Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BackItUp.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DefCfg.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\InBuild.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LangSet.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NBJ.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NBR.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Alertman.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysRescue.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysInspector.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\startup.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBGuard.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Safari.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flock.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Regedit.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Integrator.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MonCfg.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCleaner.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScnCfg32.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScanBD.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\skinset.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VB6.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Classes\batfile\shell\open\command] '' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ConfirmUnit' = '<SYSTEM32>\Unit.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regrepair.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Classes\regfile\shell\open\command] '' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Classes\VBSFile\Shell\Open\Command] '' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskman.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavCopy.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavHDBak.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavLite.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStore.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsConfig.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsLogVw.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavSSave.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegGuide.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcfgex.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avscan.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\update.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sched.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\armor2net.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Classes\Msi.Package\shell\Open\command] '' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Sudani' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ImageDrive.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswupdsv.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinRAR.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\starter.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashserv.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaisv.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebsv.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CoverDes.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nero.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeroStartSmart.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVASTSS.scr] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCmd.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashEnhcd.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgfrw.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe] 'Debugger' = '<SYSTEM32>\FiRsTlOvE.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\LoVeFiRsT.exe
- hidden files
- file extensions
- '<SYSTEM32>\Unit.exe'
- '<SYSTEM32>\FiRsTlOvE.exe'
- '<SYSTEM32>\Unit.exe' (downloaded from the Internet)
- '<SYSTEM32>\taskkill.exe' /F /IM Regedit.exe
- '<SYSTEM32>\taskkill.exe' /F /IM cmd.exe
- '<SYSTEM32>\taskkill.exe' /F /IM Armor2net.exe
- '<SYSTEM32>\taskkill.exe' /F /IM MSConfig.exe
- '<SYSTEM32>\taskkill.exe' /F /IM WinRAR.exe
- '<SYSTEM32>\taskkill.exe' /F /IM USBGuard.exe
- '<SYSTEM32>\taskkill.exe' /F /IM taskmgr.exe
- <SYSTEM32>\cmd.exe
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Main] 'Window Title' = '[ My Lover Mesha ]'
- [<HKCU>\Software\Microsoft\Internet Explorer\Main] 'Window Title' = '[ My Lover Mesha ]'
- <SYSTEM32>\Unit.exe
- <SYSTEM32>\FiRsTlOvE.exe
- <Full path to virus>
- <SYSTEM32>\Unit.exe
- <SYSTEM32>\FiRsTlOvE.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\LoVeFiRsT.exe
- <SYSTEM32>\command.com
- %TEMP%\~DF5337.tmp
- %TEMP%\~DFD3C7.tmp
- 'www.vb##rab.com':80
- 'localhost':1036
- www.vb##rab.com/vb/uploaded/62740/01346017612.rar
- DNS ASK www.vb##rab.com
- ClassName: '' WindowName: ''