Creates the following files
- %TEMP%\nsed84d.tmp
- %PROGRAMDATA%\systemnetwork\xcoremanagment.exe
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\index.dat
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\dkohepwd\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\10kk9nue\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\u9rnvwks\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\lqd8y6g9\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %TEMP%\is-jg5sr.tmp\wizardform.bitmapimage1.bmp
- %TEMP%\is-jg5sr.tmp\metroblue.vsf
- %TEMP%\is-jg5sr.tmp\vclstylesinno.dll
- %TEMP%\is-jg5sr.tmp\istask.dll
- %TEMP%\is-jg5sr.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-jg5sr.tmp\_isetup\_setup64.tmp
- %TEMP%\is-jg5sr.tmp\_isetup\_regdll.tmp
- %TEMP%\is-bfva6.tmp\1.tmp
- %APPDATA%\realtek sound blaster\realteksb.exe
- %APPDATA%\software\1.exe
- %APPDATA%\software\sponsor_68.exe
- %APPDATA%\bamboo\boat_10.exe
- %TEMP%\nsjd86d.tmp\system.dll
- %PROGRAMDATA%\systemnetwork\video.txt
- %PROGRAMDATA%\systemnetwork\arch.txt
Sets the 'hidden' attribute to the following files
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\lqd8y6g9\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\u9rnvwks\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\10kk9nue\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\dkohepwd\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
Deletes the following files
- %TEMP%\nsjd86d.tmp\system.dll
- %APPDATA%\software\sponsor_68.exe