Technical Information
- '<SYSTEM32>\wscript.exe' "%APPDATA%\givemekissfromthefisherman.vbs"
- '<SYSTEM32>\verclsid.exe' /C {BDEADF00-C265-11D0-BCED-00A0C90AB50F} /I {000214E6-0000-0000-C000-000000000046} /X 0x401
- C:\Documents\user\locals~1\temp\~df5a.tmp
- %APPDATA%\givemekissfromthefisherman.vbs
- unc\szwejp*\mailslot\net\netlogon
- %HOMEPATH%\nethood\my web sites on msn\desktop.ini
- %HOMEPATH%\nethood\my web sites on msn\target.lnk
- 'po#.tg':80
- '10#.#68.45.23':80
- 'pa##e.ee':443
- http://po#.tg/VC0KF
- http://10#.#68.45.23/9090/jhn/iwanttokiswithlotoflovesheismygirlitrulylovedherfromtheheartmysweetbabymyheartiwantsheiswithme___girlbeautifysxyandmorethanthat.doc
- http://10#.#68.45.23/9090/imageveryclearfisherman.gif
- 'pa##e.ee':443
- DNS ASK po#.tg
- DNS ASK pa##e.ee
- ClassName: 'Ghost' WindowName: ''
- '%ProgramFiles%\microsoft office\office12\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding