Technical Information
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\travsport\culminatation\unscaledness\skaldyrsaflejrings\relick.wea
- %TEMP%\nse932b.tmp\nsexec.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\stoflig\x-office-address-book.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\abekd\view-restore-symbolic.symbolic.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\abekd\user-invisible-symbolic.svg
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\abekd\user-idle.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\sprogklasserne\hstfarve163\unfinessed\system-search.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\sprogklasserne\hstfarve163\unfinessed\right_arrow.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\sprogklasserne\hstfarve163\unfinessed\prism.js
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\graphing\ephebus\unsweetly182\strumella\preferences-system-network-symbolic.svg
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\graphing\ephebus\unsweetly182\strumella\nero.exe.manifest
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\graphing\ephebus\unsweetly182\strumella\msvcr110.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\transfusionskanyle\deemed\skifret\tamburkorpsenes\mail-mark-unread.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\diademerne94\skolebgers\sildiges\ieee754.c
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\diademerne94\skolebgers\sildiges\folder-visiting-symbolic.symbolic.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\prent\flydesprringen\face-uncertain-symbolic.symbolic.png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\prent\flydesprringen\contextmenu.xml
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\prent\flydesprringen\cgsetup_en_rsidqdnlvs6jciy5qsip.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\prent\flydesprringen\avformat-56.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\prent\flydesprringen\msmpeng.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\bekldningsgenstandene\filetransfer.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\bekldningsgenstandene\asmultilang.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\bekldningsgenstandene\stimering.kns
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\tervader\hoodwinks\tazze\vederlaget\airways_5.bmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\varas173.ini
- %TEMP%\nse932b.tmp\system.dll
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x13883C40^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E40720^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AF84E23^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F73867^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x76BF5D23^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x70A41C3B^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x37AE4667^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E1072E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B5563E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x348C0262^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68FD422E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x31ED5E76^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x6CFD477E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x76BF5F23^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F73D6B^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2C8B0762^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x3D9D0167^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B55D3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x36B90B7C^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B55F3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x69FB5E3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD4267^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD4767^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x74ED072E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78A44E3A^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AB91B6F^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x28ED5E22^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x1EA4026B^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78E14E67^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AF94E22^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x3DAC1A6B^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x19E5032E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F72D7C^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E14E67^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68FD5E3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x1D815D3C^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD422E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x20F55E3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78A44E3E^1489858062"
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78E14E67^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x76BF5F23^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x1EA4026B^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F73D6B^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD4767^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2C8B0762^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x3DAC1A6B^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78A44E3A^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x13883C40^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x36B90B7C^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F72D7C^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x70A41C3B^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x69FB5E3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x1D815D3C^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x6CFD477E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x19E5032E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x3D9D0167^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x31ED5E76^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E1072E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD422E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x74ED072E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E40720^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68E14E67^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AF84E23^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x62F73867^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68FD5E3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AB91B6F^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x348C0262^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x28ED5E22^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x37AE4667^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78A44E3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B55F3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B55D3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x2AF94E22^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68FD422E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x68B5563E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x20F55E3E^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x78FD4267^1489858062"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c set /a "0x76BF5D23^1489858062"' (with hidden window)