Creates the following files
- %LOCALAPPDATA%\jtzk\secur32.dll
- %LOCALAPPDATA%\jtzk\msra.exe
- %APPDATA%\microsoft\windows\network shortcuts\9jbjthr\secur32.dll
- %APPDATA%\microsoft\windows\network shortcuts\9jbjthr\msra.exe
- %LOCALAPPDATA%\m1xl7\slc.dll
- %LOCALAPPDATA%\m1xl7\displayswitch.exe
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\1k\slc.dll
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\1k\displayswitch.exe
- %LOCALAPPDATA%\ffxctu4eg\sysdm.cpl
- %LOCALAPPDATA%\ffxctu4eg\systempropertieshardware.exe
- %APPDATA%\icqm\icq\html\uz\loading\uz\sysdm.cpl
- %APPDATA%\icqm\icq\html\uz\loading\uz\systempropertieshardware.exe
Deletes the following files
- %LOCALAPPDATA%\jtzk\msra.exe
- %LOCALAPPDATA%\jtzk\secur32.dll
- %LOCALAPPDATA%\m1xl7\displayswitch.exe
- %LOCALAPPDATA%\m1xl7\slc.dll
- %LOCALAPPDATA%\ffxctu4eg\sysdm.cpl
- %LOCALAPPDATA%\ffxctu4eg\systempropertieshardware.exe
Substitutes the following files
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-1960123792-2022915161-3775307078-1001\f58155b4b1d5a524ca0261c3ee99fb50_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee