Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\client.exe
- %APPDATA%\client.exe
- %TEMP%\res71d3.tmp
- %TEMP%\vbc71d2.tmp
- %TEMP%\9oujwb3c.out
- %TEMP%\9oujwb3c.cmdline
- %TEMP%\9oujwb3c.0.vb
- %APPDATA%\random\optional\qip 2012.exe
- %TEMP%\res6e19.tmp
- %TEMP%\vbc6e18.tmp
- %TEMP%\dynjv-1f.out
- %TEMP%\dynjv-1f.cmdline
- %TEMP%\dynjv-1f.0.vb
- %APPDATA%\random\optional\mozilla thunderbird.exe
- %TEMP%\res6aae.tmp
- %TEMP%\vbc6aad.tmp
- %TEMP%\mq1_hvto.out
- %TEMP%\mq1_hvto.cmdline
- %TEMP%\mq1_hvto.0.vb
- %APPDATA%\random\optional\mail.ru agent.exe
- %TEMP%\res6743.tmp
- %TEMP%\vbc6742.tmp
- %TEMP%\udmgqnqk.out
- %TEMP%\udmgqnqk.cmdline
- %TEMP%\udmgqnqk.0.vb
- %APPDATA%\random\optional\launch internet explorer browser.exe
- %TEMP%\res634c.tmp
- %APPDATA%\random\optional\winamp.exe
- %TEMP%\dybgtv4x.cmdline
- %TEMP%\res84ce.tmp
- %TEMP%\dybgtv4x.out
- %TEMP%\vbc84cd.tmp
- %TEMP%\unzfhr3j.out
- %TEMP%\unzfhr3j.cmdline
- %TEMP%\unzfhr3j.0.vb
- %APPDATA%\random\default\telegram.exe
- %TEMP%\res8098.tmp
- %TEMP%\vbc8097.tmp
- %TEMP%\jjnmpmym.out
- %TEMP%\jjnmpmym.cmdline
- %TEMP%\jjnmpmym.0.vb
- %APPDATA%\random\default\qip 2012.exe
- %TEMP%\res7cbf.tmp
- %TEMP%\vbc7caf.tmp
- %TEMP%\dsykkzoe.out
- %TEMP%\dsykkzoe.cmdline
- %TEMP%\dsykkzoe.0.vb
- %APPDATA%\random\default\mail.ru agent.exe
- %TEMP%\res7945.tmp
- %TEMP%\vbc7944.tmp
- %TEMP%\jwk31eja.out
- %TEMP%\jwk31eja.cmdline
- %TEMP%\jwk31eja.0.vb
- %APPDATA%\random\default\icq.exe
- %TEMP%\res753e.tmp
- %TEMP%\vbc753d.tmp
- %TEMP%\vbc634b.tmp
- %TEMP%\dybgtv4x.0.vb
- %TEMP%\ui-a2flv.out
- %TEMP%\kivp93ss.out
- %TEMP%\kivp93ss.0.vb
- %APPDATA%\random\mail.ru agent.exe
- %TEMP%\res499a.tmp
- %TEMP%\vbc4999.tmp
- %TEMP%\kqmhzqrj.out
- %TEMP%\kqmhzqrj.cmdline
- %TEMP%\kqmhzqrj.0.vb
- %APPDATA%\random\internet explorer.exe
- %TEMP%\res44d7.tmp
- %TEMP%\vbc44d6.tmp
- %TEMP%\yosmjqfw.out
- %TEMP%\yosmjqfw.cmdline
- %TEMP%\yosmjqfw.0.vb
- %APPDATA%\random\icq.exe
- %TEMP%\res3fd6.tmp
- %TEMP%\vbc3fd5.tmp
- %TEMP%\yrmr8mde.out
- %TEMP%\yrmr8mde.cmdline
- %TEMP%\yrmr8mde.0.vb
- %APPDATA%\random\google chrome.exe
- %TEMP%\res3ad4.tmp
- %TEMP%\vbc3ad3.tmp
- %TEMP%\8hsfbusq.out
- %TEMP%\8hsfbusq.cmdline
- %TEMP%\8hsfbusq.0.vb
- %TEMP%\kivp93ss.cmdline
- %TEMP%\vbc4d81.tmp
- %TEMP%\ui-a2flv.0.vb
- %TEMP%\res4d91.tmp
- %APPDATA%\random\optional\icq.exe
- %TEMP%\res5fa2.tmp
- %TEMP%\vbc5fa1.tmp
- %TEMP%\ou2e7mvm.out
- %TEMP%\ou2e7mvm.cmdline
- %TEMP%\ou2e7mvm.0.vb
- %APPDATA%\random\optional\google chrome.exe
- %TEMP%\res5c66.tmp
- %TEMP%\vbc5c65.tmp
- %TEMP%\ffpnn6ad.out
- %TEMP%\ffpnn6ad.cmdline
- %TEMP%\ffpnn6ad.0.vb
- %APPDATA%\random\windows media player.exe
- %TEMP%\res566b.tmp
- %TEMP%\vbc566a.tmp
- %TEMP%\skwjmdag.out
- %TEMP%\skwjmdag.cmdline
- %TEMP%\skwjmdag.0.vb
- %APPDATA%\random\windows explorer.exe
- %TEMP%\res5225.tmp
- %TEMP%\vbc5224.tmp
- %TEMP%\b5a74mcz.out
- %TEMP%\b5a74mcz.cmdline
- %TEMP%\b5a74mcz.0.vb
- %APPDATA%\random\opera.exe
- %TEMP%\ui-a2flv.cmdline
- %APPDATA%\random\default\total commander 64 bit.exe
- %TEMP%\res3ad4.tmp
- %TEMP%\9oujwb3c.cmdline
- %TEMP%\9oujwb3c.out
- %TEMP%\vbc71d2.tmp
- %TEMP%\res71d3.tmp
- %TEMP%\dynjv-1f.out
- %TEMP%\dynjv-1f.0.vb
- %TEMP%\dynjv-1f.cmdline
- %TEMP%\vbc6e18.tmp
- %TEMP%\res6e19.tmp
- %TEMP%\9oujwb3c.0.vb
- %TEMP%\mq1_hvto.0.vb
- %TEMP%\mq1_hvto.out
- %TEMP%\vbc6aad.tmp
- %TEMP%\res6aae.tmp
- %TEMP%\udmgqnqk.0.vb
- %TEMP%\udmgqnqk.out
- %TEMP%\udmgqnqk.cmdline
- %TEMP%\vbc6742.tmp
- %TEMP%\res6743.tmp
- %TEMP%\ui-a2flv.out
- %TEMP%\mq1_hvto.cmdline
- %TEMP%\dsykkzoe.out
- %TEMP%\unzfhr3j.out
- %TEMP%\dybgtv4x.0.vb
- %TEMP%\unzfhr3j.cmdline
- %TEMP%\vbc84cd.tmp
- %TEMP%\res84ce.tmp
- %TEMP%\jjnmpmym.cmdline
- %TEMP%\jjnmpmym.0.vb
- %TEMP%\jjnmpmym.out
- %TEMP%\vbc8097.tmp
- %TEMP%\res8098.tmp
- %TEMP%\dsykkzoe.0.vb
- %TEMP%\ui-a2flv.cmdline
- %TEMP%\dsykkzoe.cmdline
- %TEMP%\vbc7caf.tmp
- %TEMP%\res7cbf.tmp
- %TEMP%\jwk31eja.cmdline
- %TEMP%\jwk31eja.out
- %TEMP%\jwk31eja.0.vb
- %TEMP%\vbc7944.tmp
- %TEMP%\res7945.tmp
- %TEMP%\dybgtv4x.cmdline
- %TEMP%\dybgtv4x.out
- %TEMP%\res753e.tmp
- %TEMP%\vbc753d.tmp
- %TEMP%\ui-a2flv.0.vb
- %TEMP%\kivp93ss.0.vb
- %TEMP%\res4d91.tmp
- %TEMP%\kqmhzqrj.cmdline
- %TEMP%\kqmhzqrj.out
- %TEMP%\kqmhzqrj.0.vb
- %TEMP%\vbc4999.tmp
- %TEMP%\res499a.tmp
- %TEMP%\yosmjqfw.cmdline
- %TEMP%\yosmjqfw.0.vb
- %TEMP%\yosmjqfw.out
- %TEMP%\vbc4d81.tmp
- %TEMP%\vbc44d6.tmp
- %TEMP%\yrmr8mde.cmdline
- %TEMP%\yrmr8mde.0.vb
- %TEMP%\yrmr8mde.out
- %TEMP%\vbc3fd5.tmp
- %TEMP%\res3fd6.tmp
- %TEMP%\8hsfbusq.out
- %TEMP%\8hsfbusq.cmdline
- %TEMP%\8hsfbusq.0.vb
- %TEMP%\vbc3ad3.tmp
- %TEMP%\res44d7.tmp
- %TEMP%\skwjmdag.0.vb
- %TEMP%\res634c.tmp
- %TEMP%\kivp93ss.out
- %TEMP%\ou2e7mvm.cmdline
- %TEMP%\ou2e7mvm.0.vb
- %TEMP%\ou2e7mvm.out
- %TEMP%\vbc5fa1.tmp
- %TEMP%\res5fa2.tmp
- %TEMP%\ffpnn6ad.out
- %TEMP%\ffpnn6ad.cmdline
- %TEMP%\ffpnn6ad.0.vb
- %TEMP%\vbc5c65.tmp
- %TEMP%\vbc634b.tmp
- %TEMP%\res5c66.tmp
- %TEMP%\skwjmdag.cmdline
- %TEMP%\skwjmdag.out
- %TEMP%\vbc566a.tmp
- %TEMP%\res566b.tmp
- %TEMP%\b5a74mcz.0.vb
- %TEMP%\b5a74mcz.out
- %TEMP%\b5a74mcz.cmdline
- %TEMP%\vbc5224.tmp
- %TEMP%\res5225.tmp
- %TEMP%\kivp93ss.cmdline
- %TEMP%\unzfhr3j.0.vb
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk to %APPDATA%\random\google chrome.lnk
- from C:\users\public\desktop\opera.lnk to %APPDATA%\random\default\opera.lnk
- from C:\users\public\desktop\mozilla thunderbird.lnk to %APPDATA%\random\default\mozilla thunderbird.lnk
- from C:\users\public\desktop\mozilla firefox.lnk to %APPDATA%\random\default\mozilla firefox.lnk
- from C:\users\public\desktop\mirc.lnk to %APPDATA%\random\default\mirc.lnk
- from C:\users\public\desktop\google chrome.lnk to %APPDATA%\random\default\google chrome.lnk
- from C:\users\public\desktop\acrobat reader dc.lnk to %APPDATA%\random\default\acrobat reader dc.lnk
- from %HOMEPATH%\desktop\total commander 64 bit.lnk to %APPDATA%\random\default\total commander 64 bit.lnk
- from %HOMEPATH%\desktop\telegram.lnk to %APPDATA%\random\default\telegram.lnk
- from %HOMEPATH%\desktop\qip 2012.lnk to %APPDATA%\random\default\qip 2012.lnk
- from %HOMEPATH%\desktop\mail.ru agent.lnk to %APPDATA%\random\default\mail.ru agent.lnk
- from %HOMEPATH%\desktop\icq.lnk to %APPDATA%\random\default\icq.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk to %APPDATA%\random\optional\window switcher.lnk
- from C:\users\public\desktop\steam.lnk to %APPDATA%\random\default\steam.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\winamp.lnk to %APPDATA%\random\optional\winamp.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\qip 2012.lnk to %APPDATA%\random\optional\qip 2012.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\mozilla thunderbird.lnk to %APPDATA%\random\optional\mozilla thunderbird.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\mail.ru agent.lnk to %APPDATA%\random\optional\mail.ru agent.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk to %APPDATA%\random\optional\launch internet explorer browser.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\icq.lnk to %APPDATA%\random\optional\icq.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk to %APPDATA%\random\optional\google chrome.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows media player.lnk to %APPDATA%\random\windows media player.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows explorer.lnk to %APPDATA%\random\windows explorer.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\opera.lnk to %APPDATA%\random\opera.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\mail.ru agent.lnk to %APPDATA%\random\mail.ru agent.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer.lnk to %APPDATA%\random\internet explorer.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\icq.lnk to %APPDATA%\random\icq.lnk
- from %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk to %APPDATA%\random\optional\shows desktop.lnk
- from C:\users\public\desktop\winamp.lnk to %APPDATA%\random\default\winamp.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
- %HOMEPATH%\Desktop\QIP 2012.lnk
- %HOMEPATH%\Desktop\Mail.Ru Agent.lnk
- %HOMEPATH%\Desktop\ICQ.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\QIP 2012.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Mail.Ru Agent.lnk
- %HOMEPATH%\Desktop\Telegram.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mail.Ru Agent.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ICQ.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ICQ.lnk
- %HOMEPATH%\Desktop\Total Commander 64 bit.lnk
- DNS ASK Lo######43158.portmap.host
- '%APPDATA%\microsoft\windows\start menu\programs\startup\client.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dybgtv4x.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES753E.tmp" "%TEMP%\vbc753D.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jwk31eja.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7945.tmp" "%TEMP%\vbc7944.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dsykkzoe.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7CBF.tmp" "%TEMP%\vbc7CAF.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jjnmpmym.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8098.tmp" "%TEMP%\vbc8097.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\unzfhr3j.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES84CE.tmp" "%TEMP%\vbc84CD.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\skbvbrk6.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tnoruudq.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ntlrs2mh.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8BE2.tmp" "%TEMP%\vbc8BE1.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_jyozm56.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9067.tmp" "%TEMP%\vbc9066.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\z4bggorx.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES924B.tmp" "%TEMP%\vbc924A.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9ovfr6ux.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES93E1.tmp" "%TEMP%\vbc93E0.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ehqwhypj.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9558.tmp" "%TEMP%\vbc9557.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\g8zsww0t.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9CDA.tmp" "%TEMP%\vbc9CCA.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES71D3.tmp" "%TEMP%\vbc71D2.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8981.tmp" "%TEMP%\vbc8980.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9oujwb3c.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5225.tmp" "%TEMP%\vbc5224.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8hsfbusq.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3AD4.tmp" "%TEMP%\vbc3AD3.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yrmr8mde.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3FD6.tmp" "%TEMP%\vbc3FD5.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yosmjqfw.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44D7.tmp" "%TEMP%\vbc44D6.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kqmhzqrj.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES499A.tmp" "%TEMP%\vbc4999.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kivp93ss.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4D91.tmp" "%TEMP%\vbc4D81.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\b5a74mcz.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\skwjmdag.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dynjv-1f.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES566B.tmp" "%TEMP%\vbc566A.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ffpnn6ad.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5C66.tmp" "%TEMP%\vbc5C65.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ou2e7mvm.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5FA2.tmp" "%TEMP%\vbc5FA1.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ui-a2flv.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES634C.tmp" "%TEMP%\vbc634B.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\udmgqnqk.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6743.tmp" "%TEMP%\vbc6742.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mq1_hvto.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6AAE.tmp" "%TEMP%\vbc6AAD.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6E19.tmp" "%TEMP%\vbc6E18.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9EDE.tmp" "%TEMP%\vbc9EDD.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\8hsfbusq.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jwk31eja.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7945.tmp" "%TEMP%\vbc7944.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dsykkzoe.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7CBF.tmp" "%TEMP%\vbc7CAF.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jjnmpmym.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8098.tmp" "%TEMP%\vbc8097.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\unzfhr3j.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES84CE.tmp" "%TEMP%\vbc84CD.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\skbvbrk6.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8981.tmp" "%TEMP%\vbc8980.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES566B.tmp" "%TEMP%\vbc566A.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\tnoruudq.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\_jyozm56.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9067.tmp" "%TEMP%\vbc9066.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\z4bggorx.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES924B.tmp" "%TEMP%\vbc924A.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9ovfr6ux.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES93E1.tmp" "%TEMP%\vbc93E0.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ehqwhypj.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9558.tmp" "%TEMP%\vbc9557.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\g8zsww0t.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9CDA.tmp" "%TEMP%\vbc9CCA.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dybgtv4x.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES753E.tmp" "%TEMP%\vbc753D.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES71D3.tmp" "%TEMP%\vbc71D2.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9oujwb3c.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6E19.tmp" "%TEMP%\vbc6E18.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yrmr8mde.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3FD6.tmp" "%TEMP%\vbc3FD5.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\yosmjqfw.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES44D7.tmp" "%TEMP%\vbc44D6.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kqmhzqrj.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES499A.tmp" "%TEMP%\vbc4999.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\kivp93ss.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4D91.tmp" "%TEMP%\vbc4D81.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\b5a74mcz.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5225.tmp" "%TEMP%\vbc5224.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ntlrs2mh.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8BE2.tmp" "%TEMP%\vbc8BE1.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\skwjmdag.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5C66.tmp" "%TEMP%\vbc5C65.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ou2e7mvm.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5FA2.tmp" "%TEMP%\vbc5FA1.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ui-a2flv.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES634C.tmp" "%TEMP%\vbc634B.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\udmgqnqk.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6743.tmp" "%TEMP%\vbc6742.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mq1_hvto.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6AAE.tmp" "%TEMP%\vbc6AAD.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\dynjv-1f.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3AD4.tmp" "%TEMP%\vbc3AD3.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ffpnn6ad.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9EDE.tmp" "%TEMP%\vbc9EDD.tmp"