Technical Information
- '%TEMP%\tmp2RVH\service.exe' service tmp2RVH
- '<SYSTEM32>\cmd.exe' /c <Current directory>\deleteme.bat
- %TEMP%\TextLog.dat
- <Current directory>\deleteme.bat
- %TEMP%\tmp2RVH\service.exe
- %TEMP%\tmp2RVH\service_ICE.tgs
- from %TEMP%\tmp2RVH\service.exe to %TEMP%\tmp2RVH\service_ICE.tgs