To complicate detection of its presence in the operating system,
adds antivirus exclusion with following registry keys:
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\d3dxsjob.exe' = '00000000'
Injects code into
the following system processes:
the following user processes:
Hooks functions
in browsers
- firefox.exe process, nss3.dll module
- iexplore.exe process, wininet.dll module
- iexplore.exe process, advapi32.dll module
- iexplore.exe process, urlmon.dll module
Terminates or attempts to terminate
the following system processes:
Reads files which store third party applications passwords
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\ituneshelpunavailable.html
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\api-hashmap.html
- %HOMEPATH%\desktop\alert.htm
- %HOMEPATH%\desktop\cveuropeo.doc