Malware Hosted In United States Ashburn Inc.)

Contains anti-debugging code
It makes use of some deprecated flags in the Characteristics field of FileHeader
PE section has SizeOfRawData set to zero

Automatically unpack its own code
Deletes itself
Deletes itself after reboot
Drops .EXE file
Manipulates Internet Explorer settings
Runs existing executable
Suspicious delay

C:cicaafbwww.exe (v.  hxxp://

