Technical Information
To ensure autorun and distribution:
Infects the following executable system files:
- %WINDIR%\TASKMAN.EXE
- %WINDIR%\sleep.exe
- %WINDIR%\winhlp32.exe
- %WINDIR%\twunk_32.exe
- %WINDIR%\NOTEPAD.EXE
- %WINDIR%\hh.exe
- %WINDIR%\sfk.exe
- %WINDIR%\regedit.exe