Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<Full path to virus>,'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\index[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\index[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].htm
- 'www.ya##o.co.jp':80
- 'www.oz##om.jp':80
- 'www.fu######.seikohousing.co.jp':80
- http://www.ya##o.co.jp/
- http://www.oz##om.jp/blog/index.php
- http://www.fu######.seikohousing.co.jp/blog/index.php
- DNS ASK www.ya##o.co.jp
- DNS ASK www.oz##om.jp
- DNS ASK www.fu######.seikohousing.co.jp