When the Trojan is executed, it copies itself as the following file:
%UserProfile%\Application Data\[FILE NAME].exe
File name is one of the following:
- adobeflash.exe
- desktop.exe
- dwm.exe
- java.exe
- jucheck.exe
- jusched.exe
- win-firewall.exe
The Trojan then creates the following registry entry so that it runs every time Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[FILE NAME]" = "%UserProfile%\Application Data\[FILE NAME].exe"
Next, the Trojan creates the following mutex:
Had3yghhuju98gggd9G6790hfv3.4
It then collects the following information and sends it to a remote location:
- Computer name
- Path of threat
- System volume/serial number
- Version of threat
The Trojan also enumerates the running processes on the compromised computer and sends statistics to a remote location.
Statistics on the following processes are not recorded:
- adobeflash.exe
- chrome.exe
- crss.exe
- desktop.exe
- devenv.exe
- dwm.exe
- explorer.exe
- firefox.exe
- iexplore.exe
- java.exe
- jucheck.exe
- jusched.exe
- pidgin.exe
- skype.exe
- sms.exe
- steam.exe
- svchost.exe
- thunderbird.exe
- win-firewall.exe
- wininit.exe
The preceding information is sent to one or more of the following remote locations:
- 208.98.63.228/forum/login.php
- someligeoas.com/whynot/sam.php
- uipoqworkas.com/whynot/sam.php
The Trojan may also download updates of itself if necessary.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":