To complicate detection of its presence in the operating system,
forces the system hide from view:
blocks the following features:
- User Account Control (UAC)
Executes the following:
- '<SYSTEM32>\winupdater.exe'
Searches for windows to
detect analytical utilities:
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: '' WindowName: 'TCPView - Sysinternals: www.sysinternals.com'
- ClassName: '' WindowName: 'The Wireshark Network Analyzer'
- ClassName: 'TCPViewClass' WindowName: ''
detect programs and games:
- ClassName: 'gdkWindowToplevel' WindowName: ''