This Trojan may arrive as a .cab file.
When the .cab file is opened, the Trojan creates the following file, which is a Windows Telephony file:
%CurrentFolder%\1.dll
Note: The above file may also be used by other malware.
The Trojan also creates the following file, which is a malicious dialer program:
%CurrentFolder%\reg.exe
It then copies the above file to the following location:
%Windir%\smart32.exe
Next, the Trojan creates the following registry entry:
HKEY_CURRENT_USER\Alpha\"Status" = "1"
The Trojan then attempts to call the following high-cost international numbers:
- 8823460777
- 17675033611
- 88213213214
- 25240221601
It also tries to run itself again after one month.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":