To complicate detection of its presence in the operating system,
blocks the following features:
- System Restore (SR)
- System File Checker (SFC)
- Windows Security Center
Creates and executes the following:
- '<SYSTEM32>\setacl.exe' "USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Protected Storage System Provider\S-1-5-21-2052111302-484763869-725345543-1003" /registry /grant everyone /full
Executes the following:
- '%WINDIR%\regedit.exe' /s %TEMP%\yh.reg
- '<SYSTEM32>\cacls.exe' C:\System~1 /P everyone:F
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\mmc.exe' "<SYSTEM32>\devmgmt.msc"
- '<SYSTEM32>\regsvr32.exe' /u /s igfxpph.dll"
- '%WINDIR%\regedit.exe' /s %TEMP%\优化.reg
Modifies settings of Windows Explorer:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000000'
Modifies settings of Windows Internet Explorer:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
Forces autoplay for removable media.
Sets a new unauthorized home page for Windows Internet Explorer.