Threat Database Backdoors Backdoor.Agent.TOB

Backdoor.Agent.TOB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 19,922
Threat Level: 60 % (Medium)
Infected Computers: 7
First Seen: August 21, 2025
Last Seen: July 23, 2026
OS(es) Affected: Windows

The detection of Backdoor.Agent.TOB on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise your system's security and allow unauthorized access to your data. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Agent.TOB?

Backdoor.Agent.TOB is a type of malware that creates a secret doorway into your system, allowing hackers to access your computer without your knowledge or consent. This backdoor can be used to steal sensitive information, install additional malware, or take control of your system. The name "Backdoor.Agent.TOB" suggests that it is a backdoor threat, but the exact nature and origin of this malware are not specified.

How Backdoor.Agent.TOB Operates

Backdoor.Agent.TOB operates by exploiting vulnerabilities in your system or using social engineering tactics to gain access to your computer. Once inside, it can create a hidden channel for communication with its command and control server, allowing hackers to send commands and receive stolen data. This malware can also modify system settings, disable security software, and install additional malware to further compromise your system.

Symptoms of Infection

The symptoms of a Backdoor.Agent.TOB infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. Additionally, you may receive alerts from your security software or notice that your system settings have been changed without your consent.

  • Unexplained system crashes or freezes
  • Slow system performance or sluggish response
  • Unfamiliar programs or processes running in the background
  • Suspicious network activity or unusual outgoing connections
  • Changes to system settings or security software configurations

How to Remove Backdoor.Agent.TOB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.Agent.TOB from your system requires careful attention and a thorough approach. By following the steps outlined above, you can help to ensure that your system is free from this malware and prevent future infections. It is essential to remain vigilant and take proactive steps to protect your system, including keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and email attachments.

Analysis Report

General information

Family Name: Backdoor.Agent.TOB
Signature status: No Signature

Known Samples

MD5: 3597e4f2dd2f0ae51c60bdf3024fe5a0
SHA1: 85361ce6fe2334d8fac5d5a407aa56c83c9188db
SHA256: A1B09891CBCB35E7D970EF456C620F3EFD4E4346EBB1156BC3A986A35E68030D
File Size: 3.72 MB, 3724288 bytes
MD5: e07d2e2fd9274688846202094cfaabdd
SHA1: f54543ee5bd4b0bcef4301457256fc435fa7bc4b
SHA256: AAB802486BF326087610FCF6A6940050CBE5239E37236F9722703F62829F4B26
File Size: 1.71 MB, 1713664 bytes
MD5: 3dff81c321d80b07eeffa3316402ea49
SHA1: 4a53eb7c16678faea871bed00eaf9cd01f88bc4a
SHA256: D87F81F76A25ECB75E9B6CBFC28DED1AF332ED5B55BCFEC7E8BFEA92C2BFC203
File Size: 1.71 MB, 1714176 bytes
MD5: d2aa7722390714fd077b202f551acbbc
SHA1: f79480176d04c9b6e5daf46e537ff8d47b1aceb2
SHA256: 913881562C22E4361FF787A338BC994AAC9925BA6C329283A81D1CDD1314AF98
File Size: 3.25 MB, 3245056 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 20,815
Potentially Malicious Blocks: 144
Whitelisted Blocks: 15,525
Unknown Blocks: 5,146

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? x 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 ? ? 0 0 ? x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 0 0 ? ? ? 0 0 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? 0 ? ? ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? 0 0 ? ? 0 0 0 ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 ? ? ? ? ? 0 0 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 ? ? x 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? x 0 0 0 0 0 0 x 0 0 x x x 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 ? 0 ? 0 0 0 0 x 0 0 0 0 0 0 ? 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 ? ? ? 0 0 ? ? 0 ? 0 0 ? 0 0 0 x 0 ? ? 0 0 ? ? ? 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 x 0 0 0 0 x 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
\device\namedpipe\__rust_anonymous_pipe1__.5604.15767353484642555707 Generic Write,Read Attributes
\device\namedpipe\__rust_anonymous_pipe1__.5604.15767353484642555708 Generic Write,Read Attributes
c:\users\user\appdata\local\packages\microsoft.outlookforwindows_0wekyb2a8bbwe\opta7\outlook.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\securityhealth\stat.txt Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\securityhealth\winsecurityhealth.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\runonce::uninstall 39.001.0014.0001 C:\Users\Qxlbnccb\AppData\Local\Packages\Microsoft.OutlookForWindows_0wekyb2a8bbwe\opta7\Outlook.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::windowssecurityhealthservice C:\Users\Lpwqknzx\AppData\Roaming\Microsoft\SecurityHealth\WinSecurityHealth.exe RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender\exclusions\paths::c:\users\lpwqknzx\appdata\roaming\microsoft\securityhealth RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender\exclusions\paths::c:\users\lpwqknzx\appdata\roaming\microsoft\securityhealth\winsecurityhealth.exe RegNtPreCreateKey
HKLM\software\microsoft\windows defender\exclusions\paths::c:\users\lpwqknzx\appdata\roaming\microsoft\securityhealth RegNtPreCreateKey
HKLM\software\microsoft\windows defender\exclusions\paths::c:\users\lpwqknzx\appdata\roaming\microsoft\securityhealth\winsecurityhealth.exe RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender\real-time protection::disablebehaviormonitoring  RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender\real-time protection::disableonaccessprotection  RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender\real-time protection::disablescanonrealtimeenable  RegNtPreCreateKey
HKLM\software\policies\microsoft\windows defender::disableantispyware  RegNtPreCreateKey
Show More
HKLM\software\policies\microsoft\windows defender\exclusions\processes::winsecurityhealth.exe RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
Process Shell Execute
  • CreateProcess
  • ShellExecute
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
User Data Access
  • OpenClipboard

Shell Command Execution

C:\WINDOWS\system32\net.exe "net" session
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
Show More
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
runas c:\users\user\downloads\85361ce6fe2334d8fac5d5a407aa56c83c9188db_0003724288
C:\WINDOWS\system32\schtasks.exe "schtasks" /Create /SC ONLOGON /TN WindowsSecurityHealthService /TR \"C:\Users\Lpwqknzx\AppData\Roaming\Microsoft\SecurityHealth\WinSecurityHealth.exe\" /RL HIGHEST /F