![]() Which is directly followed by "cmp edx, 05h" and "jne 0040648Bh". "c51afca27e713afb95e50193ee0a23ffd39e8d47fe7fbbe7f9586f221d3a0d81.tmp" opened "%APPDATA%\Microsoft\Windows\SendTo\Open with PeaZip.lnk" with delete access "c51afca27e713afb95e50193ee0a23ffd39e8d47fe7fbbe7f9586f221d3a0d81.tmp" opened "%APPDATA%\Microsoft\Windows\SendTo\Extract here (in new folder).lnk" with delete access "c51afca27e713afb95e50193ee0a23ffd39e8d47fe7fbbe7f9586f221d3a0d81.tmp" opened "%APPDATA%\Microsoft\Windows\SendTo\Add to sfx and send by mail.lnk" with delete access "c51afca27e713afb95e50193ee0a23ffd39e8d47fe7fbbe7f9586f221d3a0d81.tmp" opened "%APPDATA%\Microsoft\Windows\SendTo\Add to self-extracting archive.lnk" with delete access ZIP and send by mail.lnk" with delete access 7Z and send by mail.lnk" with delete access "" opened "%APPDATA%\Microsoft\Windows\SendTo\Add to archive.lnk" with delete access ![]() ![]() "c51afca27e713afb95e50193ee0a23ffd39e8d47fe7fbbe7f9586f221d3a0d81.tmp" wrote 4 bytes to a remote process "C:\Program Files\PeaZip\peazip.exe" (Handle: 828)Ĭontains ability to reboot/shutdown the operating system
0 Comments
Leave a Reply. |