Technical Information
- %TEMP%\tmpldkzl\winlog.exe
- <Current directory>\deleteme.bat
- %TEMP%\textlog.dat
- %TEMP%\tmpldkzl\winlog_inix.tgs
- from %TEMP%\tmpldkzl\winlog.exe to %TEMP%\tmpldkzl\winlog_inix.tgs
- '%TEMP%\tmpldkzl\winlog.exe' winlog tmpLDKZL
- '%TEMP%\tmpldkzl\winlog.exe' winlog tmpLDKZL' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\deleteme.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\deleteme.bat