Technical Information
Modifies file system :
Creates the following files:
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\havinfo[1].htm
Deletes the following files:
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\havinfo[1].htm
Moves itself:
- from <Full path to virus> to %TEMP%\~csgt.tmp
Network activity:
Connects to:
- 'li##.#oneyhome.biz':80
TCP:
HTTP POST requests:
- li##.#oneyhome.biz/hello/havinfo.php?v=#####
UDP:
- DNS ASK li##.#oneyhome.biz