File sizes 124,868 bytes
MD5: 0F570FF4EDEAED820E4DED5E458001D0
SHA-1: EE8EEB6364E13C30626DC036CA1DA63B4447C9F4
============================================================
File created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
C:\lyhwcea.exe
C:\autorun.inf
Registry Modifications
Value AddedHKCU\Software\Microsoft\Windows\CurrentVersion\Run\
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
MD5: 0F570FF4EDEAED820E4DED5E458001D0
SHA-1: EE8EEB6364E13C30626DC036CA1DA63B4447C9F4
============================================================
File created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
C:\lyhwcea.exe
C:\autorun.inf
Registry Modifications
Value AddedHKCU\Software\Microsoft\Windows\CurrentVersion\Run\
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
