file size : 122,840 bytes
MD5: C9B1FACBAE61C0420D453CAF439BB68B
SHA-1: 00D13DF8CDD6CD09E447628FB6C1E8171717AF53
============================================================
files created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
X:\g9rv.exe
X:\3p9wj19.exe
X:\autorun.inf
Registry Modifications
Key added
HKLM\SOFTWARE\Classes\CLSID\MADOWNValue Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\
urlinfo = "da5dsa2r.k"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
MD5: C9B1FACBAE61C0420D453CAF439BB68B
SHA-1: 00D13DF8CDD6CD09E447628FB6C1E8171717AF53
============================================================
files created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
X:\g9rv.exe
X:\3p9wj19.exe
X:\autorun.inf
Registry Modifications
Key added
HKLM\SOFTWARE\Classes\CLSID\MADOWNValue Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\
urlinfo = "da5dsa2r.k"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
