When the worm executes, it attempts to copy itself to the following location if the operating system is Windows Vista:
C:\Users\Public\HEX-5823-6893-6818\jutched.exe
Otherwise, it copies itself to the following location:
C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe
It then deletes the original copy of the worm.
The worm may also download and store a configuration file in the following location:
%System%\winrtsnr.txt
Next, the worm creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Java Update Manager" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe"
It also creates the following registry entries in order to add itself to the list of applications authorized by the Windows firewall:
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe:*:Enabled:Java Update Manager"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe:*:Enabled:Java Update Manager"
Next, the worm may connect to the following location using TCP port 1866 where it receives commands and downloads configuration information:
msnsolution.nicaze.net
The worm may download files specified in the configuration files to the %Temp% folder and execute them.
Next, the worm checks for any removable drives from C through Z. It then creates the following hidden folder on the removable drive:
%DriveLetter%\8585485
The worm then searches for any folders on the removable drive. If a folder is found, the worm hides the folder and creates a .lnk file with the same name as the folder:
%DriveLetter%\[FOLDER NAME]s.lnk
The .lnk file is given a folder icon and points to a copy of the worm in the following location:
%DriveLetter%\8585485\[FOLDER NAME]s.exe
Next, the worm attempts to spread through the following instant messaging applications:
- GTALK - Google Talk
- ICQ
- MSN
- PALTALK
- SKYPE
- XFIRE
- YAHOO
It sends the following messages to all contacts in the IM clients along with a link pointing to a copy of the worm:
- mira esta fotografa :D [LINK TO A COPY OF THE WORM]
- seen this?? :D [LINK TO A COPY OF THE WORM]
- This is the funniest photo ever! [LINK TO A COPY OF THE WORM]
- olhar para esta foto :D [LINK TO A COPY OF THE WORM]
- Wie findest du das Foto? [LINK TO A COPY OF THE WORM]
- se ps dette bildet :D [LINK TO A COPY OF THE WORM]
- bekijk deze foto :D [LINK TO A COPY OF THE WORM]
- poglej to fotografijo :D [LINK TO A COPY OF THE WORM]
- pogledaj to slike :D [LINK TO A COPY OF THE WORM]
- titta ps denna bild :D [LINK TO A COPY OF THE WORM]
- pozrite sa na to fotografiu :D [LINK TO A COPY OF THE WORM]
- uita-te la aceasta fotografie :D [LINK TO A COPY OF THE WORM]
- katso tStS kuvaa :D [LINK TO A COPY OF THE WORM]
- bu resmi bakmak :D [LINK TO A COPY OF THE WORM]
- spojrzec na to zdjecie :D [LINK TO A COPY OF THE WORM]
- nTzd meg a kTpet :D [LINK TO A COPY OF THE WORM]
- ser ps dette billede :D [LINK TO A COPY OF THE WORM]
- podfvejte se na mou fotku :D [LINK TO A COPY OF THE WORM]
- guardare quest'immagine :D [LINK TO A COPY OF THE WORM]
- regardez cette photo :D [LINK TO A COPY OF THE WORM]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":