Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IMJPMIG' = '"<Full path to virus>"'
- %HOMEPATH%\User
- %HOMEPATH%\UserProfile.dll
- %HOMEPATH%\User.ini
- %HOMEPATH%\User16.dll
- %HOMEPATH%\User
- %HOMEPATH%\User16.dll
- %HOMEPATH%\User.ini
- 'go####mm.vicp.net':80
- DNS ASK go####mm.vicp.net