When the Trojan is executed, it creates the following files:
- %System%\ns2dos.exe
- %System%\ns2dos
- %System%\ns6dos.exe
- %System%\ns6dos
- %System%\ns7dos.exe
- %System%\ns7dos
- %System%\nsdos2.exe
- %System%\nsdos2
Next, the Trojan creates the following registry entries so that it executes whenever Windows starts:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"nsdos-debugg" = "[HEXADECIMAL CHARACTERS]"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"msdos-debug" = "[HEXADECIMAL CHARACTERS]"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"msdos-debug2" = "[HEXADECIMAL CHARACTERS]"
It also creates the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\[RANDOM CLSID]\"StubPath" = "[HEXADECIMAL CHARACTERS]"
The Trojan then records keystrokes on the compromised computer.
It then sends the gathered information to one of the following remote locations:
- 193.111.200.206
- 212.19.35.101
- 212.19.37.90
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":