<Drive name for removable media>:\CSCDDB74175974641F5BAFA47F24FA06C.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ppaeq04d.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5A52.tmp" "<Drive name for removable media>:\CSC3B31A41B70534307847BBE8C4AB1B2A9.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\iouhst0v.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0chnfqju.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES68AA.tmp" "<Drive name for removable media>:\CSC9A7BF32724E04B79A8F2C79778DC250.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\w0bhrcgn.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6A02.tmp" "<Drive name for removable media>:\CSC3E69F460ED514DCA904F39DDC7D03E9.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\hrdmmggj.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6B59.tmp" "<Drive name for removable media>:\CSC6288BD48F6734CC3BB965D6D9714E5.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6CA1.tmp" "<Drive name for removable media>:\CSCF24F31E4EF4149C48D38206C4A53F67.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\czpfktpq.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\32kmhqie.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6E09.tmp" "<Drive name for removable media>:\CSCBFEFF3D95C7548B5A773E76645FF22C.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\pndxm1ka.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6F61.tmp" "<Drive name for removable media>:\CSC8EE8EE1E1EFD46F782E7358D1B628DD7.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\3ixvttn3.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES70A9.tmp" "<Drive name for removable media>:\CSCD76117992B4B482E8F8F74CB967BCB15.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6723.tmp" "<Drive name for removable media>:\CSCEE2C8C5FD1094108909D6A5223223388.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\r125poew.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES65CB.tmp" "<Drive name for removable media>:\CSC9742F04C008412E822FAE7DA2A088D4.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ytspus3x.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6464.tmp" "<Drive name for removable media>:\CSC2EB07F6D991B4B73B486CEA0638EC5ED.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\k5dsirxi.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES631C.tmp" "<Drive name for removable media>:\CSC3B293B5DFB9C49619765C141393F14A4.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\a2nezx3z.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES61C4.tmp" "<Drive name for removable media>:\CSC4057378162E54A9D913F8AC3AFFA76E.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1kwcgcct.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES607C.tmp" "<Drive name for removable media>:\CSC2184BCB1470A40F9B7686052739430B2.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\oepilmsb.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5F34.tmp" "<Drive name for removable media>:\CSC123125BCD0A14DD3B0FAAFE9BB7F86.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\03ro0vrs.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5D7E.tmp" "<Drive name for removable media>:\CSCD0D96F48E1FE4940ABDDF2B6CC73BDFD.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\m5zg4ket.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5BB9.tmp" "<Drive name for removable media>:\CSCF758007AEB194A9496804CBEE9F83A76.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\zr43fg0a.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\skj0x5d5.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDF7.tmp" "<Drive name for removable media>:\CSC69F352D2D4E24766A6F3E19DDCF8EC32.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES329.tmp" "<Drive name for removable media>:\CSCBF48C47B8A9048639E81D2C8AA3733A9.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE3CA.tmp" "<Drive name for removable media>:\CSC35DD798F61724CB2B339572B9D364651.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ewe3mztp.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE198.tmp" "<Drive name for removable media>:\CSC956AC723614841A39DF1AA51954A8178.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\42cop5zn.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDE7B.tmp" "<Drive name for removable media>:\CSCD6A10A8A8AD645879B9F2D6FCF46373A.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tpylr2fc.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDC58.tmp" "<Drive name for removable media>:\CSCAB39895EF2B748A5A3F123E2FF4555DC.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\13u4beq5.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDA16.tmp" "<Drive name for removable media>:\CSC2FE22994CD0E45039CC39A7D32AC93BF.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1f3eb302.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD7A5.tmp" "<Drive name for removable media>:\CSC5ACCFB5E4C1446D499459603EE1C962.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\h5nhrhs4.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD553.tmp" "<Drive name for removable media>:\CSC3E654F0B25634ECEB5B158E8208AF126.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\5wnthktu.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\nl2f5nfb.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD2C3.tmp" "<Drive name for removable media>:\CSC53144EBFDE8F4E1E97F419BD572B6E57.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD042.tmp" "<Drive name for removable media>:\CSC504CC1B3819C405DB076F3996FA167F.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\glu4ipfq.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCDF0.tmp" "<Drive name for removable media>:\CSC2E65F4B0351849209165D0EB3351CF8.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xfx42sgm.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBCE.tmp" "<Drive name for removable media>:\CSC400AF67636B94A8383BE2F1832E7A2D5.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\egdzlovs.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC9AB.tmp" "<Drive name for removable media>:\CSCE29CE2A994214B029D3D87AEA192AC70.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xxffkkzz.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC6FB.tmp" "<Drive name for removable media>:\CSCB5AF6C20CD524857BCECD33952137E77.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\mse4hl0i.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC42C.tmp" "<Drive name for removable media>:\CSC52096DCEB9714AC991EC734E684FBEAE.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dbp3unt4.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC19C.tmp" "<Drive name for removable media>:\CSC1568D7375294EC8BBDC3275ADFF01B.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bunulmqd.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0vexljrm.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE5ED.tmp" "<Drive name for removable media>:\CSC34CDB656A53A4C499B6A25423DE6635F.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1qvzds2t.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE800.tmp" "<Drive name for removable media>:\CSC544027A53C0B4A518C8C204CA7EEF467.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFCF0.tmp" "<Drive name for removable media>:\CSC355E9E7B17304762A867E9C4ACB4617.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tqs1zeae.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFEE4.tmp" "<Drive name for removable media>:\CSC56572ECEFD5B4FFFBA4D6D2A7E2A958.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\gootnmdd.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES126.tmp" "<Drive name for removable media>:\CSCE9B4BD79FBB94D2790A5D510556DF0BC.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\23xjzees.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ikqwa32w.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBD4.tmp" "<Drive name for removable media>:\CSCFB2A3A9049A4B76A22D6981A7865721.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54C.tmp" "<Drive name for removable media>:\CSC7D0A86F4F5C442A289225199F47F4AF.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tt4ylqvv.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES77F.tmp" "<Drive name for removable media>:\CSC54B7DED5312549B6A9AA96C20369950.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\njcxuein.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9A2.tmp" "<Drive name for removable media>:\CSC69E213C757FE43DC88AAACD83C1A63AB.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\giik1o2m.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0sb1eslh.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFADC.tmp" "<Drive name for removable media>:\CSC204A28FE38B0439F804F1E3DFACE25F.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2eqa31gp.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF86B.tmp" "<Drive name for removable media>:\CSCFD73B3C2D48942A691BCB2986D895EA4.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2o0mmpvy.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF4B2.tmp" "<Drive name for removable media>:\CSC8BA01F00CAEC4DB6BD50754DBED4E43.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dlqjpzx3.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF29F.tmp" "<Drive name for removable media>:\CSC3035D9F8AE0E42349BBDF295922E181.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1gvuwwmp.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF0AB.tmp" "<Drive name for removable media>:\CSC31CD1D6163741899E56E72C27905BEE.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jjj2qqrs.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEE98.tmp" "<Drive name for removable media>:\CSC6B08C0FB6D2483E9E2E336A177C7364.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\cjpykfjh.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEC94.tmp" "<Drive name for removable media>:\CSC11AF1EB6A474FCB83DBA05FC327CBD.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xihjbsk0.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEA14.tmp" "<Drive name for removable media>:\CSCA4C5A58D1C3D49FEBB381C2978778E49.TMP"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\zrccid45.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dchigvat.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7200.tmp" "<Drive name for removable media>:\CSC7FFF1506AE84922854A2F17F0789DE.TMP"' (with hidden window)
    Executes the following
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\rz4zfhsr.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES564B.tmp" "<Drive name for removable media>:\CSC9B05F635F42E44A99F21BF021CEC44.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\33c41ygx.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54F3.tmp" "<Drive name for removable media>:\CSCF9F30BAB93CF4083876F9C7C615DA62E.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xni0vmu0.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES537C.tmp" "<Drive name for removable media>:\CSC37C1DACE3EF34937A5705F758CA55BA5.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\q0sn4y2n.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2680.tmp" "<Drive name for removable media>:\CSC3747B07E58A64FA2A3363C1525F0ABC.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0j2dx2sp.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES247D.tmp" "<Drive name for removable media>:\CSCAC2A30C684CE4D2A9F86C2FE3D7DA710.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\qreojnu3.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES225A.tmp" "<Drive name for removable media>:\CSC3022D59E8EF4D77955D1F83AA62794B.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\01qt01uy.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2066.tmp" "<Drive name for removable media>:\CSC2AF1C965AC9E45628B5A23F812E3E5DF.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES585E.tmp" "<Drive name for removable media>:\CSCC83B2EB6CE424907B7502CAAFCFA646B.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\pubsjsp3.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ru31kgeb.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1C30.tmp" "<Drive name for removable media>:\CSCF03FF74AA5834481A16CAADED9E7872.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1xijb4ih.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1A1C.tmp" "<Drive name for removable media>:\CSC9F6C97561C27449C8A8A97ED247BE1C.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\fqj4ipzf.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1828.tmp" "<Drive name for removable media>:\CSCCD4A281EB2D0472B9193DE11EA80D988.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\mwx1xc5i.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1625.tmp" "<Drive name for removable media>:\CSC4397AAF54FE14AD7B630ADE8828E4E70.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2ubhbbgu.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1412.tmp" "<Drive name for removable media>:\CSCD1223637F3E6439981A8A832245C38EA.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0f4ylewq.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES11FE.tmp" "<Drive name for removable media>:\CSC7EA37FAA50D64337B1FA48E210B65E8F.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\j21rqvig.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFFB.tmp" "<Drive name for removable media>:\CSCDA2AA511AE246CAA253E26E2C6A5F.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1E43.tmp" "<Drive name for removable media>:\CSCDDB74175974641F5BAFA47F24FA06C.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ppaeq04d.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5A52.tmp" "<Drive name for removable media>:\CSC3B31A41B70534307847BBE8C4AB1B2A9.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\iouhst0v.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0chnfqju.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES68AA.tmp" "<Drive name for removable media>:\CSC9A7BF32724E04B79A8F2C79778DC250.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\w0bhrcgn.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6A02.tmp" "<Drive name for removable media>:\CSC3E69F460ED514DCA904F39DDC7D03E9.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\hrdmmggj.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6B59.tmp" "<Drive name for removable media>:\CSC6288BD48F6734CC3BB965D6D9714E5.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6CA1.tmp" "<Drive name for removable media>:\CSCF24F31E4EF4149C48D38206C4A53F67.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\czpfktpq.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\32kmhqie.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6E09.tmp" "<Drive name for removable media>:\CSCBFEFF3D95C7548B5A773E76645FF22C.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\pndxm1ka.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6F61.tmp" "<Drive name for removable media>:\CSC8EE8EE1E1EFD46F782E7358D1B628DD7.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\3ixvttn3.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES70A9.tmp" "<Drive name for removable media>:\CSCD76117992B4B482E8F8F74CB967BCB15.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6723.tmp" "<Drive name for removable media>:\CSCEE2C8C5FD1094108909D6A5223223388.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\r125poew.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES65CB.tmp" "<Drive name for removable media>:\CSC9742F04C008412E822FAE7DA2A088D4.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ytspus3x.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6464.tmp" "<Drive name for removable media>:\CSC2EB07F6D991B4B73B486CEA0638EC5ED.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\k5dsirxi.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES631C.tmp" "<Drive name for removable media>:\CSC3B293B5DFB9C49619765C141393F14A4.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\a2nezx3z.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES61C4.tmp" "<Drive name for removable media>:\CSC4057378162E54A9D913F8AC3AFFA76E.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1kwcgcct.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES607C.tmp" "<Drive name for removable media>:\CSC2184BCB1470A40F9B7686052739430B2.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\oepilmsb.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5F34.tmp" "<Drive name for removable media>:\CSC123125BCD0A14DD3B0FAAFE9BB7F86.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\03ro0vrs.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5D7E.tmp" "<Drive name for removable media>:\CSCD0D96F48E1FE4940ABDDF2B6CC73BDFD.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\m5zg4ket.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5BB9.tmp" "<Drive name for removable media>:\CSCF758007AEB194A9496804CBEE9F83A76.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\zr43fg0a.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\skj0x5d5.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDF7.tmp" "<Drive name for removable media>:\CSC69F352D2D4E24766A6F3E19DDCF8EC32.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES329.tmp" "<Drive name for removable media>:\CSCBF48C47B8A9048639E81D2C8AA3733A9.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE3CA.tmp" "<Drive name for removable media>:\CSC35DD798F61724CB2B339572B9D364651.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ewe3mztp.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE198.tmp" "<Drive name for removable media>:\CSC956AC723614841A39DF1AA51954A8178.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\42cop5zn.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDE7B.tmp" "<Drive name for removable media>:\CSCD6A10A8A8AD645879B9F2D6FCF46373A.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tpylr2fc.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDC58.tmp" "<Drive name for removable media>:\CSCAB39895EF2B748A5A3F123E2FF4555DC.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\13u4beq5.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDA16.tmp" "<Drive name for removable media>:\CSC2FE22994CD0E45039CC39A7D32AC93BF.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1f3eb302.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD7A5.tmp" "<Drive name for removable media>:\CSC5ACCFB5E4C1446D499459603EE1C962.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\h5nhrhs4.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD553.tmp" "<Drive name for removable media>:\CSC3E654F0B25634ECEB5B158E8208AF126.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\5wnthktu.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\nl2f5nfb.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD2C3.tmp" "<Drive name for removable media>:\CSC53144EBFDE8F4E1E97F419BD572B6E57.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD042.tmp" "<Drive name for removable media>:\CSC504CC1B3819C405DB076F3996FA167F.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\glu4ipfq.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCDF0.tmp" "<Drive name for removable media>:\CSC2E65F4B0351849209165D0EB3351CF8.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xfx42sgm.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBCE.tmp" "<Drive name for removable media>:\CSC400AF67636B94A8383BE2F1832E7A2D5.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\egdzlovs.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC9AB.tmp" "<Drive name for removable media>:\CSCE29CE2A994214B029D3D87AEA192AC70.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xxffkkzz.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC6FB.tmp" "<Drive name for removable media>:\CSCB5AF6C20CD524857BCECD33952137E77.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\mse4hl0i.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC42C.tmp" "<Drive name for removable media>:\CSC52096DCEB9714AC991EC734E684FBEAE.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dbp3unt4.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC19C.tmp" "<Drive name for removable media>:\CSC1568D7375294EC8BBDC3275ADFF01B.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bunulmqd.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0vexljrm.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE5ED.tmp" "<Drive name for removable media>:\CSC34CDB656A53A4C499B6A25423DE6635F.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1qvzds2t.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE800.tmp" "<Drive name for removable media>:\CSC544027A53C0B4A518C8C204CA7EEF467.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFCF0.tmp" "<Drive name for removable media>:\CSC355E9E7B17304762A867E9C4ACB4617.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tqs1zeae.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFEE4.tmp" "<Drive name for removable media>:\CSC56572ECEFD5B4FFFBA4D6D2A7E2A958.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\gootnmdd.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES126.tmp" "<Drive name for removable media>:\CSCE9B4BD79FBB94D2790A5D510556DF0BC.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\23xjzees.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ikqwa32w.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBD4.tmp" "<Drive name for removable media>:\CSCFB2A3A9049A4B76A22D6981A7865721.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54C.tmp" "<Drive name for removable media>:\CSC7D0A86F4F5C442A289225199F47F4AF.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\tt4ylqvv.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES77F.tmp" "<Drive name for removable media>:\CSC54B7DED5312549B6A9AA96C20369950.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\njcxuein.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9A2.tmp" "<Drive name for removable media>:\CSC69E213C757FE43DC88AAACD83C1A63AB.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\giik1o2m.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\0sb1eslh.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFADC.tmp" "<Drive name for removable media>:\CSC204A28FE38B0439F804F1E3DFACE25F.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2eqa31gp.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF86B.tmp" "<Drive name for removable media>:\CSCFD73B3C2D48942A691BCB2986D895EA4.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2o0mmpvy.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF4B2.tmp" "<Drive name for removable media>:\CSC8BA01F00CAEC4DB6BD50754DBED4E43.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dlqjpzx3.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF29F.tmp" "<Drive name for removable media>:\CSC3035D9F8AE0E42349BBDF295922E181.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\1gvuwwmp.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF0AB.tmp" "<Drive name for removable media>:\CSC31CD1D6163741899E56E72C27905BEE.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jjj2qqrs.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEE98.tmp" "<Drive name for removable media>:\CSC6B08C0FB6D2483E9E2E336A177C7364.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\cjpykfjh.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEC94.tmp" "<Drive name for removable media>:\CSC11AF1EB6A474FCB83DBA05FC327CBD.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xihjbsk0.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEA14.tmp" "<Drive name for removable media>:\CSCA4C5A58D1C3D49FEBB381C2978778E49.TMP"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\zrccid45.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\dchigvat.cmdline"
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7200.tmp" "<Drive name for removable media>:\CSC7FFF1506AE84922854A2F17F0789DE.TMP"

    Рекомендации по лечению

    1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
    2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
    Скачать Dr.Web

    По серийному номеру

    Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

    На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

    Скачать Dr.Web

    По серийному номеру

    1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
    2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
      • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
      • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
      • выключите устройство и включите его в обычном режиме.

    Подробнее о Dr.Web для Android

    Демо бесплатно на 14 дней

    Выдаётся при установке