Technical Information
- <Drive name for removable media>:\JlAvZ.exe
- %TEMP%\.exe
- %TEMP%\.exe (downloaded from the Internet)
- C:\<Virus name>.exe
- %HOMEPATH%\Start Menu\Programsexplorer.exe
- %TEMP%\.exe
- <Drive name for removable media>:\JlAvZ.exe
- 'st####h-files.co.cc':80
- 'wp#d':80
- st####h-files.co.cc/savefiles/epme.exe
- wp#d/wpad.dat
- DNS ASK st####h-files.co.cc
- DNS ASK wp#d