Technical Information
To ensure autorun and distribution:
Substitutes the following executable system files:
- <SYSTEM32>\userinit.exe with <SYSTEM32>\userinit.exe
Malicious functions:
Executes the following:
- <SYSTEM32>\rundll32.exe iwudrk
- <SYSTEM32>\rundll32.exe
Modifies file system :
Creates the following files:
- <SYSTEM32>\baakvf.dll
- <SYSTEM32>\zdylko.dll
Deletes the following files:
- <SYSTEM32>\userinit.exe