The Trojan creates the following files:
- %UserProfile%\Start Menu\Programs\Startup\chkntfs.exe
- %UserProfile%\Application Data\chkntfs.dat
Note: The Trojan hides the presence of these files using rootkit techniques.
The Trojan also creates the following temporary files, which contain a copy of the Trojan and legitimate Microsoft .dll files:
%Temp%\[1-2 ALPHA-NUMERIC CHARACTERS].tmp
The Trojan opens a back door and connects to one of the following domains using HTTP port 80:
- 66kooum.com
- 55echosend.com
- club-world-auto.org
The Trojan then downloads the following encrypted files:
The Trojan then gathers information, such as the following, and it sends to the remote location:
- User name
- Operating system
- Computer name
- Host name
- Country
- Language
- Time
- Windows product key
- Uptime
- Hard disk-related data
- Processes running
- User names and passwords
- Email addresses
- Unique ID generated by the Trojan
The Trojan attempts to disable the following antivirus software:
- McAfee
- Avast4
- Avast5
- Microsoft Security Essentials
- Avira
- ArcaVir
- AVG
- ESET
- BitDefender
- DrWeb
- Sophos
The Trojan steals user names, passwords and email addresses from the following programs:
- WinVNC3
- Remote Desktop Connections
- PC Remote Control
- Freecall
- Camfrog
- ASP.NET Account
- Cached Passwords
- Cisco Systems VPN Clients
- Windows Passwords
- ICQ
- MIRANDA
- TRILLIAN
- MSN
- YAHOO
- AIM
- GAIM
- QIP
- Odigo
- GTalk
- PSI
- My Spcae
- Live Messenger
- PalTalk
- Excite
- Gizmo
- Pidgin
- AIMPRO
- Pandion
- QIPOnline
- JAJC
- Digsby
- Astra
- Opera
- Safari
- Firefox
- Chrome
- Gmail
- RimArts
- The Bat!
- Eudora
- Total Commander
- WS_FTP
- CuteFTP
- FileZilla
- Bullet Proof FTP
- SmartFTP
- FFFTP
- CoffeecupFTP
- COREFTP
- FTP Explorer
- Frigate3FTP
- WINSCP
The Trojan may also remove registry and file components of other common Trojans and intercept HTTP communications.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":