This virus infects HTT, ASP, HTM and HTML files in several Windows
directories. It may drop a debug script into
C:\Windows\System\System.dll and a batch script into
C:\Windows\WinStart.bat to process the debug script. The debug
script will create the junk file command3.com. On 5th, 15th or
30th of any month it will set the following registry keys,
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProductName =
"Windogs Fuck!",
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner =
"Kil13r",
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization =
"in Korea, DLSoft" and
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page =
"http://fuck-japan.com".