Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /im "<File name>.exe" /f
- %TEMP%\clw8ohzt\cleaner.exe
- %HOMEPATH%\desktop\cleaner.lnk
- '20#.#7.104.97':80
- '85.##.46.167':80
- http://20#.#7.104.97/powfhxhxcjzx/ping.php?su######################################
- http://85.##.46.167/software.php
- '%TEMP%\clw8ohzt\cleaner.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\CLw8OhZt\Cleaner.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\CLw8OhZt\Cleaner.exe"
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit