Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{57FEBADF-CB53-5CFD-B681-7874D424193C}' = '%HOMEPATH%\Start Menu\Programs\Startup\Windows Oturum Acma Uygulamas?.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{57FEBADF-CB53-5CFD-B681-7874D424193C}' = '%HOMEPATH%\Start Menu\Programs\Startup\Windows Oturum Acma Uygulamas?.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\explorer.exe
- <Full path to virus>
- 'sm##.gmail.com':465
- DNS ASK sm##.gmail.com
- ClassName: 'Indicator' WindowName: '(null)'