Technical Information
- '<SYSTEM32>\ntvdm.exe' -f -i1
- %ALLUSERSPROFILE%\adobex.exe
- %WINDIR%\temp\scs1.tmp
- %WINDIR%\temp\scs2.tmp
- %WINDIR%\temp\scs1.tmp
- %WINDIR%\temp\scs2.tmp
- http://gr####hos-tn.com/admin/user/me.exe
- http://gr####hos-tn.com/cgi-sys/suspendedpage.cgi
- DNS ASK gr####hos-tn.com
- ClassName: 'MsoHelp11' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-f00.f04.360001'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding