Creates the following files:
- %ALLUSERSPROFILE%\Desktop\Internet Exp1orer.lnk
- %ALLUSERSPROFILE%\Desktop\IO±¦.lnk
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\unins000.dat
- %ALLUSERSPROFILE%\Start Menu\Programs\ј«ЛЩНшВзµзКУ\Р¶ФШ ј«ЛЩНшВзµзКУ.lnk
- %ALLUSERSPROFILE%\Desktop\ј«ЛЩНшВзµзКУ.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ј«ЛЩНшВзµзКУ.lnk
- %HOMEPATH%\Favorites\AAA®??Oµ.lnk
- %HOMEPATH%\Favorites\AAA®EO?µ.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s1[1]
- %HOMEPATH%\Favorites\IO±¦.lnk
- %ALLUSERSPROFILE%\Desktop\AAA®??Oµ.lnk
- %ALLUSERSPROFILE%\Desktop\AAA®EO?µ.lnk
- %HOMEPATH%\Favorites\Internet Exp1orer.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\ј«ЛЩНшВзµзКУ\ј«ЛЩНшВзµзКУ.lnk
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-GDB70.tmp
- %TEMP%\is-DSN2N.tmp\is-J13AM.tmp
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-JT54C.tmp
- %TEMP%\is-DSN2N.tmp\LnkHelper.dll
- %TEMP%\is-4ORG3.tmp\<Virus name>.tmp
- %TEMP%\is-DSN2N.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-DSN2N.tmp\_isetup\_shfoldr.dll
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-6GR7G.tmp
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-P77CV.tmp
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-OQLEI.tmp
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-S1T08.tmp
- %PROGRAM_FILES%\sogouInput\is-VN491.tmp
- %PROGRAM_FILES%\sogouInput\is-U9MLK.tmp
- %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-8NBUS.tmp
Deletes the following files:
- %TEMP%\is-DSN2N.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-4ORG3.tmp\<Virus name>.tmp
- %TEMP%\is-DSN2N.tmp\LnkHelper.dll
- %TEMP%\is-DSN2N.tmp\_isetup\_RegDLL.tmp
Moves the following files:
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-S1T08.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\jisu.exe
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-8NBUS.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\data.dat
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-6GR7G.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\mm.ico
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-OQLEI.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\tao.ico
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-P77CV.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\mm2.ico
- from %TEMP%\is-DSN2N.tmp\is-J13AM.tmp to %TEMP%\is-DSN2N.tmp\LnkHelper.dll
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-GDB70.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\unins000.exe
- from %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\is-JT54C.tmp to %PROGRAM_FILES%\ј«ЛЩНшВзµзКУ\ethernet.dll
- from %PROGRAM_FILES%\sogouInput\is-U9MLK.tmp to %PROGRAM_FILES%\sogouInput\filmst.exe
- from %PROGRAM_FILES%\sogouInput\is-VN491.tmp to %PROGRAM_FILES%\sogouInput\ethernet.dll