Filesize: 244,675 bytes
MD5: EABB037DF4126080B26D2ABFEA51CE9B
SHA-1: F6C1A824B27FCB81976088308900426265DADED4
============================================================
C:\Windows\System32\extramain.exe
C:\Windows\System32\Iexplorer.exe
C:\Windows\%UserName%.exe
MD5: EABB037DF4126080B26D2ABFEA51CE9B
SHA-1: F6C1A824B27FCB81976088308900426265DADED4
============================================================
Files created
C:\autorun.inf
C:\Temp.pif
C:\Documents and Settings\[UserName]\Application Data\control.exe
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\Mp3.exe
C:\Windows\Loikaw.exe
C:\Windows\Jan.exeC:\autorun.inf
C:\Temp.pif
C:\Documents and Settings\[UserName]\Application Data\control.exe
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\Mp3.exe
C:\Windows\Loikaw.exe
C:\Windows\System32\extramain.exe
C:\Windows\System32\Iexplorer.exe
C:\Windows\%UserName%.exe
C:\Documents and Settings\[UserName]\Desktop\Virus Information.txt
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\autorun.inf
Registry Modifications
Keys AddedHKLM\SOFTWARE\Classes\soesoe
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
Values Added:HKUM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
\DefaultIcon :(Default) = "%System%\winlogon.exe,0"
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
Default = "%System%\mshearts.exe,0"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load = "%Windir%\Loikaw.exe"
* = "%AppData%\control.exe"
Values Midified
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind = 0x00000001
NoFolderOptions = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
DisableTaskMgr = 0x00000001
DisableRegistryTools = 0x00000001
Value deleted:HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon:(Default) = "%SystemRoot%\Explorer.exe,0"
(C:\WINDOWS\System32\shell32.dll,15)
