When the Trojan is executed, it creates the following files:
- %Temp%\f[FIVE RANDOM NUMBERS]5.dat
- %Temp%\f[THREE RANDOM NUMBERS].dat
- %Temp%\system_001.dmp
It also creates one of the following files:
- %System%\msupmgr.dll
- %System%\wuaucli.dll
- %System%\mspatch.dll
- %System%\advpacket.dll
- %System%\mscmmc.dll
This file will then modify one of the following files:
- %System%\mspatcha.dll
- %System%\tcpmon.dll
- %System%\spoolss.dll
- %System%\wuaueng.dll
- %System%\mspatcha.dll
- %System%\advpack.dll
- %System%\mscms.dll
It also creates the following file if the compromised computer is running a 64-bit operating system:
%Temp%\VX[FOUR RANDOM NUMBERS].tmp
The Trojan starts one of the following services:
It then modifies the following registry entries related to the service:
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\[SERVICE NAME]\"Start" = "2"
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[SERVICE NAME]\"FailureActions" = "[RANDOM CHARACTERS]"
The Trojan then opens a back door that allows an attacker to perform the following actions:
- Update the client
- Upload and download files
- Open a shell
- Set download and upload speeds
- Shut down or restart the compromised computer
- Add new functionality using a plugin
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":