Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lqwsmfswjrk' = 'regsvr32 /s "%APPDATA%\lqwsmfswjrk.jpg"'
- '%WINDIR%\syswow64\taskkill.exe' -f -im iexplore.exe
- iexplore.exe
- iexplore.exe
- ClassName: '' WindowName: 'l3dll'
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'nidll'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe'
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v lqwsmfswjrk /d "regsvr32 /s """%APPDATA%\lqwsmfswjrk.jpg"""" /f
- '%WINDIR%\syswow64\taskkill.exe' -f -im iexplore.exe' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v lqwsmfswjrk /d "regsvr32 /s """%APPDATA%\lqwsmfswjrk.jpg"""" /f' (with hidden window)