To bypass firewall, removes or modifies the following registry keys:
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
blocks the following features:
- User Account Control (UAC)
- Windows Security Center
Creates and executes the following:
- '%APPDATA%\sysprog\igfxpeis.exe'
Executes the following:
- '<SYSTEM32>\attrib.exe' "<Current directory>" +s +h
- '%APPDATA%\sysprog\igfxpeis.exe'
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\cmd.exe' /k attrib "<Full path to file>" +s +h
- '<SYSTEM32>\cmd.exe' /k attrib "<Current directory>" +s +h
- '<SYSTEM32>\attrib.exe' "<Full path to file>" +s +h
Injects code into
the following system processes:
the following user processes: