Technical Information
- firefox.exe process, urlmon.dll module
- firefox.exe process, cryptsp.dll module
- firefox.exe process, netutils.dll module
- firefox.exe process, wininet.dll module
- firefox.exe process, mswsock.dll module
- <SYSTEM32>\wlrmdr.exe
- %TEMP%\ixp000.tmp\0verl0ad.bat
- %TEMP%\ixp000.tmp\dds.vbs
- %TEMP%\ixp000.tmp\light.vbs
- %TEMP%\ixp000.tmp\spambox.vbs
- %TEMP%\ixp000.tmp\spambox2.vbs
- %TEMP%\ixp000.tmp\spambox3.vbs
- %TEMP%\ixp000.tmp\spambox4.vbs
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\light.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\spambox.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\spambox2.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\spambox3.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\spambox4.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\dds.vbs"
- '<SYSTEM32>\cmd.exe' /c 0VerL0AD.bat
- '<SYSTEM32>\shutdown.exe' -s -t 18 -c "Your computer has been fucked by the 0VerL0AD Virus!"
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\cmd.exe' /c 0VerL0AD.bat' (with hidden window)