Technical Information
To ensure autorun and distribution:
Modifies the following registry keys:
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'yortsed' = '%WINDIR%\yortsed.destroy'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yortsed' = '<SYSTEM32>\yortsed.EXE'
Creates the following files on removable media:
- <Drive name for removable media>:\Autorun.xls
- <Drive name for removable media>:\destroy.cur
- <Drive name for removable media>:\Autorun.inf
- <Drive name for removable media>:\destroy.exe
- <Drive name for removable media>:\destroy.destroy
Malicious functions:
Executes the following:
- '%WINDIR%\explorer.exe' <Current directory>
Modifies file system :
Creates the following files:
- C:\Far2\FarEng.nls
- C:\Far2\FarEng.dot
- C:\Far2\FarHun.cad
- C:\Far2\FarGer.vbs
- C:\Far2\FarCze.cmx
- C:\Far2.exe
- C:\Far2\Desktop.ini
- C:\Far2\far.m3u
- C:\Far2\ClearPluginsCache.log
- C:\Far2\FarHun.ogg
- C:\Far2\SaveSettings.wal
- C:\Far2\RestoreSettings.cpl
- C:\<Auxiliary name>.exe
- <Auxiliary element>
- C:\Far2\File_id.ico
- C:\Far2\FarRus.zip
- C:\Far2\FarPol.cad
- C:\Far2\FarSpa.nrg
- C:\Far2\FarRus.bmp
- C:\destroy.destroy
- C:\destroy.exe
- %WINDIR%\Z.ilu
- C:\Autorun.inf
- %WINDIR%\yortsed.exe
- <SYSTEM32>\OEMLOGO.BMP
- <SYSTEM32>\yortsed.exe
- <SYSTEM32>\oeminfo.ini
- %WINDIR%\E.ilu
- <Current directory>.exe
- <Current directory>\Desktop.ini
- C:\Documents and Settings.exe
- C:\Documents and Settings\Desktop.ini
- C:\startup_local.htm
- C:\Autorun.pdf
- %WINDIR%\C.ilu
- C:\NTDETECT.mov
- C:\destroy.amf
Sets the 'hidden' attribute to the following files:
- C:\destroy.exe
- <Drive name for removable media>:\Autorun.inf
- C:\Autorun.inf
- C:\destroy.destroy
- %WINDIR%\yortsed.exe
- <SYSTEM32>\yortsed.exe
- <Drive name for removable media>:\destroy.destroy
- <Drive name for removable media>:\destroy.exe
Deletes the following files:
- %WINDIR%\desktop.ini
Miscellaneous:
Searches for the following windows:
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'