Once executed, the Trojan creates the following file:
%System%\msnmsie.exe
Next, the Trojan creates the following registry entry so that it runs every time Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"StartKey" = "%System%\msnmsie.exe"
It also creates the following registry subkeys:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A5CDF7EC-751B-46aa-AD69-4005FE080DE8}
- HKEY_LOCAL_MACHINE\SOFTWARE\SKav
- HKEY_CURRENT_USER\Software\SKav
The Trojan then creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\SKav\"nck" = "99 6F D5 66 A0 AC EA 5F F7 EC 7F 84 DC 8A DA 00 A8 5F E4 52 A0 AC EA 5F F7 EC 7F 84 DC 8A DA 00"
- HKEY_CURRENT_USER\Software\SKav\"klg" = "00"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A5CDF7EC-751B-46aa-AD69-4005FE080DE8}\"stubpath" = "C:\WINDOWS\system32\msnmsie.exe s"
It creates a new Internet Explorer instance and injects itself into this process to hide its presence on the compromised computer.
It periodically attempts to access the following Web sites:
- freexuite.ns01.us
- gundamms08.ns1.name
The Trojan may open a back door allowing a remote attacker unauthorized access on the compromised computer.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":