Technical Information
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Test[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Jkcing[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Test[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Jkcing[1].html
- from <Full path to virus> to %TEMP%\115578.dat
- 'as####5917.3322.org':3861
- 'www.zd##s.com':80
- '20#.#6.232.182':80
- www.zd##s.com/Fuckhns/RedGirl/IP/Test.html
- www.zd##s.com/Fuckhns/RedGirl/IP/Jkcing.html
- DNS ASK as####5917.3322.org
- DNS ASK www.zd##s.com
- DNS ASK www.microsoft.com
- ClassName: 'Shell_TrayWnd' WindowName: ''