Technical Information
To ensure autorun and distribution:
Substitutes the following executable system files:
- <SYSTEM32>\userinit.exe with <SYSTEM32>\userinit.exe
- <SYSTEM32>\dllcache\userinit.exe with <SYSTEM32>\dllcache\userinit.exe
Malicious functions:
Executes the following:
- <SYSTEM32>\rundll32.exe chqqre
- <SYSTEM32>\rundll32.exe
Modifies file system :
Creates the following files:
- <SYSTEM32>\skbuwa.dll
- <SYSTEM32>\hvkuvl.dll
Deletes the following files:
- <SYSTEM32>\userinit.exe
- <SYSTEM32>\dllcache\userinit.exe