To bypass firewall, removes or modifies the following registry keys:
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
To complicate detection of its presence in the operating system,
blocks the following features:
- System Restore (SR)
- System File Checker (SFC)
- Windows Security Center
Executes the following:
- '<SYSTEM32>\mshta.exe' vbscript:msgbox(" -╟ы╣╪▒╒┤░┐┌-",,"═ъ│╔!!!")(window.close)
- '%WINDIR%\regedit.exe' /S Winxp.reg
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\A处o\快速优化.bat"
Modifies settings of Windows Explorer:
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoStartMenuMorePrograms' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
Modifies settings of Windows Internet Explorer:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
Forces autoplay for removable media.
Sets a new unauthorized home page for Windows Internet Explorer.