This threat may be downloaded on to the computer by the following Trojan:
Downloader
When the Trojan is executed, it encrypts all files that do not have the following strings in their file path location:
- krecycle
- local settings
- program files
- programdata
- ravbin
- windows
Next, it encrypts any files that have the following file extensions:
- .7z
- .asp
- .aspx
- .bas
- .c
- .cpp
- .cs
- .frm
- .go
- .gz
- .iso
- .java
- .jpg
- .jsp
- .pas
- .php
- .pl
- .png
- .psd
- .py
- .rar
- .rb
- .vb
- .zip
The Trojan also encrypts files that contain the following strings in the file extension:
- 111
- doc
- drw
- dw
- dx
- grp
- mce
- mcg
- mdb
- pag
- pdf
- pic
- ppt
- rpl
- sh
- win
- wvw
- xls
It then encrypts all files on fixed disk drives and all files that have a size between 400 and 209,715,200 bytes.
The Trojan uses the Blowfish algorithm to encrypt the files.
The initial key for the algorithm is saved in the following location:
D:\nepia.dud
Alternatively, the Trojan may generate a number of random capital letters 40 bytes in length for the initial key.
The Trojan stores the encrypted file names in the following location:
%Temp%\vxsur.bin
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":