Hi mauserme.
Did the scanning with a-squared. Ran a complete online scan with the latest Bitdefender. Nothing there.
Performed chkdsk and everything seemed normal. Because this Trident TPE var 1.4 is “an oldie” from 1993, I also checked mem in DOS: conventional 65536 bytes total & 65536 bytes available for DOS. As I disconnect could it be the dropper did not materialize, because no traces of history.doc and tpe.obj could be found either (part of Trident TPE var 1.4), because the encrypted object file is connected to an executionable file and that is the dropper. That is basically how it works. Most varieties of TPE are rather harmless, only one is dangerous. Can you comment? PS the chkdsk cluster info said 4096 bytes. Is that standard? Funny that these old polymorphic viruses seem to make a comeback somehow. Or was this a FP?
polonus