Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'win100808' = 'C:\WinApp\google\Update0808\secmd.exe'
- C:\WinApp\google\Update0808\secmd.exe Йѕ<Full path to virus>
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen C:\WinApp\google\Update0808\secmd.jpg
- %HOMEPATH%\Recent\Update0808.lnk
- %HOMEPATH%\Recent\secmd.lnk
- C:\WinApp\google\Update0808\secmd.ldb
- C:\WinApp\google\Update0808\secmd.exenet
- C:\WinApp\google\Update0808\secmd.chm
- %WINDIR%\win32.btlq
- C:\WinApp\google\Update0808\secmd.jpg
- C:\WinApp\google\Update0808\secmd.exe
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'ComboBoxEx32' WindowName: ''
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''