File size118,352 bytes
MD5: 98529588AED40D2B0324A1D5302332C6
SHA-1: 7065A171886C82371CA01AFF6066772B2B6DD68A
============================================================
Files created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
X:\obg.exe
X:\autorun.inf
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
MD5: 98529588AED40D2B0324A1D5302332C6
SHA-1: 7065A171886C82371CA01AFF6066772B2B6DD68A
============================================================
Files created
C:\Documents and Settings\[UserName]\Local Settings\Temp\uret463.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\lhgjyit0.dll (0-9)
X:\obg.exe
X:\autorun.inf
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dorfgwe = "%Temp%\uret463.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000