Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\Splhlp] 'Name' = '%ALLUSERSPROFILE%\Documents\zx.dll'
- <SYSTEM32>\winlogon.exe with <SYSTEM32>\temp.tmp
- %WINDIR%\explorer.exe with %WINDIR%\temp.tmp
- <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\zx.dll
- %WINDIR%\temp.tmp
- <SYSTEM32>\temp.tmp
- %ALLUSERSPROFILE%\Documents\dll
- %ALLUSERSPROFILE%\Documents\zx.dll
- <SYSTEM32>\dll
- %ALLUSERSPROFILE%\Documents\zx.dll
- %ALLUSERSPROFILE%\Documents\dll
- from <SYSTEM32>\winlogon.exe to %WINDIR%\Temp\winlogon.dat
- from %WINDIR%\explorer.exe to %WINDIR%\Temp\explorer.dat
- from <Full path to virus> to %ALLUSERSPROFILE%\Documents\19792079