Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Roxio Shared' = '<Full path to virus>'
- %PROGRAM_FILES%\Arquivos comuns\Roxio Shared\9.0\DLLShared\loga.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].html
- %WINDIR%\Media\NewIcon.ico
- from <Full path to virus> to <Current directory>\000003C8086FF7C8
- 'jo#######milo.sites.uol.com.br':80
- 'localhost':1036
- jo#######milo.sites.uol.com.br/index.html
- DNS ASK jo#######milo.sites.uol.com.br