Modifies the following registry keys:
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}] 'StubPath' = '%WINDIR%\InstallDir\Server.exe restart'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}] 'StubPath' = '%WINDIR%\InstallDir\Server.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = '%WINDIR%\InstallDir\Server.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,,%ProgramFiles%\ebaurodr\mhrhcrji.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = '%WINDIR%\InstallDir\Server.exe'
Creates or modifies the following files:
- %HOMEPATH%\Start Menu\Programs\Startup\mhrhcrji.exe
Infects the following executable files:
- C:\Far2\Plugins\FTP\FarFtp.dll
- C:\Far2\Plugins\HlfViewer\HlfViewer.dll
- C:\Far2\Plugins\FarCmds\FARCmds.dll
- C:\Far2\Plugins\DrawLine\DrawLine.dll
- C:\Far2\Plugins\EMenu\EMenu.dll
- C:\Far2\Plugins\TmpPanel\TmpPanel.dll
- C:\Far2\Plugins\WinSCP\WinSCP.dll
- C:\Far2\Plugins\ProcList\Proclist.dll
- C:\Far2\Plugins\MacroView\MacroView.dll
- C:\Far2\Plugins\Network\Network.dll
- C:\Far2\FExcept\FExcept.dll
- C:\Far2\Plugins\7-Zip\7-ZipFar.dll
- C:\Far2\FExcept\ExcDump.dll
- C:\Far2\Far.exe
- C:\Far2\FExcept\demangle32.dll
- C:\Far2\Plugins\Colorer\bin\colorer.dll
- C:\Far2\Plugins\Compare\Compare.dll
- C:\Far2\Plugins\Brackets\Brackets.dll
- C:\Far2\Plugins\arclite\7z.dll
- C:\Far2\Plugins\arclite\arclite.dll
Creates the following files on removable media:
- <Drive name for removable media>:\RECYCLER\S-1-4-26-5734026877-1786765000-823325755-0722\KQvqfKKC.cpl
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\RECYCLER\S-1-4-26-5734026877-1786765000-823325755-0722\wEgZCmsI.exe