This rootkit does not self-replicate. It is dropped by W32/Fujacks.worm when the system is infected. When the system is infected the rootkit is dropped to %WINDOWS%\TEMP\NtHid.sys, started as a service and removed from the disk.
Failplaya is nervous 01/19/2010 - S4 League - 5 Replies His new update, not just ass the new HGWC
1.if you got the old resource tool, notice the new xml
all are x7
2. Client is now encrypted, text are not display directly
3. Some resources added, as well as the one to trigger HGWC