Technical Information
Malicious functions:
Creates and executes the following:
- <SYSTEM32>\msvchost.exe
- <SYSTEM32>\ssvchost.com
Injects code into
the following system processes:
- %WINDIR%\Explorer.EXE
Modifies file system :
Creates the following files:
- <SYSTEM32>\ssvchost.com
- <SYSTEM32>\rgml.dll
- <SYSTEM32>\msvchost.exe
- C:\aaa.cab
- <SYSTEM32>\regc64.dll
Deletes the following files:
- C:\aaa.cab