To complicate detection of its presence in the operating system,
forces the system hide from view:
blocks execution of the following system utilities:
- Command Prompt (CMD)
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
Executes the following:
- <SYSTEM32>\taskkill.exe /f /im 360tray.exe
- <SYSTEM32>\taskkill.exe /f /im VsTskMgr.exe
- <SYSTEM32>\wbem\wmiadap.exe /R /T
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\reg.bat
- <SYSTEM32>\taskkill.exe /im /f explorer.exe
- <SYSTEM32>\taskkill.exe /f /im Mcshield.exe
- <SYSTEM32>\taskkill.exe /f /im kavsvc.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\taskkill.exe /f /im KVXP.kxp
- <SYSTEM32>\taskkill.exe /f /im Ravmon.exe
- <SYSTEM32>\taskkill.exe /f /im Rav.exe
Terminates or attempts to terminate
the following system processes:
the following user processes:
Modifies settings of Windows Explorer:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFileMenu' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetFolders' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewContextMenu' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRecentDocsMenu' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = 'FFFFFFFF'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDesktop' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = 'FFFFFFFF'
Forces autoplay for removable media.
Sets a new unauthorized home page for Windows Internet Explorer.