●The firewall disable.
●The security center disable.
●It replace icon of security center.
●After executing virus, it will create following files to the folder:
C:\Documents and Settings\[User Name]\Local Settings\Application Data\5431nbKhXK
C:\Documents and Settings\[User Name]\Local Settings\Application Data\av.exe
●Add following value to the registry, then virus will run while you start Windows:
HKEY_USERS\S-1-5-21-1123561945-1659004503-839522115-1003\Software\
Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\
[User Name]\Local Settings\Application Data\av.exe: "av"
HKEY_USERS\S-1-5-21-1123561945-1659004503-839522115-1003\Software\Classes\.exe\
shell\open\command\: ""C:\Documents and Settings\
[User Name]\Local Settings\Application Data\av.exe" /START "%1" %*"
●Modify the following registry file, and firewall service will be clesed:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=0x00000001
|