Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{C51C4AFB-2A5F-6C8E-BB41-C10F02430461}' = ''
- %TEMP%\cqhe<Virus name>.dll
- %TEMP%\cqhe<Virus name>.dll
- ClassName: 'Button' WindowName: '????'
- ClassName: '' WindowName: '????????'