When the Trojan is executed, it creates the following files:
- %Temp%\FlashPlayInstall.exe
- %SystemDrive%\ProgramData\ATS.exe
- %SystemDrive%\ProgramData\Interop.HyCam2.dll
- %SystemDrive%\ProgramData\Rar.exe
- %SystemDrive%\ProgramData\WindowsUpdater.exe
It also drops the following files, which are files associated with screen recording software:
- %ProgramFiles%\HyCam2\CamRes2.dll
- %ProgramFiles%\HyCam2\HyCam2.exe
- %ProgramFiles%\HyCam2\MClick2.dll
The Trojan then creates the following registry entries so that it runs every time Windows starts:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Windows Updater" = "%SystemDrive%\ProgramData\WindowsUpdater.exe"
- HKEY_CLASSES_ROOT\CLSID\[CLSID]\LocalServer32\"(Default)" = "%ProgramFiles%\HyCam2\HyCam2.exe"
Next, it creates the following registry entries:
- HKEY_CURRENT_USER\Software\Hyperionics\HyperCam 2\State\"Status" = "1"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"Transparency" = "1"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"QuickCompress" = "0"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"Scalability" = "0"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"EnabledAccessKey" = "0"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"AccessKey" = "0"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"MinViewportHeight" = "0"
- HKEY_CURRENT_USER\Software\Intel\Indeo\5.0\"MinViewportWidth" = "0"
The Trojan then overlays a form on the Web browser window that mimics the browser. The form is displayed when certain banking websites are visited. It then launches screen recording software that records user log in information, which may include any of the following details:
- Account number
- Birth date
- Telephone number
- Pin number
It then sends the captured information to the attacker by FTP or email.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":