Modifies the following registry keys
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '76D6.exe' = '<SYSTEM32>\76D6.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XO1XADpO01' = '"%TEMP%\894E.exe"'
Creates or modifies the following files
- <SYSTEM32>\tasks\firefox default browser agent 013543504661c59e
- %APPDATA%\microsoft\windows\start menu\programs\startup\76d6.exe
- %WINDIR%\tasks\jdjgli.job
Creates the following files on removable media
- <Drive name for removable media>:\winmine.exe.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\delete.avi.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\applicantform_en.doc.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\split.avi.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\tcm851ax32.exe
- <Drive name for removable media>:\wrar520.exe
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\contosoroot.cer.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\february_catalogue__2015.doc.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\contoso_1.cer.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\sdkfailsafeemulator.cer.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\dashborder_144.bmp.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\dashborder_96.bmp.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\tileimage.bmp.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\coffee.bmp.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\dialmap.bmp.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\correct.avi.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\testee.cer.id-c224bec2.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\hadac_newsletter_july_2010_final.docx