Injects code into
the following system processes:
- %WINDIR%\syswow64\werfault.exe
Hooks functions
in browsers
- firefox.exe process, nss3.dll module
- iexplore.exe process, wininet.dll module
- firefox.exe process, dnsapi.dll module
- iexplore.exe process, dnsapi.dll module
Terminates or attempts to terminate
the following system processes:
- %WINDIR%\syswow64\schtasks.exe
Modifies settings of Windows Internet Explorer
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'