Creates cpl and exe file on the usb stick. in The recycler\(sid) of the usb stick.
Autorun has a bunch of what appears garbage data.
Inside the autorun.inf is hidden:
oFZNCPaKpFqnypMvunsJAUxaulHmNGcfpxcxQWpTWyPLPRKSQjsQhufI
QoxPwiaWhAexFmbQfCMkhSKPqerQopYyGAhHorvIPPREcrSUnACLyfRtyQaRqI
srGYVFTeEeNyyeKVSICYaVrwxoLRvgTMtsPfDoSIjdpqmZkLAgKdU
UePqxwFZoNubGgTFYLfpmYELeDkWsNVeXnGdjUObhqyrhMAErRqscxkakCplNWQhBFZOGgh
aYvQfnbdwreDkCxhnEyhplBaADYULsoWuGegXGgjuJtZXwBqb
[autorun]
action=Open
icon=%WinDir%\system32\shell32.dll,4
shellexecute=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
shell\explore\command=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
USEAUTOPLAY=1
shell\Open\command=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
kTxSrBsVFIdVCQrfZDDOqweGuedBBMtoIaoWovaKaqPduMpQFmNBKQyDFYBJoicxILbnC
wNCJnZlQQwmhfEvOijCDKYOBrDOcEpyMsCbpBcRSVISXJpepadpsLjVimAIXFcytgSUmoOEyAPSrCaXOcpibyix
also infects c:\program files and current user startup folder.
Autorun has a bunch of what appears garbage data.
Inside the autorun.inf is hidden:
oFZNCPaKpFqnypMvunsJAUxaulHmNGcfpxcxQWpTWyPLPRKSQjsQhufI
QoxPwiaWhAexFmbQfCMkhSKPqerQopYyGAhHorvIPPREcrSUnACLyfRtyQaRqI
srGYVFTeEeNyyeKVSICYaVrwxoLRvgTMtsPfDoSIjdpqmZkLAgKdU
UePqxwFZoNubGgTFYLfpmYELeDkWsNVeXnGdjUObhqyrhMAErRqscxkakCplNWQhBFZOGgh
aYvQfnbdwreDkCxhnEyhplBaADYULsoWuGegXGgjuJtZXwBqb
[autorun]
action=Open
icon=%WinDir%\system32\shell32.dll,4
shellexecute=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
shell\explore\command=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
USEAUTOPLAY=1
shell\Open\command=\RECYCLER\S-7-8-43-5010723741-8584364467-787650441-0075\hqiRHBJM.exe
kTxSrBsVFIdVCQrfZDDOqweGuedBBMtoIaoWovaKaqPduMpQFmNBKQyDFYBJoicxILbnC
wNCJnZlQQwmhfEvOijCDKYOBrDOcEpyMsCbpBcRSVISXJpepadpsLjVimAIXFcytgSUmoOEyAPSrCaXOcpibyix
also infects c:\program files and current user startup folder.
Attachments
password infected
(78.88 KiB) Downloaded 77 times
(78.88 KiB) Downloaded 77 times