Technical Information
Modifies file system
Creates the following files
- %ProgramFiles(x86)%\altcmd\altcmd32.dll
- %ProgramFiles(x86)%\altcmd\altcmd.inf
- %ProgramFiles(x86)%\altcmd\uninstall.bat
- %TEMP%\12b5.bat
Moves itself
- from <Full path to file> to %WINDIR%\syswow64\<File name>.exe
Miscellaneous
Creates and executes the following
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\12B5.bat' (with hidden window)
Executes the following
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\12B5.bat