Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MS Update' = '%PROGRAM_FILES%\Microsoft Update\MS Update.exe'
- '%PROGRAM_FILES%\Microsoft Update\MS Update.exe'
- <Full path to virus>
- %PROGRAM_FILES%\Microsoft Update\MS Update.exe
- %TEMP%\~DF2F34.tmp
- 'de######orld.blogspot.tw':80
- de######orld.blogspot.tw/2013/04/fuyols.html
- DNS ASK de######orld.blogspot.tw
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'