Creates the following files
- %LOCALAPPDATA%\lub0zy5\p2p.dll
- %LOCALAPPDATA%\lub0zy5\p2phost.exe
- %APPDATA%\mail.ru\agent\mra\html\ua\jabber\8txk7n\p2p.dll
- %APPDATA%\mail.ru\agent\mra\html\ua\jabber\8txk7n\p2phost.exe
- %LOCALAPPDATA%\bszdu\mfc42u.dll
- %LOCALAPPDATA%\bszdu\mspaint.exe
- %APPDATA%\microsoft\windows\libraries\qh\mfc42u.dll
- %APPDATA%\microsoft\windows\libraries\qh\mspaint.exe
- %LOCALAPPDATA%\te8amr6\secur32.dll
- %LOCALAPPDATA%\te8amr6\taskmgr.exe
- %APPDATA%\microsoft\windows\themes\ywaym4dle\secur32.dll
- %APPDATA%\microsoft\windows\themes\ywaym4dle\taskmgr.exe
Deletes the following files
- %LOCALAPPDATA%\lub0zy5\p2p.dll
- %LOCALAPPDATA%\lub0zy5\p2phost.exe
- %LOCALAPPDATA%\bszdu\mfc42u.dll
- %LOCALAPPDATA%\bszdu\mspaint.exe
- %LOCALAPPDATA%\te8amr6\secur32.dll
- %LOCALAPPDATA%\te8amr6\taskmgr.exe
Substitutes the following files
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-1960123792-2022915161-3775307078-1001\f58155b4b1d5a524ca0261c3ee99fb50_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee