Folder::
c:\programdata\OtyuZecc
c:\programdata\AbmiHxiwa
File::
c:\windows\System32\config\systemprofile\AppData\Local\oivtvid.dll
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\oivtvid]
ClearJavaCache::
RegLockDel::
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run]
@DACL=(02 0000)
"oyytgod"="rundll32 \"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Local\\oyytgod.dll\",oyytgod"
.
[HKEY_USERS\S-1-5-21-16877433-1430952535-4280249599-1000_Classes\clsid\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32\*]
@Allowed: (B) (CreatorAuthority-4)
File::
c:\\Windows\\system32\\config\\systemprofile\\AppData\\Local\\oyytgod.dll