Technical Information
- '%ALLUSERSPROFILE%\sapesvx\sapesvx.scr'
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\sapesvx\sapesvx.scr
- %ALLUSERSPROFILE%\sapesvx\sapesvx.scr
- %HOMEPATH%\documents\vb8bae.tmp
- %APPDATA%\cubix\modempx.exe
- %TEMP%\vb8bad.tmp
- from %HOMEPATH%\documents\vb8bae.tmp to %TEMP%\vb8bad.tmp
- '17#.#49.14.104':6630
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\sapesvx\sapesvx.scr' (with hidden window)