Creates the following files
- %TEMP%\aute844.tmp
- %APPDATA%\z86427651\bot.exe
- %TEMP%\auteb52.tmp
- %APPDATA%\z86427651\trading bot.exe
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\index.dat
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\h9txcel5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\1ap7acbm\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\j1p050sb\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\x7hoxtst\desktop.ini
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\index.dat
- %APPDATA%\amd64_nettun.inf.resources_31bf3856ad364e35_6.3.9600.16384_ru-ru_8d060d0699605dac\config.json
Sets the 'hidden' attribute to the following files
- %APPDATA%\amd64_nettun.inf.resources_31bf3856ad364e35_6.3.9600.16384_ru-ru_8d060d0699605dac\icmp.exe
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\h9txcel5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\1ap7acbm\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\j1p050sb\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\x7hoxtst\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\desktop.ini
- %APPDATA%\amd64_nettun.inf.resources_31bf3856ad364e35_6.3.9600.16384_ru-ru_8d060d0699605dac\config.json
Deletes the following files
- %TEMP%\aute844.tmp
- %TEMP%\auteb52.tmp
Moves the following files
- from %APPDATA%\z86427651\trading bot.exe to %APPDATA%\amd64_nettun.inf.resources_31bf3856ad364e35_6.3.9600.16384_ru-ru_8d060d0699605dac\icmp.exe