Threat Database Stealers Trojan.Stealer.FAT

Trojan.Stealer.FAT

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 16,346
Threat Level: 80 % (High)
Infected Computers: 2,148
First Seen: July 28, 2023
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.FAT on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this report, we will provide you with information on what Trojan.Stealer.FAT is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is Trojan.Stealer.FAT?

Trojan.Stealer.FAT is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The term "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. The ".Stealer" part of the name suggests that this malware is designed to steal sensitive information from your computer, such as login credentials, financial data, or personal files. The ".FAT" extension may indicate the type of file system or storage device that the malware targets.

How Trojan.Stealer.FAT Operates

Once Trojan.Stealer.FAT infects your computer, it can operate in various ways to achieve its malicious goals. It may create backdoors, allowing remote access to your system, or install additional malware to further compromise your security. The malware may also attempt to communicate with its command and control servers to receive updates or transmit stolen data. Trojan.Stealer.FAT can spread through various means, including infected software downloads, phishing emails, or exploited vulnerabilities in your system or applications.

Symptoms of Infection

The symptoms of a Trojan.Stealer.FAT infection can vary, but common signs include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice that your antivirus software is disabled or that your browser settings have been altered. Additionally, you might receive suspicious emails or messages that appear to be from legitimate sources but are actually phishing attempts. If you suspect that your system is infected with Trojan.Stealer.FAT, it is essential to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.Stealer.FAT

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Trojan.Stealer.FAT.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Stealer.FAT from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined in this report, you can help ensure that your computer is free from this malicious threat. It is also essential to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when downloading files or clicking on links from unknown sources. Remember to always prioritize your online security and take immediate action if you suspect that your system has been compromised.

Analysis Report

General information

Family Name: Trojan.Stealer.FAT
Signature status: No Signature

Known Samples

MD5: 53a14a456fad21dc73814d0ed1965307
SHA1: a7b503ca75c683cebc048d48bed14802af6883e7
SHA256: 522E808D0B237E6A59D818A1046FBBDB82175FBC414F54135835AA5FB8A874DF
File Size: 721.41 KB, 721408 bytes
MD5: 69dcb0f64270c3ba43e95ce46d237fd4
SHA1: 8135d7ce8bbdd5daf98527f756031a88f1acdccd
SHA256: 714E89F99E705B8C2F9EB5559AE69B7CCC3570D8A95743AD3CA900D03577B45D
File Size: 569.86 KB, 569856 bytes
MD5: 9c5096adccd51a9746a84e562dcbaee5
SHA1: af927bcdfcef4012494bbd18e464efd88aa12c5e
SHA256: 4B4048A043BE0EB933B0E3D302539B8310C07197CBFCF0C75B19AE503B7A5746
File Size: 494.59 KB, 494592 bytes
MD5: 80178d776a7168cf291774daf1e11065
SHA1: adf24996eb76b580fd63f8f1b589bca2a3ac00d6
SHA256: F741CB7353AD5FF35A5B59DD4215F5514CEDEA6CE66E201EB57B4D8E438527F9
File Size: 607.74 KB, 607744 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\925e7e99c5\pdates.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\ixp000.tmp\3dl6oa44.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\3dl6oa44.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\em4xd5bx.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\em4xd5bx.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\i8910395.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\i8910395.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ixp000.tmp\k0233187.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\k0233187.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\n7095961.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\n7095961.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp000.tmp\x3603690.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\x3603690.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\x9759097.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\x9759097.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\y4352683.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\y4352683.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\1ir28sm6.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\1ir28sm6.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\2nr569vq.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\2nr569vq.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\g9207317.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\g9207317.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\h6723170.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\h6723170.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\j7171060.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\j7171060.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\m0284475.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\m0284475.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp001.tmp\x2161621.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\x2161621.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\y8687523.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\y8687523.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\i6020670.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\i6020670.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\k1739014.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\k1739014.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\k1739014.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\l9228160.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\l9228160.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\l9228160.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp002.tmp\x5416121.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\x5416121.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\g7727314.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\g7727314.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\g7727314.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\h2868865.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\h2868865.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\h2868865.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Szzvxjzz\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Szzvxjzz\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup2 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Szzvxjzz\AppData\Local\Temp\IXP002.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup3 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Szzvxjzz\AppData\Local\Temp\IXP003.TMP\" RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p ��^�o�ee@Vs}kP~��1Q��7 ���ﺃee��� ��1 ��fe��g� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鼅㌄珷ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �6 �v y� xy �� �a ۀT�B������1�����5����eeBx�<�� �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��1`1�1HO1�D5�G RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Hapxxdgx\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Hapxxdgx\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup2 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Hapxxdgx\AppData\Local\Temp\IXP002.TMP\" RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��2 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\user shell folders::startup C:\Users\Hapxxdgx\AppData\Local\Temp\925e7e99c5\ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 螪쮠痸ǜ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Vnudcsiz\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Vnudcsiz\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �ʑ�s�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Tcvlkxiz\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Tcvlkxiz\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserName
  • GetUserObjectInformation
Service Control
  • OpenSCManager
  • OpenService
  • StartService
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Szzvxjzz\AppData\Local\Temp\IXP000.TMP\x3603690.exe
C:\Users\Szzvxjzz\AppData\Local\Temp\IXP001.TMP\x2161621.exe
C:\Users\Szzvxjzz\AppData\Local\Temp\IXP002.TMP\x5416121.exe
C:\Users\Szzvxjzz\AppData\Local\Temp\IXP003.TMP\g7727314.exe
C:\Users\Szzvxjzz\AppData\Local\Temp\IXP003.TMP\h2868865.exe
Show More
cmd /k shutdown -s -t 0
C:\Users\Szzvxjzz\AppData\Local\Temp\IXP002.TMP\i6020670.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\IXP000.TMP\y4352683.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\IXP001.TMP\y8687523.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\IXP002.TMP\k1739014.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\IXP002.TMP\l9228160.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\925e7e99c5\pdates.exe
C:\Users\Hapxxdgx\AppData\Local\Temp\IXP001.TMP\m0284475.exe
SCHTASKS /Create /SC MINUTE /MO 1 /TN pdates.exe /TR "C:\Users\Hapxxdgx\AppData\Local\Temp\925e7e99c5\pdates.exe" /F
cmd /k echo Y|CACLS "pdates.exe" /P "Hapxxdgx:N"&&CACLS "pdates.exe" /P "Hapxxdgx:R" /E&&echo Y|CACLS "..\925e7e99c5" /P "Hapxxdgx:N"&&CACLS "..\925e7e99c5" /P "Hapxxdgx:R" /E&&Exit
WriteConsole:
WriteConsole: C:\Users\Hapxxdg
C:\Users\Vnudcsiz\AppData\Local\Temp\IXP000.TMP\x9759097.exe
C:\Users\Vnudcsiz\AppData\Local\Temp\IXP001.TMP\g9207317.exe
C:\Users\Tcvlkxiz\AppData\Local\Temp\IXP000.TMP\Em4XD5BX.exe
C:\Users\Tcvlkxiz\AppData\Local\Temp\IXP001.TMP\1IR28SM6.exe