Technical Information
To ensure autorun and distribution:
Substitutes the following executable system files:
- <SYSTEM32>\userinit.exe with <SYSTEM32>\userinit.exe
- <SYSTEM32>\dllcache\userinit.exe with <SYSTEM32>\dllcache\userinit.exe
Infects the following executable files:
- <SYSTEM32>\userinit.exe
Malicious functions:
Executes the following:
- '<SYSTEM32>\rundll32.exe'
Injects code into
the following system processes:
- <SYSTEM32>\rundll32.exe
Modifies file system :
Creates the following files:
- <SYSTEM32>\skbuwa.dll
- <SYSTEM32>\hvkuvl.dll
Deletes the following files:
- <SYSTEM32>\userinit.exe
- <SYSTEM32>\dllcache\userinit.exe