When executed, the worm copies itself as the following file:
%SystemDrive%\VIDI\UNUK\DRG.exe
The worm then creates the following file:
%SystemDrive%\VIDI\UNUK\DesKTop.ini
It then creates the following registry entry so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-01WE-AAX2-5657QCA554112}\"StubPath" = "%SystemDrive%\VIDI\UNUK\DRG.exe"
The worm attempts to download files from the following network addresses:
- acc008.homeip.net
- acc7hr33.webhop.biz
- ogard6.ircdevils.net
Note: The downloaded files may be updates to the worm.
The worm spreads by copying itself to all removable drives as the following file:
%DriveLetter%\VIDI\UNUK\DRG.exe
It also creates the following file:
%DriveLetter%\VIDI\UNUK\DesKTop.ini
The worm creates the following file so that it runs when the above drives are accessed:
%DriveLetter%\aUtOrUn.inf
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":