file size 33,800 bytes
MD5: 0x80FD86FF4C432D56DDB1B40F658FA235
SHA-1: 0xED5D5EC1D1BC3D4DA38B89266B4B1E2926AC55B6
============================================================
files created
C:\WINDOWS\system32\afxmgdvr.dll
C:\WINDOWS\system32\vyrkkwkp.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\
3.tmp
dsad11.exe
***********************jfh.exe
***********************.txt
Registry Modifications
Keys AddedHKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}
HKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}\InProcServer32
Values AddedHKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}\InProcServer32]
(Default) : "%System%\afxmgdvr.dll"
ThreadingModel : "Apartment"
(Default) : "%System%\vyrkkwkp.dll"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
ShellExecuteHooks\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633} = ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
vyrkkwkp.dll : "{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}"
afxmgdvr.dll : "{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}"
MD5: 0x80FD86FF4C432D56DDB1B40F658FA235
SHA-1: 0xED5D5EC1D1BC3D4DA38B89266B4B1E2926AC55B6
============================================================
files created
C:\WINDOWS\system32\afxmgdvr.dll
C:\WINDOWS\system32\vyrkkwkp.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\
3.tmp
dsad11.exe
***********************jfh.exe
***********************.txt
Registry Modifications
Keys AddedHKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}
HKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}\InProcServer32
Values AddedHKLM\SOFTWARE\Classes\CLSID\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}\InProcServer32]
(Default) : "%System%\afxmgdvr.dll"
ThreadingModel : "Apartment"
(Default) : "%System%\vyrkkwkp.dll"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
ShellExecuteHooks\{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633} = ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
vyrkkwkp.dll : "{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}"
afxmgdvr.dll : "{A51CEFB0-39D2-40f4-81D6-6ADE3EF4C633}"