When the Trojan is executed, it creates the following files:
- %SystemDrive%\System\200307C77\init.ini
- %SystemDrive%\System\data\20030C77\config\xmlconfig.ini
- %SystemDrive%\System\data\20030C77\config\XinConfigure.ini
It then for checks emails in the following folders:
- %SystemDrive%\Private\1000484b\Mail\Index
- %SystemDrive%\Private\1000484b\Mail2\Index
The Trojan may gather the following system information:
- IAP Service configuration
- Proxy server configuration
- SMS history
The Trojan stores the information on the following files:
- C:\data\others\CheckResponse.txt
- C:\data\others\CheckPacket.txt
- C:\data\others\reportpacket.txt
The Trojan may send the information to a remote location using HTTP.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":