Threat Database Trojans Trojan.Kryptik.FGH

Trojan.Kryptik.FGH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,655
Threat Level: 80 % (High)
Infected Computers: 27
First Seen: July 10, 2024
Last Seen: May 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.FGH on your system indicates a potential security threat. This detection name suggests a type of malicious software, but without more specific information, it's essential to understand the general characteristics of Trojan-type threats and how to address them. Trojans are a common type of malware that can cause significant harm to your computer and data. In this report, we will provide an overview of what Trojan.Kryptik.FGH might entail, its operational methods, symptoms of infection, removal guidance, and conclude with recommendations for safeguarding your system.

What Is Trojan.Kryptik.FGH?

Trojan.Kryptik.FGH, as a detection name, implies a Trojan-type threat. Trojans are malicious programs that disguise themselves as legitimate software. They can be designed to perform a wide range of malicious actions, from stealing sensitive information to providing unauthorized access to your system. The name Trojan.Kryptik.FGH itself does not directly indicate a specific malware family but suggests it could be related to or classified under the broader category of Trojan malware.

How Trojan.Kryptik.FGH Operates

Trojan-type malware, including Trojan.Kryptik.FGH, typically operates by deceiving users into installing them on their systems. This can happen through various means, such as downloading infected software, opening malicious email attachments, or clicking on compromised links. Once installed, the Trojan can start its malicious activities, which might include data theft, keystroke logging, or even turning your computer into a botnet node. The specific operational details of Trojan.Kryptik.FGH would depend on its design and purpose, which can vary widely among different types of Trojans.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unexpected changes to your computer's performance, such as slowdowns, frequent crashes, or the appearance of unfamiliar programs. You might also notice unusual network activity, even when you're not using your internet connection. Sometimes, Trojans can trigger pop-ups, redirects, or other unwanted browser behaviors. Being vigilant about these symptoms can help in early detection and removal of the threat.

How to Remove Trojan.Kryptik.FGH

  1. Enter Safe Mode with Networking to limit the malware's ability to spread or cause further damage. This mode allows you to use the internet to download removal tools if necessary.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure your antivirus software is up-to-date to increase the chances of detecting and removing the threat.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the threat was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your browser settings for Chrome, Firefox, Edge, or any other browsers you use. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan to ensure that the threat has been fully removed. Repeat the scanning process until no threats are detected.

Conclusion

Dealing with a Trojan.Kryptik.FGH infection requires careful and immediate action to prevent further damage to your system and data. By understanding the nature of Trojan-type threats and following the removal steps outlined, you can effectively eliminate the malware and protect your computer from future infections. Remember, prevention is key; keeping your operating system, software, and security tools updated, along with practicing safe computing habits, is crucial in minimizing the risk of malware infections.

Analysis Report

General information

Family Name: Trojan.Kryptik.FGH
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 43affcda02a3376f069ea9bc998bb61f
SHA1: 3555bc63f9a2d6b5311ae27544e4ce39b3f1824b
SHA256: 3BA710D071B01D485A673D6267D8053874E811CA7358C1878864E1187018BA30
File Size: 1.61 MB, 1609571 bytes
MD5: a16496bddac6c7a874a7428f2f4cf785
SHA1: 8b6493351a33a2698de4c09fc803d7b3d0cd7b1c
SHA256: 8DFE9E2BB8D08CAE5126144911741DF97C7C1705D1ED348919B90275DEA5EA6C
File Size: 3.14 MB, 3137596 bytes
MD5: d845c76b3f01dc334ca82ca0840a0e92
SHA1: 2ccf5211844b30689b7ad5a58c5838d0081177d3
SHA256: 01640BD488DA6468DA1A4E2A29F4D16810F99A076867AB3BEA49F3F322923C9E
File Size: 1.88 MB, 1884062 bytes
MD5: df5959f119ca5d26e0dbbe436b87c61f
SHA1: c671eafa85610ced37f59bd478aba97b35dddd7e
SHA256: 29EF6AE0DF39ED210149F23A6A2558488846F64A007363DC62AD8882AFCBD118
File Size: 1.56 MB, 1563432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Coder By BlueLife
Comments
  • https://fastcopy.jp
  • Made in Belorussia
Company Name
  • FastCopy Lab, LLC.
  • Victoria Software
  • www.sordum.org
File Description
  • FastCopy
  • Firewall App Blocker
  • HDD/SSD low-level test, repair & benchmark utility
File Version
  • 4.7.5.0
  • 3.9.2.0
  • 1.7.0.0
Internal Name
  • FastCopy
  • Generic DS Project
Legal Copyright
  • Copyright (C) 2004-2020 SHIROUZU Hiroaki and FastCopy Lab, LLC. All rights reserved.
  • Copyright © 2012 - 2020 www.sordum.org All Rights Reserved.
  • Sergei Kazanskij, (c) 2003-2019
Legal Trademarks Sergei Kazanski, http://hdd.by
Original Filename FastCopy.exe
Product Name
  • FastCopy
  • HSP Victoria
Product Version
  • 4.7.5.0 beta
  • 3.9.2.0

File Traits

  • 7-zip (In Overlay)
  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Files Modified

File Attributes
\device\namedpipe\pecmd_exec_1408928700 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_2155014085 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_2230725535 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_2679598059 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_2809967252 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_3364593708 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_3434041853 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_371835406 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_4269072295 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pecmd_exec_532823635 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\rgi3d9.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgi3d9.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgi466.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgi466.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgi4b6.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgi4b6.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgi4e5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgi4e5.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgi525.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgi525.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgic20d.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgic20d.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgic26b.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgic26b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgic28c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgic28c.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgic29c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgic29c.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rgic2ad.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rgic2ad.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\tmp4352$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\~1073411208753215274.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~1073411208753215274.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~3394928636595389786.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~3394928636595389786.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~3517731149208182464~ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~3517731149208182464~\sg.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~3590539733339940820~ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~3590539733339940820~\sg.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~3643889440840526254~ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~3643889440840526254~\sg.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~4602741059389092454 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~4703810647851280148 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~4818952235533974256.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~4818952235533974256.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~5360940256629074852.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~5360940256629074852.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~6945455117672694251.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~6945455117672694251.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~7230215032063226779.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~7230215032063226779.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~9163940350632943779~ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~9163940350632943779~\sg.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\recent\automaticdestinations\5f7b5f1e01b83767.automaticdestinations-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\recent\automaticdestinations\f01b4d95cf55d32a.automaticdestinations-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 휚隈❕ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 휚隈❕ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 嫛霎❕ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ᣇ饔❕ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �6( xy kP~�ރ ������^ ۴�}�Vs}5kP~5��1������d B F e#��1���h��n�} e�� e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �T�r����`��*����8��B +� �� �6 �} �� �� 7� xy �� �� � ۀ>�=�����B�O�����x�%���8�5����Bx�����\�!I�RN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�' RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 沺验❕ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 沺验❕ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ꟱䑽政ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 켞䒄政ǜ RegNtPreCreateKey
Show More
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ҟ䓼政ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~= xy�ރ��^��zee�Vs}kP~��1b��ee��� ��1��fe��h�n�i(e��r]�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�\x +� �� �6 xy �� ۀ����%���5Bx���R!wz#@�#��%f�'�(�*9*�"/9�0P%1HO1�D5,]6�^9�9ߔ>3�@V�@ڙ@��B��H��JL�J��K�iN$N�R20U_*V �VN�\te`�2c�wd��g��lR n�Ao��rnJr�7r�Btu�u�~ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 뚜됩ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 咃뚟됩ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 뜘됩ǜ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\advanced inf setup\ie complist::ie.hkcuzoneinfo RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 迪례됩ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 迪례됩ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee>Vs}kP~��1.��7 ���ﺃee��� ��1��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��0P% RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ���1��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ��1��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe kh�2��� RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • AdjustTokenPrivileges
Process Shell Execute
  • CreateProcess
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetEntry
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextFaceW

72 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

cmd.exe /c set
C:\Users\Otwvfvvt\AppData\Local\Temp\~3517731149208182464~\sg.tmp 7zG_exe x "c:\users\user\downloads\3555bc63f9a2d6b5311ae27544e4ce39b3f1824b_0001609571" -y -aoa -o"C:\Users\Otwvfvvt\AppData\Local\Temp\~4703810647851280148"
c:\users\user\downloads\3555bc63f9a2d6b5311ae27544e4ce39b3f1824b_0001609571 PECMD**pecmd-cmd* EXEC -wd:C: -IDLE --hide cmd /c "C:\Users\Otwvfvvt\AppData\Local\Temp\~5360940256629074852.cmd"
cmd /c "C:\Users\Otwvfvvt\AppData\Local\Temp\~5360940256629074852.cmd"
"C:\Users\Otwvfvvt\AppData\Local\Temp\~4703810647851280148\FastCopy.exe"
Show More
c:\users\user\downloads\3555bc63f9a2d6b5311ae27544e4ce39b3f1824b_0001609571 PECMD**pecmd-cmd* EXEC -wd:C: -IDLE --hide cmd /c "C:\Users\Otwvfvvt\AppData\Local\Temp\~1073411208753215274.cmd"
cmd /c "C:\Users\Otwvfvvt\AppData\Local\Temp\~1073411208753215274.cmd"
WriteConsole: The batch file c
C:\Users\Amcbortm\AppData\Local\Temp\~9163940350632943779~\sg.tmp 7zG_exe x "c:\users\user\downloads\8b6493351a33a2698de4c09fc803d7b3d0cd7b1c_0003137596" -y -aoa -o"C:\Users\Amcbortm\AppData\Local\Temp\~8025973702285585632"
"C:\Users\Amcbortm\AppData\Local\Temp\~8025973702285585632\论文检测报告.pdf"
c:\users\user\downloads\8b6493351a33a2698de4c09fc803d7b3d0cd7b1c_0003137596 PECMD**pecmd-cmd* EXEC -wd:C: -hide cmd /c "C:\Users\Amcbortm\AppData\Local\Temp\~6945455117672694251.cmd"
c:\users\user\downloads\8b6493351a33a2698de4c09fc803d7b3d0cd7b1c_0003137596 PECMD**pecmd-cmd* EXEC -wd:C: -hide cmd /c "C:\Users\Amcbortm\AppData\Local\Temp\~3394928636595389786.cmd"
C:\Users\Cfzvzxyh\AppData\Local\Temp\~3590539733339940820~\sg.tmp 7zG_exe x "c:\users\user\downloads\2ccf5211844b30689b7ad5a58c5838d0081177d3_0001884062" -y -aoa -o"C:\Users\Cfzvzxyh\AppData\Local\Temp\~4602741059389092454"
c:\users\user\downloads\2ccf5211844b30689b7ad5a58c5838d0081177d3_0001884062 PECMD**pecmd-cmd* EXEC -wd:C: -IDLE --hide cmd /c "C:\Users\Cfzvzxyh\AppData\Local\Temp\~4818952235533974256.cmd"
"C:\Users\Cfzvzxyh\AppData\Local\Temp\~4602741059389092454\Fab_x64.exe"
cmd /c "C:\Users\Cfzvzxyh\AppData\Local\Temp\~4818952235533974256.cmd"
c:\users\user\downloads\2ccf5211844b30689b7ad5a58c5838d0081177d3_0001884062 PECMD**pecmd-cmd* EXEC -wd:C: -IDLE --hide cmd /c "C:\Users\Cfzvzxyh\AppData\Local\Temp\~7230215032063226779.cmd"
C:\Users\Tmyyjiqu\AppData\Local\Temp\~3643889440840526254~\sg.tmp 7zG_exe x "c:\users\user\downloads\c671eafa85610ced37f59bd478aba97b35dddd7e_0001563432" -y -aos -o"C:\Users\Tmyyjiqu\AppData\Local\Temp\~7385075970585589380"

Trending

Most Viewed

Loading...