Technical Information
- <Full path to virus> (downloaded from the Internet)
- %APPDATA%\Microsoft\serv.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\serv[1].exe
- %APPDATA%\Microsoft\serv.exe
- 'sp####x.fileave.com':80
- sp####x.fileave.com/serv.exe
- DNS ASK sp####x.fileave.com