Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'yemik' = '%HOMEPATH%\yemik.exe'
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\yemik.exe
- <Drive name for removable media>:\yemik.scr
- <Drive name for removable media>:\new folder.lnk
- <Drive name for removable media>:\passwords.lnk
- <Drive name for removable media>:\documents.lnk
- <Drive name for removable media>:\pictures.lnk
- <Drive name for removable media>:\music.lnk
- <Drive name for removable media>:\video.lnk
- hidden files
- iexplore.exe
- %HOMEPATH%\yemik.exe
- %HOMEPATH%\yemik.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\yemik.exe
- <Drive name for removable media>:\yemik.scr
- '255.255.255.255':8000
- DNS ASK ns#.###picturehut.net
- '%HOMEPATH%\yemik.exe'