Technical Information
To ensure autorun and distribution
Modifies the following registry keys
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Update' = '%TEMP%\skyp\Microsoft Update.lnk'
Modifies file system
Creates the following files
- %TEMP%\aut7e43.tmp
- %TEMP%\riprzjh
- %TEMP%\skyp\server.exe
- %TEMP%\skyp\microsoft update.lnk
Deletes the following files
- %TEMP%\aut7e43.tmp
- %TEMP%\riprzjh
Network activity
UDP
- DNS ASK ib###s.ddns.net