Technical Information
- %TEMP%\pod.exe
- %TEMP%\lol2.exe
- %TEMP%\pod.exe (downloaded from the Internet)
- %TEMP%\lol2.exe (downloaded from the Internet)
- <SYSTEM32>\svchost.exe <Full path to virus>
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\pod[1].exe
- %TEMP%\pod.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lol2[1].exe
- %TEMP%\lol2.exe
- '94.##.244.56':80
- 94.##.244.56/pod.exe
- 94.##.244.56/lol2.exe