File size : 321,024 bytes
MD5: 64D35A19ABB5796C2643F4B3A28AA89A
SHA-1: E13A51D550D5BF273D7907D0DA8F713E9ED576C8
============================================================
Files created
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll (0-9)
X:\k2d8j3wa.bat
X:\autorun.inf
Value AddedHKCU\Software\Microsoft\Windows\CurrentVersion\Run
kava : "%System%\kavo.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
MD5: 64D35A19ABB5796C2643F4B3A28AA89A
SHA-1: E13A51D550D5BF273D7907D0DA8F713E9ED576C8
============================================================
Files created
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll (0-9)
X:\k2d8j3wa.bat
X:\autorun.inf
Value AddedHKCU\Software\Microsoft\Windows\CurrentVersion\Run
kava : "%System%\kavo.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
