Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XiOSS' = '<Full path to virus>'
- '<SYSTEM32>\spoolsx.exe'
- '<SYSTEM32>\xmyy33\xmyy.exe'
- '<SYSTEM32>\spoolsx.exe' (downloaded from the Internet)
- '<SYSTEM32>\ping.exe' 127.1 -n 3
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\spoolsx[1].jpg
- <SYSTEM32>\spoolsx.exe
- C:\cd.bat
- <SYSTEM32>\xmyy33\xmyy.exe
- <SYSTEM32>\xmyy33\AntiVC.dll
- <SYSTEM32>\xmyy33\gzip.dll
- <SYSTEM32>\xmyy33\xmyy.cds
- '19#.#88.104.85':80
- 'localhost':1038
- '12#.#48.245.10':88
- 19#.#88.104.85/soft/spoolsx.jpg