When the Trojan is executed, it copies itself to the following location:
%Windir%\iexplorer.exe
The Trojan adds the following run key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"iexplorer" = "C:\WINDOWS\iexplorer.exe"
The Trojan disables the User Account Control (UAC) and Task Manager:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = 0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskmgr" = 1
The Trojan gathers Operating System information and sends it to the following URLs:
- [http://]volratioch.info/admin/toma[REMOVED]
- [http://]k4n0.info/admin/toma[REMOVED]
The Trojan receives data from the above URLs and writes it to the following host file:
%System%\drivers\etc\hosts
The Trojan downloads and executes potentially malicious files from the following URLs:
- [http://]volratioch.info/admin/db/url_d[REMOVED]
- [http://]k4n0.info/admin/db/url_d[REMOVED]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":