To complicate detection of its presence in the operating system,
blocks the following features:
- User Account Control (UAC)
modifies the following system settings:
- Hides taskbar notifications
Creates and executes the following:
- '%WINDIR%\log\pass.exe' (downloaded from the Internet)
Executes the following:
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\log\pass.exe all
- '%WINDIR%\log\pass.exe' all
- '<SYSTEM32>\cmd.exe' /c netsh firewall add allowedprogram program = STcONaURjstoJeQ(uMqeEfSfaGeNmho("yJmAEIBBXdvRXSFRGegUiJnA")) name = STcONaURjstoJeQ(uMqeEfSfaGeNmho("XQ0V1bwVGZ0FQZ==")) mode = ENABLE
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram program = STcONaURjstoJeQ(uMqeEfSfaGeNmho("yJmAEIBBXdvRXSFRGegUiJnA")) name = STcONaURjstoJeQ(uMqeEfSfaGeNmho("XQ0V1bwVGZ0FQZ==")) mode = ENABLE