The virus puts three files in the system directory
- <System>\kavo.exe
- <System>\kavo0.dll
- <System>\kavo1.dll
Puts also at least one file .dll in the temporary folder, others are created randomly
- g4.dll
- avxah8.dll
- y.dll
- ig4au94g.dll
- iilov9vn.dll
- ad.dll
- 7z.dll
- or.dll
- kykvfp.dll
- 88b4ibhq.dll
- ee2m.dll
- ecoimwht.dll
- o8n4e8g9.dll
- 48d.dll
- ufe7kt.dll
- xx.dll
And put two files in the root partition of your system:
- Autorun.inf
- o.exe
- nxvhpc.exe
- ff1q0gw.bat
- i8.com
- e6ieg.exe
- 6qe.com
- cfv90h.com
- ab.cmd
- k2.cmd
- h2.com
- u.exe
- fufb6tq3.cmd
- ekf6dbg0.com
- h2.com
- rtnlpipu.com
- 1i.com
- c18vk.exe
- ntphyy.com
The file autorun.inf is always present in the root of all partitions including removable drives, external drives or flash disks, another file accompanies it.
|