files size : 105,098 bytes
MD5: 16B3D5192BFD9077EF60B17D0CB12589
SHA-1: A64D3E01C4EFE17535383C0621BD6CC65A6BCF71
============================================================
Files created
C:\WINDOWS\system32\ierdfgh.exe
C:\WINDOWS\system32\pytdfse1.dll
C:\Documents and Settings\[UserName]\Local Settings\Temp\xvassdf.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\4tddfwq0.dll(0-9)
C:\u3uvew6.bat
C:\autorun.inf
File deletedC:\WINDOWS\system32\drivers\cdaudio.sys
Keys Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Values Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo : "qaswee.e"
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Enum
Count : 0x00000000
NextInstance : 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\ControlSet001\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath : "%System%\drivers\cdaudio.sys"
DisplayName = "AVPsys"
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Count : 0x00000000
NextInstance = 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath :"%System%\drivers\cdaudio.sys"
DisplayName : "AVPsys"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kxswsoft : "%System%\ierdfgh.exe"
54dfsger : "%Temp%\xvassdf.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
MD5: 16B3D5192BFD9077EF60B17D0CB12589
SHA-1: A64D3E01C4EFE17535383C0621BD6CC65A6BCF71
============================================================
Files created
C:\WINDOWS\system32\ierdfgh.exe
C:\WINDOWS\system32\pytdfse1.dll
C:\Documents and Settings\[UserName]\Local Settings\Temp\xvassdf.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\4tddfwq0.dll(0-9)
C:\u3uvew6.bat
C:\autorun.inf
File deletedC:\WINDOWS\system32\drivers\cdaudio.sys
Keys Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Values Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo : "qaswee.e"
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Enum
Count : 0x00000000
NextInstance : 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\ControlSet001\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath : "%System%\drivers\cdaudio.sys"
DisplayName = "AVPsys"
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Count : 0x00000000
NextInstance = 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath :"%System%\drivers\cdaudio.sys"
DisplayName : "AVPsys"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kxswsoft : "%System%\ierdfgh.exe"
54dfsger : "%Temp%\xvassdf.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
