When the worm is executed, it creates the following files:
- %SystemDrive%\RECYCLER\[SID]\nissan.exe
- %SystemDrive%\RECYCLER\[SID]\Desktop.ini
- %DriveLetter%\RECYCLER\[SID]\csrxx.exe (W32.IRCBot)
- %DriveLetter%\SLATKO\torta.exe
- %DriveLetter%\SLATKO\Desktop.ini
- %DriveLetter%\autorun.inf
It then creates the following registry entry, so that it starts when Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Taskman" = "C:\RECYCLER\[SID]\nissan.exe"
The worm then opens a back door and connects to the following domains on UDP port 25000:
- sandra.prichaonica.com
- pica.banjalucke-ljepotice.ru
- l33t.brand-clothes.net
The worm also copies itself to the shared folder of the following file-sharing programs:
- Ares
- BearShare
- iMesh
- Shareaza
- Kazaa
- DC++
- eMule
- LimeWire
It then monitors browsing activities, logging passwords stored in the browsers.
The worm will send messages through Microsoft instant messaging programs, such as MSN Messenger and Windows Live Messenger, that include a link to download the worm.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":