Quote:
Creates a mutex named "AdmSkynetJKIS003." This mutex allows only one instance of the worm to execute in memory.
Deletes the values:
"Taskmon"
"Explorer"
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Deletes the values:
"KasperskyAV"
"System."
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Deletes the registry key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
Symantec has it listed as a category 3 outbreak and has posted beta definitions