Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ipxhlxlc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ipxhlxlc] 'ImagePath' = '<SYSTEM32>\ipxhlxlc\xaiigeir.exe /d"<Full path to file>"'
- [<HKLM>\SYSTEM\CurrentControlSet\services\ipxhlxlc] 'ImagePath' = '<SYSTEM32>\ipxhlxlc\xaiigeir.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\xaiigeir.exe
- C:\documents and settings\localservice:.repos
- from %TEMP%\xaiigeir.exe to <SYSTEM32>\ipxhlxlc\xaiigeir.exe
- http://www.google.com/
- http://bi#####eritagephoto.com/wp-login.php?ac#############
- http://bi######tionsresults.com/wp-login.php?re###################
- http://bi######tionsresults.com/wp-login.php?ac#############
- DNS ASK 19#.###.211.95.in-addr.arpa
- DNS ASK pr#######.#n.eu02.emsp.trendmicro.eu
- DNS ASK op####bobigny.fr
- DNS ASK ho#########.olc.protection.outlook.com
- DNS ASK ho##ail.com
- DNS ASK in###rist.net
- DNS ASK ya##o.co.nz
- DNS ASK st####idemls.com
- DNS ASK op###mkt.com
- DNS ASK ms#####p-mx1.hinet.net
- DNS ASK it##am.com
- DNS ASK ms##.hinet.net
- DNS ASK bk.ru
- DNS ASK in.###.trendmicro.com
- DNS ASK op####artners.com
- DNS ASK mx.#len.pl
- DNS ASK o2.pl
- DNS ASK ky######.##il.protection.outlook.com
- DNS ASK ky##.com
- DNS ASK ga######er.austintexas.gov
- DNS ASK au###ntexas.gov
- DNS ASK mx#.mail.ru
- DNS ASK it########.mail.protection.outlook.com
- DNS ASK wo####et.att.net
- DNS ASK co##ast.net
- DNS ASK mb##.#edianet.pv.it
- DNS ASK eu#.###.#rotection.outlook.com
- DNS ASK ho##ail.es
- DNS ASK sm####n.libero.it
- DNS ASK li##ro.it
- DNS ASK mt#.bnet.cn
- DNS ASK ci##z.net
- DNS ASK fm.##lconet.net
- DNS ASK tr###-telco.net
- DNS ASK ya##o.nl
- DNS ASK ff######x-vip2.prodigy.net
- DNS ASK go####cktours.com
- DNS ASK sn####.gobizmail.com
- DNS ASK bi######tionsresults.com
- DNS ASK re##ter.net
- DNS ASK fi####.###ster02.premiumantispam.nl
- DNS ASK ca##ni.nl
- DNS ASK mx#######701.gslb.pphosted.com
- DNS ASK cg#.com
- DNS ASK ms#####p-mx2.hinet.net
- DNS ASK mx#.#omcast.net
- DNS ASK mx#.#aver.com
- DNS ASK na##r.com
- DNS ASK mx###.##il.am0.yahoodns.net
- DNS ASK qq.com
- DNS ASK cl######.us.messagelabs.com
- DNS ASK sy###tec.com
- DNS ASK mx#.#anmail.net
- DNS ASK ha##ail.net
- DNS ASK de###.ubid.com
- DNS ASK bi#####eritagephoto.com
- DNS ASK google.com
- DNS ASK ri##ail.se
- DNS ASK mx#.##etel.net.uk
- DNS ASK mx.####o.locaweb.com.br
- DNS ASK gl##o.com
- DNS ASK te#####ionbuilder.com
- DNS ASK alt1.gmail-smtp-in.l.google.com
- DNS ASK mt##.##0.yahoodns.net
- DNS ASK mx#.#otmail.com
- DNS ASK mx#.##ailsrvr.com
- DNS ASK gmail-smtp-in.l.google.com
- DNS ASK eq####packaging.com
- DNS ASK on##el.net
- DNS ASK op##f.net
- DNS ASK mx#.qq.com
- DNS ASK ba####.beta-inter.net
- DNS ASK ya##o.de
- DNS ASK sl###baum.com
- DNS ASK alt2.gmail-smtp-in.l.google.com
- DNS ASK aspmx.l.google.com
- DNS ASK ob###ver.co.uk
- DNS ASK sm##.##cureserver.net
- DNS ASK st##s.org
- DNS ASK ma###.dbs.com
- DNS ASK db#.com
- DNS ASK d1######.#ss.barracudanetworks.com
- DNS ASK ba####ffe-meier.de
- DNS ASK gm##l.com
- DNS ASK em##r.com
- DNS ASK alt4.gmail-smtp-in.l.google.com
- DNS ASK wa###ncci.com
- DNS ASK mx####.##il.gm0.yahoodns.net
- DNS ASK ve##zon.net
- DNS ASK ALT2.ASPMX.L.GOOGLE.COM
- DNS ASK ho##.edu
- DNS ASK ec##gmt.com
- DNS ASK mx#.##ser.iphmx.com
- DNS ASK alt3.gmail-smtp-in.l.google.com
- DNS ASK al##el.net
- '<DNS_SERVER>':53
- '<SYSTEM32>\ipxhlxlc\xaiigeir.exe' /d"<Full path to file>"
- '<SYSTEM32>\cmd.exe' /C mkdir <SYSTEM32>\ipxhlxlc\' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C move /Y "%TEMP%\xaiigeir.exe" <SYSTEM32>\ipxhlxlc\' (with hidden window)
- '<SYSTEM32>\sc.exe' create ipxhlxlc binPath= "<SYSTEM32>\ipxhlxlc\xaiigeir.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"' (with hidden window)
- '<SYSTEM32>\sc.exe' description ipxhlxlc "wifi internet conection"' (with hidden window)
- '<SYSTEM32>\sc.exe' start ipxhlxlc' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C mkdir <SYSTEM32>\ipxhlxlc\
- '<SYSTEM32>\cmd.exe' /C move /Y "%TEMP%\xaiigeir.exe" <SYSTEM32>\ipxhlxlc\
- '<SYSTEM32>\sc.exe' create ipxhlxlc binPath= "<SYSTEM32>\ipxhlxlc\xaiigeir.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"
- '<SYSTEM32>\sc.exe' description ipxhlxlc "wifi internet conection"
- '<SYSTEM32>\sc.exe' start ipxhlxlc
- '<SYSTEM32>\svchost.exe'