Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- file: scsD76C.tmp
- dos=high, umb
- device=C:\Windows\system32\himem.sys
- files=40
- country=001,437,C:\Windows\system32\country.sys
- shell=C:\Windows\System32\command.com /p C:\Windows\system3
- file: scsD77C.tmp
- PREVIEW HEX
- @echo off
- lh C:\Windows\system32\mscdexnt.exe
- lh C:\Windows\system32\redir
- lh C:\Windows\system32\dosx
- SET BLASTER=A220 I5 D1 P330 T3
- file: scs987A.tmp
- dos=high, umb
- device=C:\Windows\system32\himem.sys
- files=40
- country=001,437,C:\Windows\system32\country.sys
- shell=C:\Windows\System32\command.com /p C:\Windows\system32
- file: scs987B.tmp
- @echo off
- lh C:\Windows\system32\mscdexnt.exe
- lh C:\Windows\system32\redir
- lh C:\Windows\system32\dosx
- SET BLASTER=A220 I5 D1 P330 T3
- file: UAC.dll
- https://www.virustotal.com/gui/file/0d21041a1b5cd9f9968fc1d457c78a802c9c5a23f375327e833501b65bcd095d/detection
- ps1 scrip:
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" "C:\Users\admin\AppData\Local\Temp\65e685fa-0999-4af5-b45f-5e2f5b105872.ps1
- run by powershell.exe:
- +228315ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NNX2TB7V29NGKRKV8LJL.temp
- Size: 5.90 Kb
- MD5: 2FCA486272F8F7793047404A4F6DA805binary
- +228315ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF202791.TMP
- Size: 5.90 Kb
- MD5: 2FCA486272F8F7793047404A4F6DA805binary
- +228315ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms
- Size: 5.90 Kb
- MD5: 2FCA486272F8F7793047404A4F6DA805binary
- +228877ms
- C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex
- Size: 5.32 Kb
- MD5: 7A2EF73DB3E4FBBB3E7AD2A76E884662pi2
- +229502ms
- C:\Users\admin\Desktop\tryingactually.png
- Size: 5.18 Kb
- MD5: E1708C4C06E54E5DDDC00126DD00F928image
- +229674ms
- C:\Users\admin\Desktop\perinformation.jpg
- Size: 32.4 Kb
- MD5: 8CD7974E628649F47F46B50178526DBAimage
- +229752ms
- C:\Users\admin\Desktop\fateye.png
- Size: 6.68 Kb
- MD5: BDC23F82DB4324031E10082E0817122Fimage
- +229815ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\fateye.png.lnk
- Size: 476 b
- MD5: 18D53863D21E4A07D8EBC03DD60EC6F1lnk
- +229877ms
- C:\Users\admin\Desktop\entertainmentgerman.png
- Size: 8.77 Kb
- MD5: 7F1D99187FD08E3DA128DAB67BC61FC0image
- +229940ms
- C:\Users\admin\Desktop\yetfilter.jpg
- Size: 4.50 Kb
- MD5: 7BCDA293373C9CE4BE0844B84B105F84image
- +229955ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\yetfilter.jpg.lnk
- Size: 493 b
- MD5: 0EF7201C8FF20926A5A7FC62260CE63Clnk
- +230049ms
- C:\Users\admin\Desktop\monitoringnokia.png
- Size: 7.43 Kb
- MD5: 560E7AFB67EBB6295217C05BB1A38980image
- +230158ms
- C:\Users\admin\Desktop\whetherhp.rtf
- Size: 3.00 Kb
- MD5: 638915E017375AC2B70F94885CF72AAAtext
- +230252ms
- C:\Users\admin\Desktop\creativebasic.rtf
- Size: 2.72 Kb
- MD5: 09A013A835635616E9AD6193EA319B8Btext
- +230315ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\creativebasic.rtf.lnk
- Size: 513 b
- MD5: BAF4CE032EFCB43794FDE4F2785ED6FFlnk
- +230362ms
- C:\Users\admin\Desktop\manufacturingrating.rtf
- Size: 2.79 Kb
- MD5: FA4CD9468CBB7AB6389B0A80FDBD4C97text
- +230408ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\manufacturingrating.rtf.lnk
- Size: 543 b
- MD5: 732FCB1015E33DD3FB8E7B2699607793lnk
- +230455ms
- C:\Users\admin\Desktop\organizationcross.rtf
- Size: 3.01 Kb
- MD5: 721977745B00CF047CE0E7182759122Ctext
- +230549ms
- C:\Users\admin\Desktop\recentlywashington.rtf
- Size: 2.99 Kb
- MD5: A89027701936FF57D7D2E7DFFD444AD1text
- +230612ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\recentlywashington.rtf.lnk
- Size: 538 b
- MD5: 0D76B60C062FFD449429D58486DEAD5Dlnk
- +230658ms
- C:\Users\admin\Desktop\onlyrequest.rtf
- Size: 2.86 Kb
- MD5: A4AAD26EEFFA005CCAD5EDD0B84EE723text
- +230737ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\onlyrequest.rtf.lnk
- Size: 503 b
- MD5: 3BFCB0EE8DEDAF32A8CBB77B2FACFC77lnk
- +230799ms
- C:\Users\admin\Pictures\settingsimportant.png
- Size: 2.26 Kb
- MD5: FD785E9A8CA89BF7295BF00FBCEF3230image
- +230877ms
- C:\Users\admin\Pictures\drugboston.png
- Size: 7.85 Kb
- MD5: B21893313DEC8BBBCD2B016DE6960B51image
- +230987ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\drugboston.png.lnk
- Size: 706 b
- MD5: 3E8581D5136860239C4797FCA1491483lnk
- +231033ms
- C:\Users\admin\Pictures\includesdocumentation.png
- Size: 1.62 Kb
- MD5: B2155EDDFB0EBA2B11AF098473C06038image
- +231049ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\includesdocumentation.png.lnk
- Size: 761 b
- MD5: 266817B9AFAAB2A360150E0CCE5A172Elnk
- +231096ms
- C:\Users\admin\Pictures\maryselected.png
- Size: 3.57 Kb
- MD5: ED386810FAAF6A7CFE3246BFE660DA92image
- +231112ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\maryselected.png.lnk
- Size: 716 b
- MD5: 8EE737876364F0E1D70077F8F7A12143lnk
- +231174ms
- C:\Users\admin\Pictures\havingtool.jpg
- Size: 7.33 Kb
- MD5: 12FFA21E7DF58BC6EB7A15E0B63D9A89image
- +231221ms
- C:\Users\admin\Documents\yearsign.rtf
- Size: 2.91 Kb
- MD5: 4C5DB9150BAD016A3354D9B781296ABFtext
- +231268ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\yearsign.rtf.lnk
- Size: 699 b
- MD5: 1908F1F14B343C47E602084C1275CD87lnk
- +231330ms
- C:\Users\admin\Documents\phonealways.rtf
- Size: 2.75 Kb
- MD5: C1871E27331C9250EA5A0797D827F8AEtext
- +231393ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\phonealways.rtf.lnk
- Size: 714 b
- MD5: E05DB585516563DAABA722D542D2DDF9lnk
- +231440ms
- C:\Users\admin\Documents\movelikely.rtf
- Size: 2.74 Kb
- MD5: 057DC0E3AC284127C8A49EA094BD7904text
- +231533ms
- C:\Users\admin\Documents\accountstook.rtf
- Size: 2.66 Kb
- MD5: D6730999D23CCF27CD0EBB1DBB63129Dtext
- +231580ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\accountstook.rtf.lnk
- Size: 719 b
- MD5: 63F995A18A6208CB090BCD75BD8F0ADAlnk
- +231627ms
- C:\Users\admin\Documents\ltdtable.rtf
- Size: 2.67 Kb
- MD5: BB74F237DD5294966A4ADF79598AB406text
- +231690ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\ltdtable.rtf.lnk
- Size: 699 b
- MD5: 6F85793281CF1476BA097ECAD99C1C08lnk
- +231768ms
- C:\Users\admin\Downloads\particularlysecure.png
- Size: 8.91 Kb
- MD5: BFB5B2917A1109227CED102F71C842B2image
- +231783ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\particularlysecure.png.lnk
- Size: 733 b
- MD5: D68CE0D217953E07A47AC207CF5C6E2Dlnk
- +231846ms
- C:\Users\admin\Downloads\havingdeep.jpg
- Size: 5.54 Kb
- MD5: 5F79B6564A903452F906AD60423A54B7image
- +231877ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\havingdeep.jpg.lnk
- Size: 693 b
- MD5: 4D4D80A2C305E4629190861C2D4E1B22lnk
- +231955ms
- C:\Users\admin\Downloads\electriccopyright.jpg
- Size: 15.1 Kb
- MD5: 319C130AD0D0C1CE2CFACFCCD5B266E8image
- +231971ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\electriccopyright.jpg.lnk
- Size: 728 b
- MD5: 0871FF7E138F9BC457A15A2D8C4C9486lnk
- +232018ms
- C:\Users\admin\Downloads\modelsself.png
- Size: 2.63 Kb
- MD5: D93C000560837FCC862283DD382D3063image
- +232033ms
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\modelsself.png.lnk
- Size: 693 b
- MD5: 972975FCF4AB5997E3A1A1ED131408E4lnk
- +232080ms
- C:\Users\admin\Downloads\bottomliving.png
- Size: 3.35 Kb
- MD5: 91761ABBD3BBF5D23EAF9F4755D8144Eimage
- +232158ms
- C:\Users\admin\Downloads\clinicalcells.png
- Size: 4.63 Kb
- MD5: 1D7BBB59DE8E32BECF44B29DCC9339EFimage
- +232205ms
- C:\Users\admin\AppData\Local\Temp\lkfxwoxt.ky5
- Size: 717 b
- MD5: 34D810063102A5E4FFE85589E5AC2BFCbinary
- +232237ms
- C:\Users\admin\AppData\Local\Temp\utqycenp.bee
- Size: 257 b
- MD5: FF34ADF6AD723833A36C3947945338D8binary
- +232252ms
- C:\Users\admin\AppData\Local\Temp\5d0kb4ud.cyy
- Size: 297 b
- MD5: 3FA51E921827E61FFFD4E2DCF9FF01E2binary
- +232330ms
- C:\Users\admin\AppData\Local\Temp\lgu2avi3.4rp
- Size: 891 b
- MD5: 83E27FCEF02EB252D67717DACF76C437binary
- +232362ms
- C:\Users\admin\AppData\Local\Temp\mz30vffo.1gp
- Size: 722 b
- MD5: F92045A92A8A5088042D2D25DEBD3124binary
- +232393ms
- C:\Users\admin\AppData\Local\Temp\zqbl3dxm.lhn
- Size: 484 b
- MD5: E68BCCFD99B96779BA147BD0C1D37E2Bbinary
- +232408ms
- C:\Users\admin\AppData\Local\Temp\jokklbvp.alj
- Size: 513 b
- MD5: 945AF1CA64A4165D3C3F852B16B9BFA2binary
- +232455ms
- C:\Users\admin\AppData\Local\Temp\mbpk3n1n.jky
- Size: 755 b
- MD5: B31955EED7EBD011875E19B79D9D361Dbinary
- +232471ms
- C:\Users\admin\AppData\Local\Temp\r54uzwon.tjh
- Size: 311 b
- MD5: BD5DF11AD9AECDA27C07A2FFEA3AE30Dbinary
- +232518ms
- C:\Users\admin\AppData\Local\Temp\etz3wygc.wwd
- Size: 889 b
- MD5: 9B0FA1462B44914EAF0CC9E4591A9A4Fbinary
- +232533ms
- C:\Users\admin\AppData\Local\Temp\2xmuf54q.qu1
- Size: 228 b
- MD5: DF0EA13856B780894AA2C310C465BC37binary
- +232580ms
- C:\Users\admin\AppData\Local\Temp\n1uhllh2.kmx
- Size: 916 b
- MD5: 61713B690E3B3281F07D37F2EE4794F2binary
- +232612ms
- C:\Users\admin\AppData\Local\Temp\tmiwv5zy.3tc
- Size: 328 b
- MD5: E0EC3098AA1249796C2958145D72300Dbinary
- +232643ms
- C:\Users\admin\AppData\Local\Temp\ys25gsx5.knz
- Size: 659 b
- MD5: 702E875F62F2A043DD6FCD8CFB10ACAAbinary
- +232690ms
- C:\Users\admin\AppData\Local\Temp\cicqlb55.4ok
- Size: 718 b
- MD5: 95DE358148EFA16DA700E24DCF8F75EFbinary
- +232705ms
- C:\Users\admin\AppData\Local\Temp\4rkyqdhg.05s
- Size: 263 b
- MD5: 0687AC7780616496585619F92850ADCFbinary
- +232705ms
- C:\Users\admin\AppData\Local\Temp\yvvri4b3.bwn
- Size: 164 b
- MD5: 95E4AB209CDEC0FBCE156988A2AAB5D1binary
- +232737ms
- C:\Users\admin\AppData\Local\Temp\ktm3davc.ps5
- Size: 286 b
- MD5: A7F813FB9D49B6B2DBB15E5A5E3E32B1binary
- +232752ms
- C:\Users\admin\AppData\Local\Temp\ssvwxvgg.5ad
- Size: 184 b
- MD5: 33E15D5FCCD65F725E07995CF649F023binary
- +232783ms
- C:\Users\admin\AppData\Local\Temp\sr3b1teg.xhu
- Size: 647 b
- MD5: 4EDE7E06F7AFE96A15EA3CECD835B4E4binary
- -------------------------
- research files:
- 228.31 s
- 3004
- powershell.exe
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NNX2TB7V29NGKRKV8LJL.temp
- 5.90 Kb
- binary
- 228.31 s
- 3004
- powershell.exe
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF202791.TMP
- 5.90 Kb
- binary
- 228.31 s
- 3004
- powershell.exe
- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms
- 5.90 Kb
Add Comment
Please, Sign In to add comment