A malicious trojan horse that represent security risk for the compromised system and its network environment.
Remote Host: pool.hybridtx.com
Port: 1750
File
The virus puts files in your system directory:
<System>\msgnms.exe
<Temp>\wjsfldwg.exe
<Temp>\cymqdwmk.exe
<System>\ssttr.dl
<System>\lmllji.dll
<System>\ssttr.dll
<System>\vtstq.dll
<System>\nexdxndep.exe
<System>\vtutq.dll
<System>\vtsts.dll
<System>\jkkji.dll
<System>\tuvtqpq.dll
<System>\moywh.dll
Registry
The registry entry bellow are created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Live
msgnms.exe