Technical Information
- '<SYSTEM32>\svchost.exe' "<Full path to virus>"
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\MSCMOS.SYS
- %TEMP%\1d973.dat
- from <Full path to virus> to %HOMEPATH%\IEXPL0RE.EXE
- '22#.#68.92.199':8080
- 'localhost':8080
- ClassName: 'Shell_TrayWnd' WindowName: ''