Technical Information
- <Current directory>\einfoGuide_delete.exe
- <Current directory>\einfoGuide.exe
- from <Full path to virus> to <Full path to virus>temp
- '22#.#43.42.75':80
- '21#.#33.39.72':80
- 'na##r.com':80
- http://22#.#43.42.75/g_upload/einfoGuide.exe
- http://22#.#43.42.75/g_upload/einfoGuide_delete.exe
- http://na##r.com/
- http://21#.#33.39.72/~window/w_ctrl/pver.php
- DNS ASK na##r.com
- '22#.#43.42.75':6506
- '22#.#43.42.75':6505
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''