Technical Information
- %WINDIR%\sisten.exe
- <Full path to virus>
- '11#.#.#62.88.hotmail.ru':80
- 11#.#.#62.88.hotmail.ru/puxa.txt
- DNS ASK 11#.#.#62.88.hotmail.ru
- '<Private IP address>':1037
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''