To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
deletes volume shadow copies.
Creates and executes the following (exploit)
Creates and loads libraries (exploit)
- %APPDATA%\zvgpmzeaujxk.pwn
Executes the following
- '%WINDIR%\syswow64\net.exe' stop MpsSvc
Executes the following (exploit)
- '<SYSTEM32>\cmd.exe' /C start /B "" "%APPDATA%\svnhost.exe"
Injects code into
the following system processes:
- %WINDIR%\syswow64\explorer.exe
the following user processes: