Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'chrome_update' = '%WINDIR%\Temp\chrome_frame_helper.exe'
- '%WINDIR%\Temp\chrome_frame_helper.exe'
- %WINDIR%\Temp\chrome_frame_info.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\microsoft[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\microsoft[1]
- %WINDIR%\Temp\usertemp.ini
- %WINDIR%\Temp\chrome_frame_helper.dll
- %WINDIR%\Temp\chrome_frame_helper.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\microsoft[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\microsoft[1]
- from <Full path to virus> to %WINDIR%\Temp\iexpl001.tmp
- '20#.#6.232.182':80
- 20#.#6.232.182/
- DNS ASK www.microsoft.com
- ClassName: 'Indicator' WindowName: '(null)'