Once the script is launched, the Trojan creates two hidden frames:
- a web page located at the address shown below will be opened in the first frame: http://82.179.170.11/dia489/
- A WMF file located at the address shown below will be opened in the second
frame:
http://latech.co.kr/n.wmf
- Delete the Trojan HTML page (the location will depend on how the program originally penetrated the victim machine).
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
This Trojan opens web links without the knowledge or consent of the user. It is an HTML file. The file is 483 bytes in size.
Payload

Subscribe
Hot Articles