Threat Database Trojans Trojan.MSIL.Downloader.J

Trojan.MSIL.Downloader.J

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,164
Threat Level: 80 % (High)
Infected Computers: 482
First Seen: December 30, 2012
Last Seen: June 13, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.J on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malware that could be used to download additional malicious components, potentially leading to further system compromise. Understanding the nature of this threat and taking prompt action is crucial to protect your computer and sensitive information.

What Is Trojan.MSIL.Downloader.J?

Trojan.MSIL.Downloader.J is identified as a Trojan-type threat, which typically means it is designed to allow unauthorized access to the victim's computer. The "Downloader" part of its name implies that it may be used to download and install additional malware or malicious software components. This type of malware can be particularly dangerous because it can lead to a variety of malicious activities on the infected computer, including data theft, ransom demands, or the installation of more malware.

How Trojan.MSIL.Downloader.J Operates

Trojan.MSIL.Downloader.J, like other Trojans, is likely to operate by disguising itself as legitimate software or by exploiting vulnerabilities in the system or applications to gain unauthorized access. Once inside, it can communicate with its command and control servers to receive instructions, which may include downloading additional malware. This malware can be highly adaptable and may evolve over time to evade detection by security software. Its primary goal is often to maintain a covert presence on the infected system, allowing the attackers to carry out their malicious intentions without being detected.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Downloader.J infection can vary widely, depending on the specific goals of the attackers and the additional malware it downloads. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or frequent crashes. You might also notice unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your permission. In some cases, the infection might not display obvious symptoms, making it difficult to detect without the aid of security software.

How to Remove Trojan.MSIL.Downloader.J

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Downloader.J requires careful and immediate action to prevent further damage to your system and to protect your personal data. By following the steps outlined above and maintaining vigilance with regular system scans and updates, you can significantly reduce the risk of malware infections. It's also important to practice safe computing habits, such as avoiding suspicious downloads and emails, to minimize the chance of future infections. Remember, staying informed and proactive is key to securing your digital environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.J
Signature status: No Signature

Known Samples

MD5: 34ca6de64fe308eb6667953123155d98
SHA1: ab3a2d61ee0670f78cf3f8626ab0c2a952e8f6ea
SHA256: 3B099DBA8E1B6493418F4D600DB9478EEDA9904FA2E2EB9FADC18ED114DEF6DD
File Size: 610.82 KB, 610816 bytes
MD5: 890fe61c68c8e6fe6f4ba07ad8944d79
SHA1: e479d8fecfc9b0ab8b8ab33d86e3acc9174a140a
SHA256: C47E3791FB2FC1A2D71AFE6242B515E1BAC35B0320B4805DC62CF0BCF21B68B8
File Size: 189.95 KB, 189952 bytes
MD5: 5c6c3eb103a172187f9c5656d56781d4
SHA1: e205d3b00c7c39afeb8e91e210677226c16e334a
SHA256: 2733BB1CD0AE7673D259B1F2C2E71CB5E26C204479AD499C4CBE6B8EEE9039C7
File Size: 198.66 KB, 198656 bytes
MD5: d6dc6778f9278052dd7be8d8664419c5
SHA1: e80147aea87557c3fa3f8ba9eb3a2dfade121a1f
SHA256: 31FA202997B00428C008768DDC00043FED77F87075E98023CF540DED7CF09BFA
File Size: 1.18 MB, 1176220 bytes
MD5: e643574554004cdc3a958cc218a2a8fb
SHA1: 20fe55cc59bc57353e76f2a3ceaa08da2da023b5
SHA256: 6AC94482E7757E83E4D6C9B6E901F826123E56969963548B3BC5E030FD5B4487
File Size: 352.26 KB, 352256 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Limpiador de medios extraíbles
Company Name
  • GHOST SPECTRE
  • MOVISUR Tool
  • Streuner Corporation
File Description
  • GHOST TOOLBOX
  • Limpiador de medios extraíbles
File Version
  • 18.00.00.00
  • 1. 6. 7. 0
  • 1. 4. 5. 0
  • 0. 0. 0. 0
Internal Name USB File Resc
Legal Copyright
  • 2020
  • CopyRight @ 2021
Legal Trademarks
  • CopyRight @ 2021- México - 2013-11 a 2021-01
  • GHOST SPECTRE
Original Filename
  • GHOST TOOLBOX
  • USB File Resc
Product Name
  • GHOST TOOLBOX
  • MOVISUR Tool
  • USB File Resc
Product Version
  • 18.00.00.00
  • 1.6.7.0
  • 1.4.5.0
  • 0.0.0.0

File Traits

  • No Version Info
  • packed
  • VirtualQueryEx
  • WinZip SFX
  • x64
  • ZIP (In Overlay)
  • ZIPinO

Block Information

Total Blocks: 1,092
Potentially Malicious Blocks: 279
Whitelisted Blocks: 812
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 1 0 0 0 1 0 0 0 1 0 0 1 0 0 0 1 0 0 0 1 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x 0 0 0 x x x x x 0 0 0 0 x x x 0 0 0 0 x x 0 x 0 x x 0 x x 0 0 x x x x 0 x 0 0 x x 0 0 x x x 0 x x x x x 0 x 0 0 x x 0 0 x x 0 0 x 0 x x x x x x x x x x x x x x x 0 x x 0 0 x x 0 x x x x x x x x x 0 0 x x x x x x 0 x 0 x x x x x 0 x 0 0 x x 0 x x x x x 0 x x x x 0 x x 0 x 0 0 x 0 0 x 0 x 0 x 0 0 x x x x x x 0 0 0 x x x x x x 0 x x x x x x 0 x 0 0 0 x x 0 0 x x x x x 0 x 0 x 0 x 0 x x x x x x x 0 x 0 x x 0 x 0 x x x x 0 x x x x 0 x 0 x x 0 x 0 x 0 x x 0 x 0 0 x x 0 x x x 0 x 0 x 0 x x 0 x 0 x 0 0 0 0 x 1 x x x 0 1 0 x x x x x x x x x x x 0 x x x x x 0 x x x x x 0 x 0 x x x x x 0 x x 0 0 x x x x x x 0 x 0 0 x x x 0 x x x x x 0 x x x x 0 x x 0 x x 0 x 0 0 0 x 0 x 0 0 x x x x x 0 x 0 0 x 0 x x x 0 x x 0 x x 0 x 0 x 0 x x x x x 0 x x x x x 0 x x x x x x x x x x x x x 0 x x x x 0 x 0 x x x 0 x 0 0 x x 0 0 0 0 1 0 0 x ? 0 0 x 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.GY
  • Alien.A
  • MSIL.Downloader.J
  • Vemptik.A

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\pshost.134219301117301458.8040.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\usb file resc\datos\estoy de acuerdo 2020-12.txt Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4e59qa58.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\85xr8qyw.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_mtqg1zpm.4yb.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_tryvapl2.klu.psm1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\cn8hgcnb.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\qb749cf7.cf\winhttpjs.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\ p Generic Write,Read Attributes
c:\users\user\downloads\ b Generic Write,Read Attributes
c:\users\user\downloads\ g Generic Write,Read Attributes
c:\users\user\downloads\ s Generic Write,Read Attributes
c:\users\user\downloads\ c Generic Write,Read Attributes
c:\users\user\downloads\ e Generic Write,Read Attributes
c:\users\user\downloads\ h Generic Write,Read Attributes
c:\users\user\downloads\ o Generic Write,Read Attributes
c:\users\user\downloads\ p Generic Write,Read Attributes
c:\users\user\downloads\ r Generic Write,Read Attributes
c:\users\user\downloads\ s Generic Write,Read Attributes
c:\users\user\downloads\ t Generic Write,Read Attributes
c:\users\user\downloads\ d Generic Write,Read Attributes
c:\users\user\downloads\ e Generic Write,Read Attributes
c:\users\user\downloads\ o Generic Write,Read Attributes
c:\users\user\downloads\ r Generic Write,Read Attributes
c:\users\user\downloads\ w Generic Write,Read Attributes
c:\users\user\downloads\ y Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 됅솬韆ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᘶ솯韆ǜ RegNtPreCreateKey
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\ndfapi.dll,-40001 Windows Network Diagnostics RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ₢偞ꋣǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 姾偸ꋣǜ RegNtPreCreateKey
HKCU\console::windowalpha ó RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ߞC��� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySection
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2

20 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserNameEx
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

cmd.exe /c ""C:\Users\Mdoqpycd\AppData\Local\Temp\4E59QA58.bat" "c:\users\user\downloads\e479d8fecfc9b0ab8b8ab33d86e3acc9174a140a_0000189952""
C:\WINDOWS\system32\chcp.com chcp 65001
WriteConsole: Active code page
C:\WINDOWS\system32\net.exe net session
C:\WINDOWS\system32\takeown.exe takeown /f "c:\Users\user\downloads\." /r /d n
Show More
WriteConsole: ERROR:
WriteConsole: This stream is n
C:\WINDOWS\system32\cacls.exe cacls "c:\Users\user\downloads\." /t /e /p administrators:f
WriteConsole: c:\Users\user\do
C:\WINDOWS\system32\cacls.exe cacls "c:\Users\user\downloads\." /t /e /p users:f
WriteConsole: The system canno
cmd.exe /c ""C:\Users\Twluwncs\AppData\Local\Temp\85XR8QYW.bat" "c:\users\user\downloads\e205d3b00c7c39afeb8e91e210677226c16e334a_0000198656""
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " P" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " o" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " w" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " e" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " r" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " d" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " b" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:03 /R "+" " y" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " G" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " H" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " O" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " S" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " T" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " S" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " P" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " E" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " C" nul
C:\WINDOWS\system32\findstr.exe findstr /v /a:0D /R "+" " R" nul
C:\WINDOWS\system32\timeout.exe timeout /t 2
C:\WINDOWS\system32\reg.exe REG ADD "HKCU\Console" /v "WindowAlpha" /t REG_DWORD /d "243" /f
cmd.exe /c ""C:\Users\Blqekjvr\AppData\Local\Temp\CN8HGCNB.bat" "c:\users\user\downloads\e80147aea87557c3fa3f8ba9eb3a2dfade121a1f_0001176220""
C:\WINDOWS\system32\mode.com MODE CON: COLS=33 LINES=25
C:\WINDOWS\system32\timeout.exe timeout -t 0
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe Powershell Get-Date

Related Posts

Trending

Most Viewed

Loading...