Technical Information
- %WINDIR%\Tasks\Oxy.job
- '%TEMP%\<Virus name>.exe'
- [<HKCU>\Software\Microsoft\MessengerService]
- %APPDATA%\Oxy\config.xml
- %APPDATA%\Oxy\Updater.exe
- %TEMP%\htmlayout.dll
- %TEMP%\<Virus name>.exe
- %TEMP%\<Virus name>_002892.log
- 'www.ma###soth.com':80
- http://www.ma###soth.com/api/firstscreenshown/84461843006448f9ab2e66f9d4bb6165/1366000001
- http://www.ma###soth.com/api/keywordexecute/84461843006448f9ab2e66f9d4bb6165/1366000001/<Auxiliary name>
- http://www.ma###soth.com/api/cc
- DNS ASK www.ma###soth.com
- ClassName: 'Shell_TrayWnd' WindowName: ''