Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}] 'Exec' = 'http://www.ietoolexpress.com/redirect.php'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] 'start' = '<Full path to virus>'
- <Current directory>\iebtmm.exe
- <Current directory>\iebtmm.exe
- <Current directory>\iebt.dll