Technical Information
- <Current directory>\h4714log.txt
- from <Full path to virus> to <Current directory>\bola7.txt
- 'ne##########-com-br.web102.redehost.com.br':80
- ne##########-com-br.web102.redehost.com.br/che/worm.php
- DNS ASK ne##########-com-br.web102.redehost.com.br
- '<Private IP address>':1037
- ClassName: 'MS_WINHELP' WindowName: ''