Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SmartIndex' = '<Full path to virus>'
- <DRIVERS>\npf.sys
- <SYSTEM32>\wpcap.dll
- <SYSTEM32>\Packet.dll
- 'localhost':1046
- '11#.#3.194.36':80
- '59.#7.10.5':80
- '62.##2.164.134':80
- 'localhost':1049
- '12#.#8.119.38':80
- 'localhost':1037
- 'localhost':1040
- 'localhost':1043
- '77.#39.3.11':80