Technical Information
- '<Current directory>\<Virus name>_.exe'
- '<Current directory>\<Virus name>_.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /c <Current directory>\$$336699.bat
- ClassName: 'OLLYDBG' WindowName: '(null)'
- <Current directory>\$$336699.bat
- <Current directory>\<Virus name>_.exe
- 'sp###soft.com':80
- sp###soft.com/store/SGUE_inst.exe
- sp###soft.com/store/updates/SGUE/upd.dat
- DNS ASK sp###soft.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'