- To ensure its autorun and to spread, the Trojan does the following:
Modifies the following registry keys:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'KB01321295.exe' = '"%APPDATA%\KB01321295.exe"'
- Malicious activities
The Trojan creates and runs the following file:
- %APPDATA%\KB01321295.exe
The following file is also run by the malicious program:
- %WINDIR%\explorer.exe
The Trojan injects the malicious code into
\ctfmon.exe
and a large number of user processes.
- The malware changes the file system as follows:
It creates the following files:
- %APPDATA%\KB01321295.exe
- %TEMP%\exp1.tmp.bat
Then the Trojan removes itself.
Once the malicious code is injected into firefox.exe, iexplore.exe, and explorer.exe, the malware establishes a connection to the remote command and control server over HTTP. Then it gathers information on the current user profile and Firefox and Internet Explorer cookies. The Trojan can execute the following commands:
- Forward requests to the Windows command interpreter
- Upload/download files
- List files residing in a folder
- Search files starting from the specified directory