When the Trojan is executed, it creates the following files:
- %WinDir%\Temp\_$Cf\[TROJAN].docx
- %WinDir%\Temp\_$Cf\[TROJAN].docx
- %WinDir%\Temp\_$Cf\osk.exe
- %System%\WINWORD.exe
- %System%\Com\ctfmoon.exe
The Trojan creates the following registry entries so that it runs every time Windows starts:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"ctfmoon.exe" = "%System%\Com\ctfmoon.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"AUTOWORD" = "%System%\WINWORD.EXE"
The Trojan may then search for .doc and .docx files, encrypt them and add a copy of itself, and then change the filename extension from .doc or .docx to an .exe file extension.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":