When the Trojan is executed, it creates one of the following mutexes to ensure that only one copy of the threat is running on the computer:
- __SYSTEM__23D80F10__
- __SYSTEM__45A2F601__
- __SYSTEM__64AD0625__
- __SYSTEM__7F4523E5__
- __SYSTEM__91C38905__
It then creates the following files:
%System%\ntos.exe
The Trojan checks to see if the following files are running, and ends them if so:
It then creates the following files:
- %System%\wsnpoem\audio.dll
- %System%\wsnpoem\video.dll
Note: The Trojan sets the System and Hidden attributes on the "wsnpoem" folder.
The Trojan then creates the following registry entry, so that it starts when Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"userinit" = "%System%\ntos.exe"
It also modifies the following registry entry, so that it starts when Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%System%\userinit.exe, %System% \ntos.exe"
The Trojan attempts to create malicious threads in all running processes except for the following one:
CSRSS.EXE
The Trojan may intercept or redirect network traffic.
The Trojan may create the following registry entry as an infection marker:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\"UID" = "[COMPUTERNAME]_[UNIQUE_ID]"
It then attempts to download files from the following URLs:
- [http://]blatundalqik.ru/panama/odess[REMOVED]
- [http://]blatundalqik.ru/panama/odess[REMOVED]
- [http://]blatundalqik.ru/panama/kiev[REMOVED]
- [http://]wfrules.ru/wfrule[REMOVED]
The Trojan opens a back door on three random ports and listens for connections from the attacker.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":