Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /f /Im "<File name>.exe"
- %TEMP%\nutw.exe
- nul
- %TEMP%\ynsf.gys
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\nutw.exe' -PlWQJgzwwP75N4aWNs3S
- '%WINDIR%\syswow64\cmd.exe' /Q /r type "<Full path to file>" > NUTw.EXe && staRT NuTW.exE -PlWQJgzwwP75N4aWNs3S& iF ""== "" for%Q iN ("<Full path to file>" ...
- '%WINDIR%\syswow64\cmd.exe' /Q /r type "%TEMP%\NUTw.EXe" > NUTw.EXe && staRT NuTW.exE -PlWQJgzwwP75N4aWNs3S& iF "-PlWQJgzwwP75N4aWNs3S"== "" for%Q iN ("%TEMP%\NUTw...
- '%WINDIR%\syswow64\regsvr32.exe' /u YNSf.GYS -S