Technical Information
- '%APPDATA%\.necraft\launcher.exe' delete <Full path to virus>
- '%APPDATA%\.necraft\launcher.exe' (downloaded from the Internet)
- %APPDATA%\.necraft\launcher.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\launcher[1].exe
- 'ne##aft.ru':80
- ne##aft.ru/launcher.exe
- ne##aft.ru//launcher/hash.php
- DNS ASK st####.necraft.ru
- DNS ASK ne##aft.ru
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'