Technical Information
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\svchost.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:<Virus name>.e...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<Full path to virus>" "<Virus name>.exe" ENABLE
- C:\autorun.inf
- C:\svchost.exe
- <Drive name for removable media>:\svchost.exe
- <Drive name for removable media>:\autorun.inf
- C:\svchost.exe
- C:\autorun.inf
- 'ph####1.ddns.net':1177
- DNS ASK ph####1.ddns.net