Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'sawtvi' = '"%APPDATA%\sawtvi\SawTv_s.exe"'
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- C:\DelUS.bat
- %TEMP%\nsj2.tmp\SelfDelete.dll
- %APPDATA%\sawtvi\SawTv_s.exe
- %TEMP%\nsj2.tmp\SelfDelete.dll