When TrojanDownloader.Nekotimed.a is executed, it performs the following activities:
After execution, it drops the following files: %windir%\system32\-101-163876 %windir%s\ystem32\-85-163876 %windir%\system32\067o.dll %windir%\system32\17bc %windir%\system32\6d6d.exe %windir%\system32\6d6e.dll %windir%\Tasks\ms.job %windir%\c16d.exe %windir%\c16d.flv %windir%\c16u.bmp
It modifies/creates the following registry entries: