When the Trojan is executed, it creates the following files:
- %Windir%\twexx32.dll
- %UserProfile%\Application Data\1c3mi6lobytdgsfa.dat
- %UserProfile%\Application Data\0g4zaq903f25wwj2.dat
The Trojan then replaces the following file with a copy of itself:
%Windir%\explorer.exe
The original explorer.exe file is copied to the following location:
%Windir%\twexx32.dll
The Trojan also modifies the following files:
- %System%\dllcache\explorer.exe
- %UserProfile%\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
Next, the Trojan locks the computer and displays a message claiming that the computer has been locked by the authorities, and that the user needs to pay a fee to have the computer unlocked. The message displayed varies depending on the country that the computer resides in.
The Trojan attempts to contact the following URL to determine the geographical location of the computer:
[http://]tools.ip2location.com/ib2/
It may also steal information from the computer and upload it to the following remote locations:
- [http://]cndroaayghmf.com/de/2/gate.php
- [http://]xmeplogvybzr.com/gate.php
- [http://]xjwsmvrpeprt.ru/gate.php
- [http://]fwhgxivtfrgq.com/gate.php
- [http://]sxnykimafhbj.com/gate.php
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":