To bypass firewall, removes or modifies the following registry keys:
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
To complicate detection of its presence in the operating system,
blocks the following features:
- User Account Control (UAC)
Executes the following:
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '<SYSTEM32>\attrib.exe' "%TEMP%\gg.exe" +s +h
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Local Settings\Temp" +s +h
- '%TEMP%\gg.exe'
- '<SYSTEM32>\cmd.exe' /k attrib "%TEMP%\gg.exe" +s +h
- '<SYSTEM32>\cmd.exe' /k attrib "%HOMEPATH%\Local Settings\Temp" +s +h
Injects code into
the following user processes: