This Trojan may be downloaded by clicking links on any of the following domains:
aqua11freesex.info
aqua12freesex.info
aqua1freesex.info
aqua2freesex.info
aqua3freesex.info
aqua4freesex.info
aqua5freesex.info
aqua6freesex.info
aqua7freesex.info
aqua8freesex.info
aqua9freesex.info
avivideo-freak.info
badgirlfuck.info
badgirlsfuck.info
badsexygirls.info
coolsex1-avi.info
coolsex2-avi.info
coolsex3-avi.info
coolsex4-avi.info
coolsex4ever.info
coolsex5-avi.info
coolsex6-avi.info
coolsex7-avi.info
coolsex8-avi.info
coolsex9-avi.info
coolsexcnow.info
coolsexdnow.info
coolsexenow.info
freak-aviporno.info
freak-pornoavi.info
freak-videoavi.info
fuckercoolbaby.info
fuckgirl1free.info
fuckgirl2free.info
fuckgirl3free.info
fuckgirl4free.info
fuckthisgirls4free.info
fuckthisgirlsforfree.info
g00dsexporno.info
g0odsexporn0.info
g0odsexporno.info
go0dsexporno.info
goodsexp0rn0.info
goodsexp0rno.info
goodsexporn0.info
goodsexporno.info
hochutebyafree1.info
hochutebyafree2.info
hochutebyafree3.info
hochutebyafree4.info
hochutebyafree5.info
hochutebyafree6.info
hochutebyafree7.info
hot-avi11video.info
hot-avi12video.info
hot-avi1video.info
hot-avi2video.info
hot-avi3video.info
hot-avi4video.info
hot-avi5video.info
hot-avi6video.info
hot-avi7video.info
hot-avi8video.info
hot-avi9video.info
megaaarchiveporno.info
megabarchiveporno.info
megacarchiveporno.info
megadarchiveporno.info
megaearchiveporno.info
megafarchiveporno.info
megapornobesplatno4u.info
pornosexababy.info
realpornovideoarolik.info
realpornovideodrolik.info
realpornovideoerolik.info
realpornovideofrolik.info
realpornovideogrolik.info
realpornovideohrolik.info
realpornovideoirolik.info
realpornovideoqrolik.info
realpornovideorrolik.info
realpornovideosrolik.info
realpornovideotrolik.info
realpornovideourolik.info
realpornovideowrolik.info
realpornovideoyrolik.info
super-sexafree.info
super-sexbfree.info
super-sexcfree.info
super-sexdfree.info
super-sexefree.info
super-sexffree.info
super-sexgfree.info
super-sexhfree.info
super-sexjfree.info
super-sexkfree.info
teenacoolsex.info
teenbcoolsex.info
teenccoolsex.info
verycoolsex.info
When the Trojan is executed, it creates the following file:
%UserProfile%\[TEN RANDOM NUMBERS].exe
Next, it creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[TEN RANDOM NUMBERS]" = "%UserProfile%\[TEN RANDOM NUMBERS].exe"
It also modifies the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%Windir%\system32\userinit.exe, %UserProfile%\[TEN RANDOM NUMBERS].exe"
The Trojan also ends the following process:
Taskman.exe
Next, the computer shuts down.
When it restarts, an image is displayed and the user is prompted to send a premium-rate SMS to receive an unlock code, which must then be entered in to a text field in order to unlock the computer.
The Trojan attempts to prevent any other interaction with the computer until the following unlock code is entered:
SVADBA
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":