Technical Information
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\IEXPL0RE.LNK
- %TEMP%\mscmos.sys
- %ProgramFiles%\Internet Explorer\IE.EXE
- %TEMP%\2714e.dat
- from <Full path to file> to %HOMEPATH%\IEXPL0RE.EXE
- '20#.#6.11.22':80
- '21#.#8.65.237':8000
- http://20#.#6.11.22/default.asp?38###############################
- '<SYSTEM32>\svchost.exe' "<Full path to file>"