Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\conme.exe 7gh'
- '%WINDIR%\conme.exe'
- %TEMP%\iakfw.htm
- %WINDIR%\conme.exe
- <Full path to virus>
- '1.##2sm.com':80
- 'localhost':1039
- '21#.#0.132.196':1106
- http://1.##2sm.com/reques0.asp?ki##############################################
- DNS ASK 1.##2sm.com