Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader24.37866

Добавлен в вирусную базу Dr.Web: 2017-04-13

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\xxx\xxx.exe
  • <Drive name for removable media>:\delongcacert.pem
  • <Drive name for removable media>:\cert.pem
  • <Drive name for removable media>:\2015-02-worms-nanoparticle-toxicity.pdf
  • <Drive name for removable media>:\fil_20060629111052.pdf
  • <Drive name for removable media>:\clip_480_5sec_6mbps_h264.mp4
  • <Drive name for removable media>:\video_1.mp4
  • <Drive name for removable media>:\video.mp4
  • <Drive name for removable media>:\51.mp4
  • <Drive name for removable media>:\spanner.mov
  • <Drive name for removable media>:\scan.mov
  • <Drive name for removable media>:\ck_ugo.pem
  • <Drive name for removable media>:\etc6_m_1.mov
  • <Drive name for removable media>:\pushkin.jpg
  • <Drive name for removable media>:\2.jpg
  • <Drive name for removable media>:\13.jpg
  • <Drive name for removable media>:\region-north-karelia.jpg
  • <Drive name for removable media>:\1189.jpg
  • <Drive name for removable media>:\region-north-karelia.jpeg
  • <Drive name for removable media>:\13.jpeg
  • <Drive name for removable media>:\4f0bf7ff71f28.jpeg
  • <Drive name for removable media>:\3.jpeg
  • <Drive name for removable media>:\api-hashmap.html
  • <Drive name for removable media>:\parnas_01.jpg
  • <Drive name for removable media>:\hhhlcert.pem
  • <Drive name for removable media>:\irgeek.pem
  • <Drive name for removable media>:\server.pem
  • <Drive name for removable media>:\phytoremediation.rtf
  • <Drive name for removable media>:\waterlandhealthkano.rtf
  • <Drive name for removable media>:\krsweden.rtf
  • <Drive name for removable media>:\swc_2009-03-02.rdf
  • <Drive name for removable media>:\20140114.rdf
  • <Drive name for removable media>:\schema.rdf
  • <Drive name for removable media>:\elvisimp.rdf
  • <Drive name for removable media>:\middaugh_keynote.pptx
  • <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
  • <Drive name for removable media>:\indogerman2010.pptx
  • <Drive name for removable media>:\samieee_obiee_presentation.pptx
  • <Drive name for removable media>:\gruenspecht_02172016.pptx
  • <Drive name for removable media>:\waterresourcesag.pptx
  • <Drive name for removable media>:\hypothyroidism_slides.pptx.exe
  • <Drive name for removable media>:\hypothyroidism_slides.pptx
  • <Drive name for removable media>:\asaprojectcompetition.pptx.exe
  • <Drive name for removable media>:\asaprojectcompetition.pptx
  • <Drive name for removable media>:\ksearch_esa_talk.ppt
  • <Drive name for removable media>:\mappingconcepthubberlin.ppt
  • <Drive name for removable media>:\sim_gametheory_to_finance.ppt
  • <Drive name for removable media>:\ppswamp.ppt
  • <Drive name for removable media>:\file1.ppt
  • <Drive name for removable media>:\dissolveanother.png
  • <Drive name for removable media>:\tree_view.html
  • <Drive name for removable media>:\myhrvoldhanssenbiharfamine.rtf
  • <Drive name for removable media>:\iisstart.html
  • <Drive name for removable media>:\howto-index.html
  • <Drive name for removable media>:\pmd.cer.exe
  • <Drive name for removable media>:\pmd.cer
  • <Drive name for removable media>:\contoso_1.cer.exe
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\coffee.bmp.exe
  • <Drive name for removable media>:\coffee.bmp
  • <Drive name for removable media>:\tileimage.bmp.exe
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\dialmap.bmp.exe
  • <Drive name for removable media>:\dialmap.bmp
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\default.bmp.exe
  • <Drive name for removable media>:\dashborder_120.bmp.exe
  • <Drive name for removable media>:\dashborder_120.bmp
  • <Drive name for removable media>:\dashborder_144.bmp.exe
  • <Drive name for removable media>:\dashborder_144.bmp
  • <Drive name for removable media>:\dial.bmp.exe
  • <Drive name for removable media>:\dial.bmp
  • <Drive name for removable media>:\split.avi.exe
  • <Drive name for removable media>:\split.avi
  • <Drive name for removable media>:\join.avi.exe
  • <Drive name for removable media>:\join.avi
  • <Drive name for removable media>:\default.bmp
  • <Drive name for removable media>:\testcertificate.cer.exe
  • <Drive name for removable media>:\contoso.cer
  • <Drive name for removable media>:\contoso.cer.exe
  • <Drive name for removable media>:\about.htm
  • <Drive name for removable media>:\iisstart.htm
  • <Drive name for removable media>:\trivial-merge.htm
  • <Drive name for removable media>:\advice_process.htm
  • <Drive name for removable media>:\alert.htm
  • <Drive name for removable media>:\calc.exe
  • <Drive name for removable media>:\chromesetup.exe
  • <Drive name for removable media>:\jre-7u75-windows-i586-iftw.exe
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\utorrent.exe
  • <Drive name for removable media>:\glidescope_review_rev_010.docx
  • <Drive name for removable media>:\issi2013_template_for_posters.docx
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
  • <Drive name for removable media>:\nwfieldnotes1966.docx
  • <Drive name for removable media>:\adhd_and_obesity.docx
  • <Drive name for removable media>:\fi51.doc.exe
  • <Drive name for removable media>:\fi51.doc
  • <Drive name for removable media>:\sdkfailsafeemulator.cer.exe
  • <Drive name for removable media>:\sdkfailsafeemulator.cer
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer.exe
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer.exe
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\browse.html
  • <Drive name for removable media>:\router_manual.rtf
Modifies file system
Creates the following files
  • %ALLUSERSPROFILE%\xxx\join.ico
  • %TEMP%\l7f0-nmy.cmdline
  • %TEMP%\l7f0-nmy.0.vb
  • %ALLUSERSPROFILE%\xxx\scan.ico
  • %TEMP%\res6fb4.tmp
  • %TEMP%\vbc6fa3.tmp
  • %TEMP%\zd2vuilh.out
  • %TEMP%\zd2vuilh.cmdline
  • %TEMP%\zd2vuilh.0.vb
  • %ALLUSERSPROFILE%\xxx\etc6_m_1.ico
  • %TEMP%\res6cd7.tmp
  • %TEMP%\crybisci.out
  • %TEMP%\vbc6cc6.tmp
  • %TEMP%\ubsf3zdk.cmdline
  • %TEMP%\ubsf3zdk.0.vb
  • %ALLUSERSPROFILE%\xxx\parnas_01.ico
  • %TEMP%\res692f.tmp
  • %TEMP%\vbc692e.tmp
  • %TEMP%\opvcjqgo.out
  • %TEMP%\opvcjqgo.cmdline
  • %TEMP%\opvcjqgo.0.vb
  • %ALLUSERSPROFILE%\xxx\pushkin.ico
  • %TEMP%\res670d.tmp
  • %TEMP%\ubsf3zdk.out
  • %TEMP%\vbc670c.tmp
  • %TEMP%\l7f0-nmy.out
  • %TEMP%\vbc78f6.tmp
  • %TEMP%\6hv5rejb.out
  • %TEMP%\6hv5rejb.cmdline
  • %TEMP%\6hv5rejb.0.vb
  • %ALLUSERSPROFILE%\xxx\video_1.ico
  • %TEMP%\res7ba5.tmp
  • %TEMP%\vbc7b95.tmp
  • %TEMP%\alth8vpy.out
  • %TEMP%\alth8vpy.cmdline
  • %TEMP%\alth8vpy.0.vb
  • %ALLUSERSPROFILE%\xxx\video.ico
  • %TEMP%\res72cf.tmp
  • %TEMP%\vbc72bf.tmp
  • %TEMP%\knpie3by.out
  • %TEMP%\knpie3by.cmdline
  • %TEMP%\knpie3by.0.vb
  • %ALLUSERSPROFILE%\xxx\51.ico
  • %TEMP%\res75eb.tmp
  • %TEMP%\vbc75ea.tmp
  • %TEMP%\8ladetd1.out
  • %TEMP%\8ladetd1.cmdline
  • %TEMP%\8ladetd1.0.vb
  • %ALLUSERSPROFILE%\xxx\spanner.ico
  • %TEMP%\res7907.tmp
  • %TEMP%\crybisci.cmdline
  • %TEMP%\crybisci.0.vb
  • %ALLUSERSPROFILE%\xxx\2.ico
  • %TEMP%\res5754.tmp
  • %TEMP%\vbc5753.tmp
  • %TEMP%\gda9aywv.out
  • %TEMP%\gda9aywv.cmdline
  • %TEMP%\gda9aywv.0.vb
  • %ALLUSERSPROFILE%\xxx\4f0bf7ff71f28.ico
  • %TEMP%\res54d4.tmp
  • %TEMP%\vbc54c4.tmp
  • %TEMP%\mns5dxkt.out
  • %TEMP%\ql4dbfg_.0.vb
  • %TEMP%\mns5dxkt.cmdline
  • %ALLUSERSPROFILE%\xxx\3.ico
  • %TEMP%\res51e7.tmp
  • %TEMP%\vbc51e6.tmp
  • %TEMP%\zt_8ar_x.out
  • %TEMP%\zt_8ar_x.cmdline
  • %TEMP%\zt_8ar_x.0.vb
  • %ALLUSERSPROFILE%\xxx\api-hashmap.ico
  • %TEMP%\res4efb.tmp
  • %TEMP%\vbc4eea.tmp
  • %TEMP%\kutdm1xr.out
  • %TEMP%\mns5dxkt.0.vb
  • %TEMP%\ql4dbfg_.cmdline
  • %ALLUSERSPROFILE%\xxx\13.ico
  • %TEMP%\ql4dbfg_.out
  • %TEMP%\res64ac.tmp
  • %TEMP%\vbc5f20.tmp
  • %TEMP%\vbc64ab.tmp
  • %TEMP%\mwh-niw1.out
  • %TEMP%\mwh-niw1.cmdline
  • %TEMP%\mwh-niw1.0.vb
  • %TEMP%\res61df.tmp
  • %TEMP%\vbc61de.tmp
  • %TEMP%\mc6u2rjm.out
  • %TEMP%\mc6u2rjm.cmdline
  • %TEMP%\mc6u2rjm.0.vb
  • %TEMP%\res5f21.tmp
  • %TEMP%\_yopawda.out
  • %TEMP%\vbc59f2.tmp
  • %TEMP%\_yopawda.cmdline
  • %TEMP%\_yopawda.0.vb
  • %ALLUSERSPROFILE%\xxx\1189.ico
  • %TEMP%\res5ca1.tmp
  • %TEMP%\vbc5ca0.tmp
  • %TEMP%\ob0jzy7k.out
  • %TEMP%\ob0jzy7k.cmdline
  • %TEMP%\ob0jzy7k.0.vb
  • %ALLUSERSPROFILE%\xxx\region-north-karelia.ico
  • %TEMP%\res5a02.tmp
  • %TEMP%\vbc7edf.tmp
  • %TEMP%\res7ef0.tmp
  • %ALLUSERSPROFILE%\xxx\clip_480_5sec_6mbps_h264.ico
  • %TEMP%\tykqmicx.0.vb
  • %TEMP%\vbc9f2b.tmp
  • %TEMP%\vuewfy3k.out
  • %TEMP%\vuewfy3k.cmdline
  • %TEMP%\vuewfy3k.0.vb
  • %ALLUSERSPROFILE%\xxx\sim_gametheory_to_finance.ico
  • %TEMP%\res9d29.tmp
  • %TEMP%\vbc9d28.tmp
  • %TEMP%\8z50kemm.out
  • %TEMP%\8z50kemm.cmdline
  • %TEMP%\8z50kemm.0.vb
  • %TEMP%\res9f2c.tmp
  • %ALLUSERSPROFILE%\xxx\ppswamp.ico
  • %TEMP%\vbc9af7.tmp
  • %TEMP%\u1s0nf4x.out
  • %TEMP%\u1s0nf4x.cmdline
  • %TEMP%\u1s0nf4x.0.vb
  • %ALLUSERSPROFILE%\xxx\file1.ico
  • %TEMP%\res9849.tmp
  • %TEMP%\vbc9839.tmp
  • %TEMP%\8_lcyfrx.out
  • %TEMP%\8_lcyfrx.cmdline
  • %TEMP%\8_lcyfrx.0.vb
  • %TEMP%\res9af8.tmp
  • %ALLUSERSPROFILE%\xxx\mappingconcepthubberlin.ico
  • %TEMP%\7npbmyou.0.vb
  • %TEMP%\7npbmyou.cmdline
  • %TEMP%\rr8j2tbq.0.vb
  • %ALLUSERSPROFILE%\xxx\waterresourcesag.ico
  • %TEMP%\resa988.tmp
  • %TEMP%\vbca978.tmp
  • %TEMP%\dstcx7pd.out
  • %TEMP%\dstcx7pd.cmdline
  • %TEMP%\dstcx7pd.0.vb
  • %ALLUSERSPROFILE%\xxx\hypothyroidism_slides.ico
  • %TEMP%\resa6bb.tmp
  • %TEMP%\vbca6ba.tmp
  • %TEMP%\9fwpydvy.out
  • %TEMP%\9fwpydvy.cmdline
  • %TEMP%\9fwpydvy.0.vb
  • %ALLUSERSPROFILE%\xxx\asaprojectcompetition.ico
  • %TEMP%\resa3ed.tmp
  • %TEMP%\vbca3ec.tmp
  • %TEMP%\xjk3n_tn.out
  • %TEMP%\xjk3n_tn.cmdline
  • %TEMP%\xjk3n_tn.0.vb
  • %ALLUSERSPROFILE%\xxx\ksearch_esa_talk.ico
  • %TEMP%\resa17d.tmp
  • %TEMP%\vbca17c.tmp
  • %TEMP%\7npbmyou.out
  • %ALLUSERSPROFILE%\xxx\dissolveanother.ico
  • %TEMP%\vbc958a.tmp
  • %TEMP%\res959b.tmp
  • %TEMP%\eh75avoa.out
  • %TEMP%\res8a55.tmp
  • %TEMP%\vbc8a44.tmp
  • %TEMP%\1rstbxon.out
  • %TEMP%\1rstbxon.cmdline
  • %TEMP%\1rstbxon.0.vb
  • %ALLUSERSPROFILE%\xxx\cert.ico
  • %TEMP%\res87c6.tmp
  • %TEMP%\vbc87b5.tmp
  • %TEMP%\ykiprpv0.out
  • %TEMP%\ykiprpv0.cmdline
  • %ALLUSERSPROFILE%\xxx\delongcacert.ico
  • %TEMP%\ykiprpv0.0.vb
  • %TEMP%\res846c.tmp
  • %TEMP%\vbc845b.tmp
  • %TEMP%\8moltxjt.out
  • %TEMP%\8moltxjt.cmdline
  • %TEMP%\8moltxjt.0.vb
  • %ALLUSERSPROFILE%\xxx\fil_20060629111052.ico
  • %TEMP%\res819e.tmp
  • %TEMP%\vbc819d.tmp
  • %TEMP%\tykqmicx.out
  • %TEMP%\tykqmicx.cmdline
  • %ALLUSERSPROFILE%\xxx\2015-02-worms-nanoparticle-toxicity.ico
  • %TEMP%\abwerfge.0.vb
  • %TEMP%\abwerfge.cmdline
  • %TEMP%\abwerfge.out
  • %TEMP%\eh75avoa.cmdline
  • %TEMP%\eh75avoa.0.vb
  • %ALLUSERSPROFILE%\xxx\server.ico
  • %TEMP%\res933b.tmp
  • %TEMP%\vbc933a.tmp
  • %TEMP%\8oxaii-x.out
  • %TEMP%\8oxaii-x.cmdline
  • %TEMP%\8oxaii-x.0.vb
  • %ALLUSERSPROFILE%\xxx\irgeek.ico
  • %TEMP%\res90f9.tmp
  • %TEMP%\vbc90f8.tmp
  • %TEMP%\oqvh076b.out
  • %TEMP%\oqvh076b.cmdline
  • %TEMP%\oqvh076b.0.vb
  • %ALLUSERSPROFILE%\xxx\hhhlcert.ico
  • %TEMP%\res8eb8.tmp
  • %TEMP%\vbc8eb7.tmp
  • %TEMP%\me2eodir.out
  • %TEMP%\me2eodir.cmdline
  • %TEMP%\me2eodir.0.vb
  • %ALLUSERSPROFILE%\xxx\ck_ugo.ico
  • %TEMP%\res8c87.tmp
  • %TEMP%\vbc8c76.tmp
  • %TEMP%\rr8j2tbq.cmdline
  • %TEMP%\kutdm1xr.cmdline
  • %TEMP%\kutdm1xr.0.vb
  • %ALLUSERSPROFILE%\xxx\tree_view.ico
  • %TEMP%\vbcd42f.tmp
  • %TEMP%\tn7mfv7c.out
  • %TEMP%\tn7mfv7c.cmdline
  • %TEMP%\tn7mfv7c.0.vb
  • %ALLUSERSPROFILE%\xxx\contoso.ico
  • %TEMP%\rescffc.tmp
  • %TEMP%\vbccffb.tmp
  • %TEMP%\sot3niwh.out
  • %TEMP%\sot3niwh.cmdline
  • %TEMP%\sot3niwh.0.vb
  • %TEMP%\resc1ba.tmp
  • %ALLUSERSPROFILE%\xxx\testcertificate.ico
  • %TEMP%\vbccb79.tmp
  • %TEMP%\aigivj6z.out
  • %TEMP%\aigivj6z.cmdline
  • %TEMP%\aigivj6z.0.vb
  • %ALLUSERSPROFILE%\xxx\pmd.ico
  • %TEMP%\resc64c.tmp
  • %TEMP%\vbcc64b.tmp
  • %TEMP%\rjlgo4ap.out
  • %TEMP%\rjlgo4ap.cmdline
  • %TEMP%\rjlgo4ap.0.vb
  • %TEMP%\rescb7a.tmp
  • %ALLUSERSPROFILE%\xxx\contoso_1.ico
  • %TEMP%\resd430.tmp
  • %ALLUSERSPROFILE%\xxx\sdkfailsafeemulator.ico
  • %TEMP%\rese9c3.tmp
  • %TEMP%\vbce9b2.tmp
  • %TEMP%\vbrp6-ct.out
  • %TEMP%\vbrp6-ct.cmdline
  • %TEMP%\vbrp6-ct.0.vb
  • %ALLUSERSPROFILE%\xxx\fi51.ico
  • %TEMP%\rese3ba.tmp
  • %TEMP%\vbce3b9.tmp
  • %TEMP%\0fkpscgx.out
  • %TEMP%\0fkpscgx.cmdline
  • %TEMP%\hzcgvp9l.0.vb
  • %ALLUSERSPROFILE%\xxx\sdksampleprivdeveloper.ico
  • %TEMP%\resde9c.tmp
  • %TEMP%\vbcde8b.tmp
  • %TEMP%\63jqsdbm.out
  • %TEMP%\63jqsdbm.cmdline
  • %TEMP%\63jqsdbm.0.vb
  • %ALLUSERSPROFILE%\xxx\sdksampleunprivdeveloper.ico
  • %TEMP%\resd8a3.tmp
  • %TEMP%\vbcd893.tmp
  • %TEMP%\hzcgvp9l.out
  • %TEMP%\hzcgvp9l.cmdline
  • %TEMP%\0fkpscgx.0.vb
  • %TEMP%\vbcc1b9.tmp
  • %TEMP%\3islouwm.out
  • %TEMP%\3islouwm.cmdline
  • %TEMP%\1ruztzmd.out
  • %TEMP%\1ruztzmd.cmdline
  • %TEMP%\1ruztzmd.0.vb
  • %ALLUSERSPROFILE%\xxx\dashborder_144.ico
  • %TEMP%\resa3af.tmp
  • %TEMP%\vbca3ae.tmp
  • %TEMP%\3mhqr7bf.out
  • %TEMP%\3mhqr7bf.cmdline
  • %TEMP%\3mhqr7bf.0.vb
  • %TEMP%\resa979.tmp
  • %ALLUSERSPROFILE%\xxx\dial.ico
  • %TEMP%\vbc9f0c.tmp
  • %TEMP%\dtomg2x3.out
  • %TEMP%\dtomg2x3.cmdline
  • %TEMP%\dtomg2x3.0.vb
  • %ALLUSERSPROFILE%\xxx\split.ico
  • %TEMP%\res9a5c.tmp
  • %TEMP%\vbc9a5b.tmp
  • %TEMP%\laxpzwbz.out
  • %TEMP%\laxpzwbz.cmdline
  • %TEMP%\laxpzwbz.0.vb
  • %TEMP%\res9f1d.tmp
  • %ALLUSERSPROFILE%\xxx\dashborder_120.ico
  • %TEMP%\vbca968.tmp
  • %TEMP%\2ak7yhme.0.vb
  • %TEMP%\3islouwm.0.vb
  • %TEMP%\zgoqyeoy.cmdline
  • %ALLUSERSPROFILE%\xxx\coffee.ico
  • %TEMP%\resbd18.tmp
  • %TEMP%\vbcbd17.tmp
  • %TEMP%\rb89bdoc.out
  • %TEMP%\rb89bdoc.cmdline
  • %TEMP%\rb89bdoc.0.vb
  • %ALLUSERSPROFILE%\xxx\tileimage.ico
  • %TEMP%\resb828.tmp
  • %TEMP%\vbcb827.tmp
  • %TEMP%\zgoqyeoy.out
  • %TEMP%\zgoqyeoy.0.vb
  • %TEMP%\2ak7yhme.cmdline
  • %ALLUSERSPROFILE%\xxx\dialmap.ico
  • %TEMP%\resb2eb.tmp
  • %TEMP%\vbcb2ea.tmp
  • %TEMP%\yqvdunfw.out
  • %TEMP%\yqvdunfw.cmdline
  • %TEMP%\yqvdunfw.0.vb
  • %ALLUSERSPROFILE%\xxx\default.ico
  • %TEMP%\resad9e.tmp
  • %TEMP%\vbcad8d.tmp
  • %TEMP%\2ak7yhme.out
  • %ALLUSERSPROFILE%\xxx\adhd_and_obesity.ico
  • %TEMP%\7ae4ffvh.0.vb
  • %TEMP%\7ae4ffvh.cmdline
  • %TEMP%\7ae4ffvh.out
  • %ALLUSERSPROFILE%\xxx\iisstart.ico
  • %TEMP%\res368b.tmp
  • %TEMP%\vbc368a.tmp
  • %TEMP%\bognxghk.out
  • %TEMP%\bognxghk.cmdline
  • %TEMP%\bognxghk.0.vb
  • %ALLUSERSPROFILE%\xxx\trivial-merge.ico
  • %TEMP%\res315d.tmp
  • %TEMP%\vbc315c.tmp
  • %TEMP%\cdb4whn0.out
  • %TEMP%\sylnu1aw.0.vb
  • %TEMP%\cdb4whn0.cmdline
  • %ALLUSERSPROFILE%\xxx\advice_process.ico
  • %TEMP%\res2c7d.tmp
  • %TEMP%\vbc2c7c.tmp
  • %TEMP%\6tisr2oq.out
  • %TEMP%\6tisr2oq.cmdline
  • %TEMP%\6tisr2oq.0.vb
  • %ALLUSERSPROFILE%\xxx\alert.ico
  • %TEMP%\res274f.tmp
  • %TEMP%\vbc274e.tmp
  • %TEMP%\w0zqkf6h.out
  • %TEMP%\cdb4whn0.0.vb
  • %TEMP%\sylnu1aw.cmdline
  • %TEMP%\sylnu1aw.out
  • %TEMP%\vbc3c16.tmp
  • %TEMP%\vbc4cb8.tmp
  • %TEMP%\_chhk1vl.out
  • %TEMP%\_chhk1vl.cmdline
  • %TEMP%\_chhk1vl.0.vb
  • %TEMP%\res49cd.tmp
  • %TEMP%\vbc49bc.tmp
  • %TEMP%\21fun7qb.out
  • %TEMP%\21fun7qb.cmdline
  • %TEMP%\21fun7qb.0.vb
  • %ALLUSERSPROFILE%\xxx\browse.ico
  • %TEMP%\res44fc.tmp
  • %TEMP%\vbc44ec.tmp
  • %TEMP%\xi1dg1nn.out
  • %TEMP%\xi1dg1nn.cmdline
  • %TEMP%\xi1dg1nn.0.vb
  • %ALLUSERSPROFILE%\xxx\howto-index.ico
  • %TEMP%\res407a.tmp
  • %TEMP%\vbc4079.tmp
  • %TEMP%\2jyynbw1.out
  • %TEMP%\2jyynbw1.cmdline
  • %TEMP%\2jyynbw1.0.vb
  • %ALLUSERSPROFILE%\xxx\about.ico
  • %TEMP%\res3c17.tmp
  • %TEMP%\w0zqkf6h.cmdline
  • %ALLUSERSPROFILE%\xxx\calc.ico
  • %TEMP%\w0zqkf6h.0.vb
  • %TEMP%\res21d3.tmp
  • %TEMP%\0rbaz-xh.0.vb
  • %ALLUSERSPROFILE%\xxx\glidescope_review_rev_010.ico
  • %TEMP%\res2ee.tmp
  • %TEMP%\vbc2dd.tmp
  • %TEMP%\b_ul9qxa.out
  • %TEMP%\b_ul9qxa.cmdline
  • %TEMP%\b_ul9qxa.0.vb
  • %ALLUSERSPROFILE%\xxx\issi2013_template_for_posters.ico
  • %TEMP%\resfc59.tmp
  • %TEMP%\vbcfc58.tmp
  • %TEMP%\0rbaz-xh.cmdline
  • %TEMP%\xui5hvpm.out
  • %TEMP%\xui5hvpm.0.vb
  • %ALLUSERSPROFILE%\xxx\aoc_saq_d_v3_merchant.ico
  • %TEMP%\resf67f.tmp
  • %TEMP%\vbcf66f.tmp
  • %TEMP%\ccbwjy6v.out
  • %TEMP%\ccbwjy6v.cmdline
  • %TEMP%\ccbwjy6v.0.vb
  • %ALLUSERSPROFILE%\xxx\nwfieldnotes1966.ico
  • %TEMP%\resefac.tmp
  • %TEMP%\vbcef9b.tmp
  • %TEMP%\xui5hvpm.cmdline
  • %TEMP%\0rbaz-xh.out
  • %TEMP%\vbc8c6.tmp
  • %TEMP%\res8d7.tmp
  • %TEMP%\vbc21c2.tmp
  • %TEMP%\phbcxp1b.out
  • %TEMP%\phbcxp1b.cmdline
  • %TEMP%\phbcxp1b.0.vb
  • %ALLUSERSPROFILE%\xxx\chromesetup.ico
  • %TEMP%\res1bbb.tmp
  • %TEMP%\vbc1bba.tmp
  • %TEMP%\u0y6mtu9.out
  • %TEMP%\u0y6mtu9.cmdline
  • %TEMP%\u0y6mtu9.0.vb
  • %ALLUSERSPROFILE%\xxx\jre-7u75-windows-i586-iftw.ico
  • %TEMP%\res1545.tmp
  • %TEMP%\vbc1544.tmp
  • %TEMP%\dcktaqig.out
  • %TEMP%\dcktaqig.cmdline
  • %TEMP%\dcktaqig.0.vb
  • %ALLUSERSPROFILE%\xxx\wrar520.ico
  • %TEMP%\resf0e.tmp
  • %TEMP%\vbcf0d.tmp
  • %TEMP%\arb8imrm.out
  • %TEMP%\arb8imrm.cmdline
  • %TEMP%\arb8imrm.0.vb
  • %ALLUSERSPROFILE%\xxx\utorrent.ico
  • %TEMP%\res4cc9.tmp
  • %TEMP%\rr8j2tbq.out
Sets the 'hidden' attribute to the following files
  • <Drive name for removable media>:\xxx\xxx.exe
Deletes the following files
  • %TEMP%\res9a5c.tmp
  • %TEMP%\zd2vuilh.cmdline
  • %TEMP%\zd2vuilh.0.vb
  • %TEMP%\zd2vuilh.out
  • %TEMP%\vbc6fa3.tmp
  • %TEMP%\res6fb4.tmp
  • %TEMP%\ubsf3zdk.out
  • %TEMP%\ubsf3zdk.0.vb
  • %TEMP%\ubsf3zdk.cmdline
  • %TEMP%\res72cf.tmp
  • %TEMP%\vbc6cc6.tmp
  • %TEMP%\opvcjqgo.cmdline
  • %TEMP%\opvcjqgo.out
  • %TEMP%\opvcjqgo.0.vb
  • %TEMP%\vbc692e.tmp
  • %TEMP%\res692f.tmp
  • %TEMP%\crybisci.out
  • %TEMP%\crybisci.cmdline
  • %TEMP%\crybisci.0.vb
  • %TEMP%\res6cd7.tmp
  • %TEMP%\knpie3by.0.vb
  • %TEMP%\6hv5rejb.cmdline
  • %TEMP%\l7f0-nmy.0.vb
  • %TEMP%\vbc7edf.tmp
  • %TEMP%\res7ef0.tmp
  • %TEMP%\alth8vpy.0.vb
  • %TEMP%\alth8vpy.cmdline
  • %TEMP%\alth8vpy.out
  • %TEMP%\vbc7b95.tmp
  • %TEMP%\res7ba5.tmp
  • %TEMP%\knpie3by.cmdline
  • %TEMP%\vbc670c.tmp
  • %TEMP%\knpie3by.out
  • %TEMP%\vbc78f6.tmp
  • %TEMP%\res7907.tmp
  • %TEMP%\8ladetd1.out
  • %TEMP%\8ladetd1.cmdline
  • %TEMP%\8ladetd1.0.vb
  • %TEMP%\vbc75ea.tmp
  • %TEMP%\res75eb.tmp
  • %TEMP%\l7f0-nmy.cmdline
  • %TEMP%\vbc72bf.tmp
  • %TEMP%\l7f0-nmy.out
  • %TEMP%\res670d.tmp
  • %TEMP%\ql4dbfg_.out
  • %TEMP%\res5a02.tmp
  • %TEMP%\gda9aywv.out
  • %TEMP%\gda9aywv.0.vb
  • %TEMP%\gda9aywv.cmdline
  • %TEMP%\vbc5753.tmp
  • %TEMP%\res5754.tmp
  • %TEMP%\mns5dxkt.out
  • %TEMP%\mns5dxkt.cmdline
  • %TEMP%\vbc59f2.tmp
  • %TEMP%\mns5dxkt.0.vb
  • %TEMP%\res54d4.tmp
  • %TEMP%\zt_8ar_x.cmdline
  • %TEMP%\zt_8ar_x.0.vb
  • %TEMP%\zt_8ar_x.out
  • %TEMP%\vbc51e6.tmp
  • %TEMP%\res51e7.tmp
  • %TEMP%\kutdm1xr.0.vb
  • %TEMP%\kutdm1xr.out
  • %TEMP%\vbc54c4.tmp
  • %TEMP%\_yopawda.out
  • %TEMP%\mwh-niw1.out
  • %TEMP%\ql4dbfg_.0.vb
  • %TEMP%\mwh-niw1.cmdline
  • %TEMP%\vbc64ab.tmp
  • %TEMP%\res64ac.tmp
  • %TEMP%\mc6u2rjm.cmdline
  • %TEMP%\mc6u2rjm.out
  • %TEMP%\mc6u2rjm.0.vb
  • %TEMP%\vbc61de.tmp
  • %TEMP%\res61df.tmp
  • %TEMP%\mwh-niw1.0.vb
  • %TEMP%\_yopawda.0.vb
  • %TEMP%\_yopawda.cmdline
  • %TEMP%\vbc5f20.tmp
  • %TEMP%\res5f21.tmp
  • %TEMP%\ob0jzy7k.out
  • %TEMP%\ob0jzy7k.0.vb
  • %TEMP%\ob0jzy7k.cmdline
  • %TEMP%\vbc5ca0.tmp
  • %TEMP%\res5ca1.tmp
  • %TEMP%\ql4dbfg_.cmdline
  • %TEMP%\6hv5rejb.out
  • %TEMP%\6hv5rejb.0.vb
  • %TEMP%\res819e.tmp
  • %TEMP%\vuewfy3k.cmdline
  • %TEMP%\vuewfy3k.0.vb
  • %TEMP%\vuewfy3k.out
  • %TEMP%\vbc9f2b.tmp
  • %TEMP%\res9f2c.tmp
  • %TEMP%\8z50kemm.cmdline
  • %TEMP%\8z50kemm.0.vb
  • %TEMP%\8z50kemm.out
  • %TEMP%\res9849.tmp
  • %TEMP%\vbc9d28.tmp
  • %TEMP%\u1s0nf4x.0.vb
  • %TEMP%\u1s0nf4x.out
  • %TEMP%\u1s0nf4x.cmdline
  • %TEMP%\vbc9af7.tmp
  • %TEMP%\res9af8.tmp
  • %TEMP%\8_lcyfrx.cmdline
  • %TEMP%\8_lcyfrx.0.vb
  • %TEMP%\8_lcyfrx.out
  • %TEMP%\res9d29.tmp
  • %TEMP%\vbc9839.tmp
  • %TEMP%\resa17d.tmp
  • %TEMP%\vbca6ba.tmp
  • %TEMP%\rr8j2tbq.0.vb
  • %TEMP%\dstcx7pd.cmdline
  • %TEMP%\dstcx7pd.0.vb
  • %TEMP%\dstcx7pd.out
  • %TEMP%\vbca978.tmp
  • %TEMP%\resa988.tmp
  • %TEMP%\9fwpydvy.out
  • %TEMP%\9fwpydvy.0.vb
  • %TEMP%\7npbmyou.cmdline
  • %TEMP%\vbca17c.tmp
  • %TEMP%\resa6bb.tmp
  • %TEMP%\xjk3n_tn.cmdline
  • %TEMP%\xjk3n_tn.out
  • %TEMP%\xjk3n_tn.0.vb
  • %TEMP%\vbca3ec.tmp
  • %TEMP%\resa3ed.tmp
  • %TEMP%\7npbmyou.out
  • %TEMP%\7npbmyou.0.vb
  • %TEMP%\9fwpydvy.cmdline
  • %TEMP%\eh75avoa.0.vb
  • %TEMP%\eh75avoa.cmdline
  • %TEMP%\eh75avoa.out
  • %TEMP%\1rstbxon.cmdline
  • %TEMP%\vbc8a44.tmp
  • %TEMP%\res8a55.tmp
  • %TEMP%\ykiprpv0.out
  • %TEMP%\ykiprpv0.0.vb
  • %TEMP%\ykiprpv0.cmdline
  • %TEMP%\vbc87b5.tmp
  • %TEMP%\1rstbxon.0.vb
  • %TEMP%\res87c6.tmp
  • %TEMP%\8moltxjt.out
  • %TEMP%\8moltxjt.cmdline
  • %TEMP%\vbc845b.tmp
  • %TEMP%\res846c.tmp
  • %TEMP%\tykqmicx.out
  • %TEMP%\tykqmicx.cmdline
  • %TEMP%\tykqmicx.0.vb
  • %TEMP%\vbc819d.tmp
  • %TEMP%\8moltxjt.0.vb
  • %TEMP%\res8c87.tmp
  • %TEMP%\1rstbxon.out
  • %TEMP%\vbc8c76.tmp
  • %TEMP%\vbc958a.tmp
  • %TEMP%\oqvh076b.0.vb
  • %TEMP%\res959b.tmp
  • %TEMP%\8oxaii-x.cmdline
  • %TEMP%\8oxaii-x.out
  • %TEMP%\8oxaii-x.0.vb
  • %TEMP%\vbc933a.tmp
  • %TEMP%\res933b.tmp
  • %TEMP%\oqvh076b.out
  • %TEMP%\oqvh076b.cmdline
  • %TEMP%\vbc90f8.tmp
  • %TEMP%\abwerfge.out
  • %TEMP%\res90f9.tmp
  • %TEMP%\me2eodir.out
  • %TEMP%\me2eodir.cmdline
  • %TEMP%\me2eodir.0.vb
  • %TEMP%\vbc8eb7.tmp
  • %TEMP%\res8eb8.tmp
  • %TEMP%\abwerfge.cmdline
  • %TEMP%\abwerfge.0.vb
  • %TEMP%\kutdm1xr.cmdline
  • %TEMP%\rr8j2tbq.out
  • %TEMP%\vbc4eea.tmp
  • %TEMP%\_chhk1vl.cmdline
  • %TEMP%\tn7mfv7c.0.vb
  • %TEMP%\vbcd42f.tmp
  • %TEMP%\resd430.tmp
  • %TEMP%\sot3niwh.cmdline
  • %TEMP%\sot3niwh.out
  • %TEMP%\sot3niwh.0.vb
  • %TEMP%\vbccffb.tmp
  • %TEMP%\rescffc.tmp
  • %TEMP%\tn7mfv7c.out
  • %TEMP%\aigivj6z.cmdline
  • %TEMP%\aigivj6z.out
  • %TEMP%\vbccb79.tmp
  • %TEMP%\rescb7a.tmp
  • %TEMP%\rjlgo4ap.cmdline
  • %TEMP%\rjlgo4ap.0.vb
  • %TEMP%\rjlgo4ap.out
  • %TEMP%\vbcc64b.tmp
  • %TEMP%\resc64c.tmp
  • %TEMP%\aigivj6z.0.vb
  • %TEMP%\rese3ba.tmp
  • %TEMP%\resefac.tmp
  • %TEMP%\vbcd893.tmp
  • %TEMP%\vbrp6-ct.0.vb
  • %TEMP%\vbrp6-ct.cmdline
  • %TEMP%\vbrp6-ct.out
  • %TEMP%\vbce9b2.tmp
  • %TEMP%\rese9c3.tmp
  • %TEMP%\0fkpscgx.out
  • %TEMP%\0fkpscgx.cmdline
  • %TEMP%\0fkpscgx.0.vb
  • %TEMP%\3islouwm.out
  • %TEMP%\vbce3b9.tmp
  • %TEMP%\63jqsdbm.cmdline
  • %TEMP%\63jqsdbm.0.vb
  • %TEMP%\63jqsdbm.out
  • %TEMP%\vbcde8b.tmp
  • %TEMP%\resde9c.tmp
  • %TEMP%\hzcgvp9l.out
  • %TEMP%\hzcgvp9l.0.vb
  • %TEMP%\hzcgvp9l.cmdline
  • %TEMP%\tn7mfv7c.cmdline
  • %TEMP%\resd8a3.tmp
  • %TEMP%\3islouwm.0.vb
  • %TEMP%\vbcad8d.tmp
  • %TEMP%\1ruztzmd.cmdline
  • %TEMP%\1ruztzmd.0.vb
  • %TEMP%\vbca968.tmp
  • %TEMP%\resa979.tmp
  • %TEMP%\3mhqr7bf.0.vb
  • %TEMP%\3mhqr7bf.cmdline
  • %TEMP%\3mhqr7bf.out
  • %TEMP%\vbca3ae.tmp
  • %TEMP%\1ruztzmd.out
  • %TEMP%\resa3af.tmp
  • %TEMP%\dtomg2x3.out
  • %TEMP%\dtomg2x3.0.vb
  • %TEMP%\vbc9f0c.tmp
  • %TEMP%\res9f1d.tmp
  • %TEMP%\laxpzwbz.cmdline
  • %TEMP%\laxpzwbz.0.vb
  • %TEMP%\laxpzwbz.out
  • %TEMP%\vbc9a5b.tmp
  • %TEMP%\dtomg2x3.cmdline
  • %TEMP%\vbcb827.tmp
  • %TEMP%\vbcc1b9.tmp
  • %TEMP%\2ak7yhme.cmdline
  • %TEMP%\resc1ba.tmp
  • %TEMP%\rb89bdoc.0.vb
  • %TEMP%\rb89bdoc.out
  • %TEMP%\rb89bdoc.cmdline
  • %TEMP%\vbcbd17.tmp
  • %TEMP%\resbd18.tmp
  • %TEMP%\zgoqyeoy.0.vb
  • %TEMP%\zgoqyeoy.cmdline
  • %TEMP%\3islouwm.cmdline
  • %TEMP%\zgoqyeoy.out
  • %TEMP%\resb828.tmp
  • %TEMP%\yqvdunfw.0.vb
  • %TEMP%\yqvdunfw.cmdline
  • %TEMP%\yqvdunfw.out
  • %TEMP%\vbcb2ea.tmp
  • %TEMP%\resb2eb.tmp
  • %TEMP%\2ak7yhme.0.vb
  • %TEMP%\2ak7yhme.out
  • %TEMP%\resad9e.tmp
  • %TEMP%\vbcef9b.tmp
  • %TEMP%\7ae4ffvh.cmdline
  • %TEMP%\7ae4ffvh.out
  • %TEMP%\sylnu1aw.out
  • %TEMP%\vbc3c16.tmp
  • %TEMP%\res3c17.tmp
  • %TEMP%\bognxghk.0.vb
  • %TEMP%\bognxghk.cmdline
  • %TEMP%\bognxghk.out
  • %TEMP%\vbc368a.tmp
  • %TEMP%\res368b.tmp
  • %TEMP%\w0zqkf6h.cmdline
  • %TEMP%\cdb4whn0.cmdline
  • %TEMP%\cdb4whn0.0.vb
  • %TEMP%\vbc315c.tmp
  • %TEMP%\res315d.tmp
  • %TEMP%\6tisr2oq.0.vb
  • %TEMP%\6tisr2oq.cmdline
  • %TEMP%\6tisr2oq.out
  • %TEMP%\vbc2c7c.tmp
  • %TEMP%\res2c7d.tmp
  • %TEMP%\cdb4whn0.out
  • %TEMP%\w0zqkf6h.out
  • %TEMP%\sylnu1aw.0.vb
  • %TEMP%\xi1dg1nn.cmdline
  • %TEMP%\_chhk1vl.out
  • %TEMP%\_chhk1vl.0.vb
  • %TEMP%\vbc4cb8.tmp
  • %TEMP%\res4cc9.tmp
  • %TEMP%\21fun7qb.0.vb
  • %TEMP%\21fun7qb.cmdline
  • %TEMP%\21fun7qb.out
  • %TEMP%\vbc49bc.tmp
  • %TEMP%\res407a.tmp
  • %TEMP%\sylnu1aw.cmdline
  • %TEMP%\xi1dg1nn.0.vb
  • %TEMP%\xi1dg1nn.out
  • %TEMP%\vbc44ec.tmp
  • %TEMP%\res44fc.tmp
  • %TEMP%\2jyynbw1.cmdline
  • %TEMP%\2jyynbw1.out
  • %TEMP%\2jyynbw1.0.vb
  • %TEMP%\vbc4079.tmp
  • %TEMP%\res49cd.tmp
  • %TEMP%\w0zqkf6h.0.vb
  • %TEMP%\vbc274e.tmp
  • %TEMP%\res274f.tmp
  • %TEMP%\res8d7.tmp
  • %TEMP%\b_ul9qxa.out
  • %TEMP%\b_ul9qxa.cmdline
  • %TEMP%\b_ul9qxa.0.vb
  • %TEMP%\vbc2dd.tmp
  • %TEMP%\res2ee.tmp
  • %TEMP%\xui5hvpm.out
  • %TEMP%\0rbaz-xh.cmdline
  • %TEMP%\xui5hvpm.cmdline
  • %TEMP%\vbcfc58.tmp
  • %TEMP%\resfc59.tmp
  • %TEMP%\ccbwjy6v.0.vb
  • %TEMP%\ccbwjy6v.cmdline
  • %TEMP%\ccbwjy6v.out
  • %TEMP%\vbcf66f.tmp
  • %TEMP%\resf67f.tmp
  • %TEMP%\7ae4ffvh.0.vb
  • %TEMP%\xui5hvpm.0.vb
  • %TEMP%\0rbaz-xh.0.vb
  • %TEMP%\vbc8c6.tmp
  • %TEMP%\0rbaz-xh.out
  • %TEMP%\phbcxp1b.cmdline
  • %TEMP%\res1bbb.tmp
  • %TEMP%\phbcxp1b.0.vb
  • %TEMP%\phbcxp1b.out
  • %TEMP%\vbc21c2.tmp
  • %TEMP%\res21d3.tmp
  • %TEMP%\u0y6mtu9.cmdline
  • %TEMP%\u0y6mtu9.out
  • %TEMP%\u0y6mtu9.0.vb
  • %TEMP%\vbc1bba.tmp
  • %TEMP%\dcktaqig.out
  • %TEMP%\resf0e.tmp
  • %TEMP%\dcktaqig.cmdline
  • %TEMP%\dcktaqig.0.vb
  • %TEMP%\vbc1544.tmp
  • %TEMP%\res1545.tmp
  • %TEMP%\arb8imrm.out
  • %TEMP%\arb8imrm.0.vb
  • %TEMP%\arb8imrm.cmdline
  • %TEMP%\vbcf0d.tmp
  • %TEMP%\res4efb.tmp
  • %TEMP%\rr8j2tbq.cmdline
Substitutes the following executable files
  • <Drive name for removable media>:\utorrent.exe
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\jre-7u75-windows-i586-iftw.exe
  • <Drive name for removable media>:\chromesetup.exe
  • <Drive name for removable media>:\calc.exe
Changes user data files extensions (Trojan.Encoder).
Network activity
Connects to
  • 'xz#####0774.portmap.io':20774
UDP
  • DNS ASK xz#####0774.portmap.io
Miscellaneous
Creates and executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\laxpzwbz.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES819E.tmp" "%TEMP%\vbc819D.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8moltxjt.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES846C.tmp" "%TEMP%\vbc845B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ykiprpv0.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES87C6.tmp" "%TEMP%\vbc87B5.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1rstbxon.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8A55.tmp" "%TEMP%\vbc8A44.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\abwerfge.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8C87.tmp" "%TEMP%\vbc8C76.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\me2eodir.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8EB8.tmp" "%TEMP%\vbc8EB7.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\oqvh076b.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES90F9.tmp" "%TEMP%\vbc90F8.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8oxaii-x.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES933B.tmp" "%TEMP%\vbc933A.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\eh75avoa.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES959B.tmp" "%TEMP%\vbc958A.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tykqmicx.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8_lcyfrx.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7EF0.tmp" "%TEMP%\vbc7EDF.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7BA5.tmp" "%TEMP%\vbc7B95.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mwh-niw1.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES64AC.tmp" "%TEMP%\vbc64AB.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\crybisci.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES670D.tmp" "%TEMP%\vbc670C.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\opvcjqgo.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES692F.tmp" "%TEMP%\vbc692E.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ubsf3zdk.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6CD7.tmp" "%TEMP%\vbc6CC6.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zd2vuilh.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6FB4.tmp" "%TEMP%\vbc6FA3.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\l7f0-nmy.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES72CF.tmp" "%TEMP%\vbc72BF.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8ladetd1.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES75EB.tmp" "%TEMP%\vbc75EA.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\knpie3by.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7907.tmp" "%TEMP%\vbc78F6.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\alth8vpy.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6hv5rejb.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9849.tmp" "%TEMP%\vbc9839.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u1s0nf4x.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9AF8.tmp" "%TEMP%\vbc9AF7.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBFD6.tmp" "%TEMP%\vbcBFD5.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0ge6ruhu.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC217.tmp" "%TEMP%\vbcC207.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ln8y7mlv.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC4B6.tmp" "%TEMP%\vbcC4A5.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6o8t8jui.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC6C8.tmp" "%TEMP%\vbcC6C7.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD28B.tmp" "%TEMP%\vbcD27B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1y3bqiti.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\hy-_sqgs.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCB3B.tmp" "%TEMP%\vbcCB3A.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gjokd8ut.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCE18.tmp" "%TEMP%\vbcCE08.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\al8kw5k0.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD02B.tmp" "%TEMP%\vbcD02A.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xwoch1p-.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBDC4.tmp" "%TEMP%\vbcBDC3.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\nefi_iky.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\j1ihgrgg.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBB73.tmp" "%TEMP%\vbcBB72.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\o67qg0ge.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9D29.tmp" "%TEMP%\vbc9D28.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\vuewfy3k.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F2C.tmp" "%TEMP%\vbc9F2B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7npbmyou.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA17D.tmp" "%TEMP%\vbcA17C.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xjk3n_tn.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA3ED.tmp" "%TEMP%\vbcA3EC.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES61DF.tmp" "%TEMP%\vbc61DE.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA6BB.tmp" "%TEMP%\vbcA6BA.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9fwpydvy.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA988.tmp" "%TEMP%\vbcA978.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rr8j2tbq.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESABAA.tmp" "%TEMP%\vbcABA9.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kclb0uph.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB413.tmp" "%TEMP%\vbcB412.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_axntpfd.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB674.tmp" "%TEMP%\vbcB673.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8z50kemm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dstcx7pd.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC919.tmp" "%TEMP%\vbcC909.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mc6u2rjm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mns5dxkt.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sot3niwh.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCFFC.tmp" "%TEMP%\vbcCFFB.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tn7mfv7c.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD430.tmp" "%TEMP%\vbcD42F.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\hzcgvp9l.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD8A3.tmp" "%TEMP%\vbcD893.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\63jqsdbm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDE9C.tmp" "%TEMP%\vbcDE8B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0fkpscgx.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE3BA.tmp" "%TEMP%\vbcE3B9.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\vbrp6-ct.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE9C3.tmp" "%TEMP%\vbcE9B2.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7ae4ffvh.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEFAC.tmp" "%TEMP%\vbcEF9B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ccbwjy6v.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF67F.tmp" "%TEMP%\vbcF66F.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xui5hvpm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCB7A.tmp" "%TEMP%\vbcCB79.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFC59.tmp" "%TEMP%\vbcFC58.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\aigivj6z.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rjlgo4ap.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9A5C.tmp" "%TEMP%\vbc9A5B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dtomg2x3.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F1D.tmp" "%TEMP%\vbc9F0C.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\3mhqr7bf.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA3AF.tmp" "%TEMP%\vbcA3AE.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1ruztzmd.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA979.tmp" "%TEMP%\vbcA968.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\2ak7yhme.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESAD9E.tmp" "%TEMP%\vbcAD8D.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yqvdunfw.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB2EB.tmp" "%TEMP%\vbcB2EA.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zgoqyeoy.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB828.tmp" "%TEMP%\vbcB827.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rb89bdoc.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBD18.tmp" "%TEMP%\vbcBD17.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\3islouwm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC1BA.tmp" "%TEMP%\vbcC1B9.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC64C.tmp" "%TEMP%\vbcC64B.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\b_ul9qxa.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2EE.tmp" "%TEMP%\vbc2DD.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0rbaz-xh.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\21fun7qb.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES49CD.tmp" "%TEMP%\vbc49BC.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_chhk1vl.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4CC9.tmp" "%TEMP%\vbc4CB8.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kutdm1xr.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4EFB.tmp" "%TEMP%\vbc4EEA.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zt_8ar_x.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_yopawda.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES51E7.tmp" "%TEMP%\vbc51E6.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54D4.tmp" "%TEMP%\vbc54C4.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gda9aywv.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5754.tmp" "%TEMP%\vbc5753.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ql4dbfg_.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5A02.tmp" "%TEMP%\vbc59F2.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ob0jzy7k.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5CA1.tmp" "%TEMP%\vbc5CA0.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xi1dg1nn.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44FC.tmp" "%TEMP%\vbc44EC.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES407A.tmp" "%TEMP%\vbc4079.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\2jyynbw1.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3C17.tmp" "%TEMP%\vbc3C16.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\arb8imrm.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF0E.tmp" "%TEMP%\vbcF0D.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dcktaqig.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1545.tmp" "%TEMP%\vbc1544.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u0y6mtu9.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1BBB.tmp" "%TEMP%\vbc1BBA.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\phbcxp1b.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5F21.tmp" "%TEMP%\vbc5F20.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\w0zqkf6h.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES21D3.tmp" "%TEMP%\vbc21C2.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6tisr2oq.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2C7D.tmp" "%TEMP%\vbc2C7C.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\cdb4whn0.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES315D.tmp" "%TEMP%\vbc315C.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\bognxghk.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES368B.tmp" "%TEMP%\vbc368A.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sylnu1aw.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8D7.tmp" "%TEMP%\vbc8C6.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES274F.tmp" "%TEMP%\vbc274E.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zwqei4jw.cmdline"' (with hidden window)
Executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\laxpzwbz.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES819E.tmp" "%TEMP%\vbc819D.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8moltxjt.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES846C.tmp" "%TEMP%\vbc845B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ykiprpv0.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES87C6.tmp" "%TEMP%\vbc87B5.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1rstbxon.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8A55.tmp" "%TEMP%\vbc8A44.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\abwerfge.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8C87.tmp" "%TEMP%\vbc8C76.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\me2eodir.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8EB8.tmp" "%TEMP%\vbc8EB7.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\oqvh076b.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES90F9.tmp" "%TEMP%\vbc90F8.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8oxaii-x.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES933B.tmp" "%TEMP%\vbc933A.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\eh75avoa.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES959B.tmp" "%TEMP%\vbc958A.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tykqmicx.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8_lcyfrx.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7EF0.tmp" "%TEMP%\vbc7EDF.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7BA5.tmp" "%TEMP%\vbc7B95.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mwh-niw1.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES64AC.tmp" "%TEMP%\vbc64AB.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\crybisci.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES670D.tmp" "%TEMP%\vbc670C.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\opvcjqgo.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES692F.tmp" "%TEMP%\vbc692E.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ubsf3zdk.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6CD7.tmp" "%TEMP%\vbc6CC6.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zd2vuilh.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6FB4.tmp" "%TEMP%\vbc6FA3.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\l7f0-nmy.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES72CF.tmp" "%TEMP%\vbc72BF.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8ladetd1.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES75EB.tmp" "%TEMP%\vbc75EA.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\knpie3by.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7907.tmp" "%TEMP%\vbc78F6.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\alth8vpy.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6hv5rejb.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9849.tmp" "%TEMP%\vbc9839.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u1s0nf4x.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9AF8.tmp" "%TEMP%\vbc9AF7.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBFD6.tmp" "%TEMP%\vbcBFD5.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0ge6ruhu.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC217.tmp" "%TEMP%\vbcC207.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ln8y7mlv.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC4B6.tmp" "%TEMP%\vbcC4A5.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6o8t8jui.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC6C8.tmp" "%TEMP%\vbcC6C7.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD28B.tmp" "%TEMP%\vbcD27B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1y3bqiti.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\hy-_sqgs.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCB3B.tmp" "%TEMP%\vbcCB3A.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gjokd8ut.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCE18.tmp" "%TEMP%\vbcCE08.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\al8kw5k0.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD02B.tmp" "%TEMP%\vbcD02A.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xwoch1p-.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBDC4.tmp" "%TEMP%\vbcBDC3.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\nefi_iky.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\j1ihgrgg.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBB73.tmp" "%TEMP%\vbcBB72.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\o67qg0ge.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9D29.tmp" "%TEMP%\vbc9D28.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\vuewfy3k.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F2C.tmp" "%TEMP%\vbc9F2B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7npbmyou.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA17D.tmp" "%TEMP%\vbcA17C.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xjk3n_tn.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA3ED.tmp" "%TEMP%\vbcA3EC.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES61DF.tmp" "%TEMP%\vbc61DE.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA6BB.tmp" "%TEMP%\vbcA6BA.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9fwpydvy.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA988.tmp" "%TEMP%\vbcA978.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rr8j2tbq.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESABAA.tmp" "%TEMP%\vbcABA9.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kclb0uph.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB413.tmp" "%TEMP%\vbcB412.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_axntpfd.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB674.tmp" "%TEMP%\vbcB673.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8z50kemm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dstcx7pd.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC919.tmp" "%TEMP%\vbcC909.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mc6u2rjm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mns5dxkt.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sot3niwh.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCFFC.tmp" "%TEMP%\vbcCFFB.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tn7mfv7c.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD430.tmp" "%TEMP%\vbcD42F.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\hzcgvp9l.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD8A3.tmp" "%TEMP%\vbcD893.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\63jqsdbm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESDE9C.tmp" "%TEMP%\vbcDE8B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0fkpscgx.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE3BA.tmp" "%TEMP%\vbcE3B9.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\vbrp6-ct.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESE9C3.tmp" "%TEMP%\vbcE9B2.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7ae4ffvh.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEFAC.tmp" "%TEMP%\vbcEF9B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ccbwjy6v.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF67F.tmp" "%TEMP%\vbcF66F.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xui5hvpm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCB7A.tmp" "%TEMP%\vbcCB79.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFC59.tmp" "%TEMP%\vbcFC58.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\aigivj6z.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rjlgo4ap.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9A5C.tmp" "%TEMP%\vbc9A5B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dtomg2x3.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F1D.tmp" "%TEMP%\vbc9F0C.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\3mhqr7bf.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA3AF.tmp" "%TEMP%\vbcA3AE.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\1ruztzmd.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA979.tmp" "%TEMP%\vbcA968.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\2ak7yhme.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESAD9E.tmp" "%TEMP%\vbcAD8D.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yqvdunfw.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB2EB.tmp" "%TEMP%\vbcB2EA.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zgoqyeoy.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB828.tmp" "%TEMP%\vbcB827.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\rb89bdoc.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBD18.tmp" "%TEMP%\vbcBD17.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\3islouwm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC1BA.tmp" "%TEMP%\vbcC1B9.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC64C.tmp" "%TEMP%\vbcC64B.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\b_ul9qxa.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2EE.tmp" "%TEMP%\vbc2DD.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0rbaz-xh.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\21fun7qb.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES49CD.tmp" "%TEMP%\vbc49BC.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_chhk1vl.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4CC9.tmp" "%TEMP%\vbc4CB8.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kutdm1xr.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4EFB.tmp" "%TEMP%\vbc4EEA.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zt_8ar_x.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_yopawda.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES51E7.tmp" "%TEMP%\vbc51E6.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES54D4.tmp" "%TEMP%\vbc54C4.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gda9aywv.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5754.tmp" "%TEMP%\vbc5753.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ql4dbfg_.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5A02.tmp" "%TEMP%\vbc59F2.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ob0jzy7k.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5CA1.tmp" "%TEMP%\vbc5CA0.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xi1dg1nn.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44FC.tmp" "%TEMP%\vbc44EC.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES407A.tmp" "%TEMP%\vbc4079.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\2jyynbw1.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3C17.tmp" "%TEMP%\vbc3C16.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\arb8imrm.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF0E.tmp" "%TEMP%\vbcF0D.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dcktaqig.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1545.tmp" "%TEMP%\vbc1544.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u0y6mtu9.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1BBB.tmp" "%TEMP%\vbc1BBA.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\phbcxp1b.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5F21.tmp" "%TEMP%\vbc5F20.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\w0zqkf6h.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES21D3.tmp" "%TEMP%\vbc21C2.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\6tisr2oq.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2C7D.tmp" "%TEMP%\vbc2C7C.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\cdb4whn0.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES315D.tmp" "%TEMP%\vbc315C.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\bognxghk.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES368B.tmp" "%TEMP%\vbc368A.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sylnu1aw.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8D7.tmp" "%TEMP%\vbc8C6.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES274F.tmp" "%TEMP%\vbc274E.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\zwqei4jw.cmdline"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке