To bypass firewall, removes or modifies the following registry keys:
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
blocks the following features:
- User Account Control (UAC)
- Windows Security Center
Executes the following:
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\cmd.exe' /k attrib "%HOMEPATH%\Local Settings\Temp" +s +h
- '%APPDATA%\MSDCSC\msdcsc.exe'
- '<SYSTEM32>\attrib.exe' "%TEMP%\v1.exe" +s +h
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Local Settings\Temp" +s +h
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\excec.bat" "
- '%TEMP%\excec.exe'
- '%TEMP%\V1Pack.exe' -pAsdzxc123!@# -d%HOMEPATH%\Local Settings\Temp
- '<SYSTEM32>\cmd.exe' /k attrib "%TEMP%\v1.exe" +s +h
- '%TEMP%\v1.exe'
Injects code into
the following system processes: