Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'hsys' = '<Current directory>\HSYS.EXE'
- <Current directory>\HSYS.EXE Kill_50903C9=<Full path to virus>
- Handler for all processes: <Current directory>\kl.dll
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '*.bat'
- <Current directory>\kl.dll
- <Current directory>\hsys.log
- <Current directory>\HSYS.EXE
- ClassName: 'Shell_TrayWnd' WindowName: ''