Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /im "<File name>.exe" /f
- '%WINDIR%\syswow64\taskkill.exe' /im "ZkjEO4Zben=.exe" /f
- <Current directory>\zkjeo4zben=.exe
- <Current directory>\zkjeo4zben=.exe
- http://wi###clean.hk/bus
- DNS ASK wi###clean.hk
- ClassName: '' WindowName: ''
- '<Current directory>\zkjeo4zben=.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "<Current directory>\ZkjEO4Zben=.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "ZkjEO4Zben=.exe" /f & erase "<Current directory>\ZkjEO4Zben=.exe" & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "<Current directory>\ZkjEO4Zben=.exe"
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "ZkjEO4Zben=.exe" /f & erase "<Current directory>\ZkjEO4Zben=.exe" & exit