Technical Information
- '<SYSTEM32>\taskkill.exe' /F /PID "1624"
- %TEMP%\remove.bat
- DNS ASK so##tel4.ru
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Remove.bat" "1624" "<Full path to file>""
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 3
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Remove.bat" "1624" "<Full path to file>""' (with hidden window)