Technical Information
- <SYSTEM32>\remover.exe <Full path to virus>
- %PROGRAM_FILES%\SinFile\SinFileDown.exe <Virus name>.exe first
- <SYSTEM32>\remover.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\app[1].htm
- %PROGRAM_FILES%\SinFile\SinFileDown.exe
- %PROGRAM_FILES%\SinFile\Uninstall.exe
- 'si##ile.kr':80
- 'localhost':1036
- si##ile.kr/app/bundle/bundle.ini
- si##ile.kr/log/install.php?pd#####
- si##ile.kr/app.htm
- DNS ASK si##ile.kr
- '<Private IP address>':1037
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''