The virus puts four files in the system directory
- <System>\fool0.dll
- <System>\fool1.dll
- <System>\ieso0.dll
- <System>\kxvo.exe
Puts also at least one file .dll in the temporary folder, others are created randomly
- 57heb9v5.dll
- 58b95y4o.dll
- 63j8zs.sys
- 757yropw.dll
- 7uw44.dll
- 8lm5ns.dll
- 9e7ktl.dll
- an.dll
- cd.dll
- dwyq.dll
- e.dll
- ee.dll
- kdk.dll
- lh4yhy4.dll
- nn.dll
- omq.dll
- p8rjys.dll
- q8xvk.dll
- t.dll
- vak94lt9.dll
- vd.dll
- wjlg44s8.dll
- wmyz.dll
- ybndb.dll
- z7.dll
And put two files in the root partition of your system:
- Autorun.inf
- 3g.com
- 6krxwx.cmd
- 800dost.com
- b.bat
- es.exe
- fg8m.exe
- g2lbn.cmd
- hbq.exe
- kso6.bat
- l2quk.exe
- lg.com
- lpufwi6.com
- lqxo8w.cmd
- nej30aw.exe
- ojbss9gv.com
- uulaqvl.cmd
- vuts0e.cmd
- vuts0e.cmd
- w00g.exe
The file autorun.inf is always present in the root of all partitions including removable drives, external drives or flash disks, another file accompanies it.
|