Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup1' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP001.TMP\"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\IXP001.TMP\ivy.exe'
- '<SYSTEM32>\msnworm.exe'
- '%TEMP%\IXP000.TMP\update.EXE'
- '%TEMP%\1077692.scr' /S
- '%TEMP%\2017590.EXE'
- '<SYSTEM32>\msnworm.exe' (downloaded from the Internet)
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- ClassName: 'RegmonClass' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: '(null)' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- ClassName: 'FilemonClass' WindowName: '(null)'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\setup[1].zip
- <SYSTEM32>\iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\setup[1].exe
- <SYSTEM32>\msnworm.exe
- %TEMP%\IXP001.TMP\ivy.exe
- %TEMP%\2017590.EXE
- %TEMP%\1077692.scr
- %TEMP%\IXP000.TMP\FOTO_C~1.SCR
- %TEMP%\IXP000.TMP\update.EXE
- %TEMP%\IXP000.TMP\update.EXE
- %TEMP%\IXP000.TMP\FOTO_C~1.SCR
- %TEMP%\IXP001.TMP\ivy.exe
- 'www.my#####og.memebot.com':80
- 'my#####og.zoomshare.com':80
- 'localhost':1036
- www.my#####og.memebot.com/setup.exe
- my#####og.zoomshare.com/files/setup.zip
- DNS ASK jr###.dyndns.org
- DNS ASK h1.##pway.com
- DNS ASK my#####og.zoomshare.com
- DNS ASK www.my#####og.memebot.com
- ClassName: 'Progman' WindowName: '(null)'
- ClassName: '18467-41' WindowName: '(null)'