Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /f /im "<File name>.exe"
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- <Current directory>\hpsocket4c.dll
- <Current directory>\exuikrnln_win32.lib
- '11#.#59.190.209':9001
- 'ns#.#nspod.net':6666
- '14#.#10.17.173':55655
- http://ns#.#nspod.net/
- '11#.#59.190.209':9001
- DNS ASK ns#.#nspod.net
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im "<File name>.exe" &start "" "<File name>.exe" &exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im "<File name>.exe" &start "" "<File name>.exe" &exit