Technical Information
- [HKLM\Software\Classes\KXGowh EXpnx\Shell\Open\Command] '' = '"C:\Users\Public\Downloads\WoAkDIhx.exe"ulmjHiIg TemmgBSa AUspNHFc'
- User Account Control (UAC)
- C:\users\public\downloads\woakdihx.exe
- C:\users\public\downloads\kxgowh expnx.qgyd
- %TEMP%\_@3783.tmp
- from C:\users\public\downloads\woakdihx.exe to %TEMP%\_@3783.tmp
- '11#.#9.134.193':6666
- '11#.#9.134.193':6666
- 'C:\users\public\downloads\woakdihx.exe'
- '%WINDIR%\syswow64\cmd.exe' cmd/c ping -n 2 127.0.0.1 > nul && del %TEMP%\_@3783.tmp > nul
- '%WINDIR%\syswow64\ping.exe' -n 2 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' cmd/c ping -n 2 127.0.0.1 > nul && del %TEMP%\_@3783.tmp > nul' (with hidden window)