Technical Information
- <DRIVERS>\etc\hosts.ics
- <SYSTEM32>\COMCTL32.OCX
- <SYSTEM32>\COMDLG32.OCX
- <SYSTEM32>\MSINET.OCX
- %APPDATA%\u9ihY.dll
- <DRIVERS>\etc\hosts
- 'localhost':1037
- 'ci######ongans.blogspot.com':80
- 'localhost':1040
- 'ce##it.com':80
- http://ci######ongans.blogspot.com/
- http://www.ce##it.com/input/TuamNiakkAdretAopcvAdh.vmp.dll via ce##it.com
- DNS ASK ci######ongans.blogspot.com
- DNS ASK www.ce##it.com
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c icacls <DRIVERS>\etc\hosts /reset
- '<SYSTEM32>\cmd.exe' /c icacls <DRIVERS>\etc\hosts.ics /reset
- '<SYSTEM32>\cmd.exe' /c icacls %WINDIR%\Volume.dll /deny administrators:F
- '<SYSTEM32>\cmd.exe' /c icacls %WINDIR%\Volume.dll /deny Users:F
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome