File system changes

Created the following files:


Removes the files:


Changes the processes

Creates the process:

%programfiles%\Internet Explorer\IEXPLORE.EXE

Uses the following temporary processes:


Creates the following mutexes:

IEXPLORE.EXE: _SHuassist.mtx

Network activity

It tries to download files from:[REMOVED].php

Registry changes

It write the following values:

HKCU\Software\Microsoft\Internet Explorer\Main
FullScreen = no

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\\\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count HRZR_PGYFRFFVBA = \x94\x3F\x43\x0E\x28\x00\x00\x00