Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{9C0ADB68-353A-61DD-ED09-1D8003A61111}' = ''
- %WINDIR%\syswow64\kb1111p.dll
- <Current directory>\vvsg.bat
- <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\cmd.exe' /c vvsg.bat
- '%WINDIR%\syswow64\cmd.exe' /c vvsg.bat' (with hidden window)