Technical Information
- <SYSTEM32>\userinit.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\KB980
- %ALLUSERSPROFILE%\Application Data\svchost.txt
- %ALLUSERSPROFILE%\Application Data\SVCH0ST.dll
- %TEMP%\temp.txt
- %TEMP%\Metxt
- %ALLUSERSPROFILE%\Application Data\KB7927447.exe
- <Full path to virus>
- %TEMP%\Metxt
- %TEMP%\KB980
- from %ALLUSERSPROFILE%\Application Data\svchost.txt to %ALLUSERSPROFILE%\Application Data\KB7927447.exe
- '22#.#2.9.248':9000