The virus starts by decryipting a part of its code in order to resolve its imports. When that is done it searches for the process svchost.exe, injects in it and creates the mutex asd..6567fj.
After the virus code has been injected it checks if it runs from C:\Recycler\D-1-5-21-1482476501-1644491937-682003330-1013\autorun.exe and if doesn
Please let BitDefender disinfect your files.
Presence of C:\autorun.inf file

Subscribe
Hot Articles