Al ejecutarse crea los siguientes archivos:
c:\autorun.inf c:\b2.exe c:\Temp\vsi.dll c:\windows\System32\fool0.dll c:\windows\System32\fool1.dll c:\windows\System32\fool2.dll c:\windows\System32\ieso0.dll c:\windows\System32\kxvo.exe
Crea las siguientes claves en el registro:
HKLM\SOFTWARE\Classes\CLSID \{CE7C3CF0-4B15-11D1-ABED-709549C10000}\VersionIndependentProgID (Default) = "IEHlprObj.IEHlprObj"
HKLM\SOFTWARE\Classes\CLSID \{CE7C3CF0-4B15-11D1-ABED-709549C10000}\ProgID (Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}
\InprocServer32 (Default) = "%System%\ieso0.dll" ThreadingModel = "Apartment"
HKLM\SOFTWARE\Classes\CLSID \{CE7C3CF0-4B15-11D1-ABED-709549C10000} (Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer (Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj (Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID (Default) = "{CE7C3CF0-4B15-11D1-ABED-709549C10000}"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 (Default) = "IEHlprObj Class"
HKCU\Software\Microsoft\Windows \CurrentVersion\Run kxva = "c:\windows\System32\kxvo.exe"
HKLM\SOFTWARE\Microsoft\Windows \CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL CheckedValue = 0x00000000
Se conecta al siguente sitio para descargar un archivo llamado "ll.rar":
http: //www . hg7890 . com/hg2/
|