Technical Information
Malicious functions:
Executes the following:
- <SYSTEM32>\ping.exe 127.0.0.1 -n 2
Modifies file system :
Creates the following files:
- %TEMP%\HZ~1.tmp.bat
- <DRIVERS>\etc\hosts(1)
Deletes the following files:
- <DRIVERS>\etc\hosts
Substitutes the HOSTS file.
Deletes itself.
Miscellaneous:
Searches for the following windows:
- ClassName: 'Shell_TrayWnd' WindowName: ''