Technical Information
- %ALLUSERSPROFILE%\yxinqjfskmtrpv.exe
- %ALLUSERSPROFILE%\yxinqjfskmtrpv.exe
- 'localhost':443
- '%ALLUSERSPROFILE%\yxinqjfskmtrpv.exe'
- '%WINDIR%\syswow64\cmd.exe' /c (timeout /t 10) & (del /F /Q "<Full path to file>") & (start "" "%ALLUSERSPROFILE%\YxinqJFsKmTrPv.exe")
- '%WINDIR%\syswow64\timeout.exe' /t 10
- '%WINDIR%\syswow64\cmd.exe' /c (timeout /t 10) & (del /F /Q "<Full path to file>") & (start "" "%ALLUSERSPROFILE%\YxinqJFsKmTrPv.exe")' (with hidden window)