Technical Information
Malicious functions:
Executes the following:
- <SYSTEM32>\attrib.exe +h "<Current directory>\mozsqlite3.dll"
Terminates or attempts to terminate
the following user processes:
- zlclient.exe
- outpost.exe
Modifies file system :
Creates the following files:
- <Current directory>\mozsqlite3.dll
Sets the 'hidden' attribute to the following files:
- <Current directory>\mozsqlite3.dll