Modifies the following registry keys
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ad76a6098df431046ffdf41b1a2ed40a' = '"%PROGRAMDATA%\svchost.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ad76a6098df431046ffdf41b1a2ed40a' = '"%PROGRAMDATA%\svchost.exe" ..'
Creates or modifies the following files
- %APPDATA%\microsoft\windows\start menu\programs\startup\ad76a6098df431046ffdf41b1a2ed40a.exe
Creates the following files on removable media
- <Drive name for removable media>:\ad76a6098df431046ffdf41b1a2ed40a.exe
- <Drive name for removable media>:\sdszfo.docx.lnk
- <Drive name for removable media>:\adhd_and_obesity.docx.lnk
- <Drive name for removable media>:\file_p_00000000_1371597592.docx.lnk
- <Drive name for removable media>:\hadac_newsletter_july_2010_final.docx.lnk
- <Drive name for removable media>:\thlps_keeper_mayer_1965.docx.lnk
- <Drive name for removable media>:\ovp25012015.doc.lnk
- <Drive name for removable media>:\sdkfailsafeemulator.cer.lnk
- <Drive name for removable media>:\pmd.cer.lnk
- <Drive name for removable media>:\tcm851ax32.exe.lnk
- <Drive name for removable media>:\sdksampleprivdeveloper.cer.lnk
- <Drive name for removable media>:\dashborder_120.bmp.lnk
- <Drive name for removable media>:\default.bmp.lnk
- <Drive name for removable media>:\tileimage.bmp.lnk
- <Drive name for removable media>:\delete.avi.lnk
- <Drive name for removable media>:\correct.avi.lnk
- <Drive name for removable media>:\split.avi.lnk
- <Drive name for removable media>:\archer.avi.lnk
- <Drive name for removable media>:\join.avi.lnk
- <Drive name for removable media>:\dashborder_96.bmp.lnk
- <Drive name for removable media>:\wrar520.exe.lnk