Technical Information
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %TEMP%\6a75.tmp\6a86.tmp\6a87.bat
- %TEMP%\6a75.tmp\6a86.tmp\6a87.bat
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\6A75.tmp\6A86.tmp\6A87.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\6A75.tmp\6A86.tmp\6A87.bat <Full path to file>"