Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\asr_imon] 'Start' = '00000001'
- <SYSTEM32>\attrib.exe -r -s -h"<Full path to virus>"
- <SYSTEM32>\cmd.exe /c ""<Current directory>\131640.bat" "<Full path to virus>""
- <SYSTEM32>\spoolsv.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\cgi[1].pl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\cgi[1].pl
- <Current directory>\131640.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\cgi[2].pl
- <SYSTEM32>\spool\prtprocs\w32x86\drwtmem.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\cgi[1].pl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\cgi[1].pl
- <DRIVERS>\finddsvr.sys
- <SYSTEM32>\spool\prtprocs\w32x86\drwtmem.dll
- '20#.#2.243.162':80
- 'localhost':1037
- 20#.#2.243.162/cgi-bin/cgi.pl?id#######################################################