Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<Virus name>' = '"%HOMEPATH%\<Virus name>.exe" /s'
- '%HOMEPATH%\<Virus name>.exe' /s
- '<SYSTEM32>\PING.EXE' -n 2 127.0.0.1
- %TEMP%\msvcru32.bat
- %HOMEPATH%\<Virus name>.exe
- '18#.#4.39.210':443