To bypass firewall, removes or modifies the following registry keys:
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
blocks the following features:
- User Account Control (UAC)
- Windows Security Center
Executes the following:
- '%HOMEPATH%\My Documents\MSDCSC\msdcsc.exe'
- '<SYSTEM32>\cmd.exe' /k attrib "%HOMEPATH%\Local Settings\Temp" +s +h
- '<SYSTEM32>\attrib.exe' "%TEMP%\HD.exe" +s +h
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Local Settings\Temp" +s +h
- '<SYSTEM32>\notepad.exe'
- '%TEMP%\zg.exe' -p12345 -d%HOMEPATH%\Local Settings\Temp
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\12.bat" "
- '%TEMP%\HD.exe'
- '<SYSTEM32>\cmd.exe' /k attrib "%TEMP%\HD.exe" +s +h
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\12.jpg
Injects code into
the following system processes: