CRC32: DDDE5823
MD5: 1D20848028BB13833F3CE669E9E152D9
SHA-1: DC84C6CA9D9F71A9EEE3A78AB0C1E18B0444D2A0
===================================================
MD5: 1D20848028BB13833F3CE669E9E152D9
SHA-1: DC84C6CA9D9F71A9EEE3A78AB0C1E18B0444D2A0
===================================================
Create file
C:\DOCUME~1\[user]\LOCALS~1\temp\olhrwef.exe
C:\DOCUME~1\[user]\LOCALS~1\temp\nmdfgds0.dll (0-9)
X:\aphqg.exe
X:\autorun.inf
Delete file
C:\WINDOWS\system32\drivers\cdaudio.sys
Download file
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\am1.rar > am1.exe
Keys added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security
HKLM\SYSTEM\ControlSet001Services\AVPsys\Enum
HKLM\SYSTEM\CurrentControlSet\Services\AVPsysH
KLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\EnumValues addedHKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum\Count: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum\NextInstance: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum\INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Type: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Start: 0x00000003
HKLM\SYSTEM\ControlSet001\Services\AVPsys\ErrorControl: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\AVPsys\
ImagePath: "\??\C:\WINDOWS\system32\drivers\cdaudio.sys"
HKLM\SYSTEM\ControlSet001\Services\AVPsys\DisplayName: "AVPsys"
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum\Count: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum\NextInstance: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum\INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Type: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Start: 0x00000003
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\ErrorControl: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\ImagePath: "\??\C:\WINDOWS\system32\drivers\cdaudio.sys"
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\DisplayName: "AVPsys"
HKCU\ Software\Microsoft\Windows\CurrentVersion\Run\
cdoosoft: "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\olhrwef.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\ \Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\ \Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000