Technical Information
- [<HKLM>\SOFTWARE\Classes\JSEFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\JSFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\htafile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\VBSFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\WSFFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\WSHFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- [<HKLM>\SOFTWARE\Classes\VBEFile\Shell\Open\Command] '' = '"%WINDIR%\notepad.exe" "%1"'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.bat" <Full path to virus>"
- <SYSTEM32>\cmd.exe
- %TEMP%\1.tmp\2.bat
- %TEMP%\1.tmp\2.bat