Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\TE5B81W917] 'Start' = '00000002'
- <Full path to virus>.lnk.lnk
- <Full path to virus>.lnk
- <SYSTEM32>\ntvdm.exe -f -i1
- <Current directory>\DD95AT.PIF
- <Current directory>\IK1BS3.PIF
- %PROGRAM_FILES%\1GGJ1G1TNNVH\B975QV.exe
- %WINDIR%\Temp\scs6.tmp
- %WINDIR%\Temp\scs5.tmp
- <Current directory>\VQHTT0.log
- <Full path to virus>.lnk.lnk
- <Full path to virus>.lnk
- %TEMP%\nso2.tmp
- %TEMP%\nsg4.tmp
- %TEMP%\~nsu.tmp\Au_.exe
- %PROGRAM_FILES%\1GGJ1G1TNNVH\B975QV.exe
- %WINDIR%\Temp\scs6.tmp
- %WINDIR%\Temp\scs5.tmp
- '20#.#09.168.5':80
- 'fi#####tv.freetcp.com':80
- 20#.#09.168.5/robots.txt
- fi#####tv.freetcp.com/robots.txt
- DNS ASK fi#####tv.freeTCP.com
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-bdc.be0.390001'
- ClassName: 'Shell_TrayWnd' WindowName: ''