Note - <system folder> refers to a variable location that is determined by the malware by querying the Operating System. The default installation location for the System folder for Windows 2000 and NT is C:\Winnt\System32; and for XP and Vista is C:\Windows\System32.
The registry is modified to execute the dropped DLL component when the Web browser Internet Explorer is launched.
Sets value: "(default)"
With data: "iconhandle"
In subkey: HKLM\SOFTWARE\Classes\AppID\{DD0AD1D0-6C36-4894-B38E-9E5D3392114D}
Sets value: "AppID"
With data: "{dd0ad1d0-6c36-4894-b38e-9e5d3392114d}"
In subkey: HKLM\SOFTWARE\Classes\AppID\iconhandle.DLL
Sets value: "(default)"
With data: "seticon class"
In subkey: HKLM\SOFTWARE\Classes\iconhandle.seticon.1
Sets value: "(default)"
With data: "{aefa7e78-cf7e-4550-829f-2c786a0070bf}"
In subkey: HKLM\SOFTWARE\Classes\iconhandle.seticon.1\CLSID
Sets value: "(default)"
With data: "seticon class"
In subkey: HKLM\SOFTWARE\Classes\iconhandle.seticon
Sets value: "(default)"
With data: "{aefa7e78-cf7e-4550-829f-2c786a0070bf}"
In subkey: HKLM\SOFTWARE\Classes\iconhandle.seticon\CLSID
Sets value: "(default)"
With data: "iconhandle.seticon.1"
In subkey: HKLM\SOFTWARE\Classes\iconhandle.seticon\CurVer
Sets value: "(default)"
With data: "seticon class"
In subkey: HKLM\SOFTWARE\Classes\CLSID\{AEFA7E78-CF7E-4550-829F-2C786A0070BF}
Sets value: "(default)"
With data: "iconhandle.seticon.1"
In subkey: HKLM\SOFTWARE\Classes\CLSID\{AEFA7E78-CF7E-4550-829F-2C786A0070BF}\ProgID
Sets value: "(default)"
With data: "iconhandle.seticon"
In subkey: HKLM\SOFTWARE\Classes\CLSID\{AEFA7E78-CF7E-4550-829F-2C786A0070BF}\VersionIndependentProgID
Sets value: "(default)"
With data: "<system folder>\iconhandle.dll"
In subkey: HKLM\SOFTWARE\Classes\CLSID\{AEFA7E78-CF7E-4550-829F-2C786A0070BF}\InprocServer32
Sets value: "(default)"
With data: "{581f1707-4ad0-4b7b-ad6e-057db8f686f3}"
In subkey: HKLM\SOFTWARE\Classes\CLSID\{AEFA7E78-CF7E-4550-829F-2C786A0070BF}\TypeLib
Sets value: "(default)"
With data: "{aefa7e78-cf7e-4550-829f-2c786a0070bf}"
In subkey: HKLM\SOFTWARE\Classes\txtfile\shellEx\IconHandler
Sets value: "(default)"
With data: "iconhandle 1.0 ààðí¿â"
In subkey: HKLM\SOFTWARE\Classes\TypeLib\{581F1707-4AD0-4B7B-AD6E-057DB8F686F3}\1.0
Sets value: "(default)"
With data: "0"
In subkey: HKLM\SOFTWARE\Classes\TypeLib\{581F1707-4AD0-4B7B-AD6E-057DB8F686F3}\1.0\FLAGS
Sets value: "(default)"
With data: "<system folder>\iconhandle.dll"
In subkey: HKLM\SOFTWARE\Classes\TypeLib\{581F1707-4AD0-4B7B-AD6E-057DB8F686F3}\1.0\0\win32
Sets value: "(default)"
With data: "%windir%\system32"
In subkey: HKLM\SOFTWARE\Classes\TypeLib\{581F1707-4AD0-4B7B-AD6E-057DB8F686F3}\1.0\HELPDIR
Sets value: "(default)"
With data: "iseticon"
In subkey: HKLM\SOFTWARE\Classes\Interface\{72397142-9352-4A45-99AD-2EF143072AC0}
Sets value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
In subkey: HKLM\SOFTWARE\Classes\Interface\{72397142-9352-4A45-99AD-2EF143072AC0}\ProxyStubClsid
Sets value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
In subkey: HKLM\SOFTWARE\Classes\Interface\{72397142-9352-4A45-99AD-2EF143072AC0}\ProxyStubClsid32
Sets value: "(default)"
With data: "{581f1707-4ad0-4b7b-ad6e-057db8f686f3}"
In subkey: HKLM\SOFTWARE\Classes\Interface\{72397142-9352-4A45-99AD-2EF143072AC0}\TypeLib
Analysis by Wei Li