A multicomponent Trojan that acts as a bot and serves the purpose of sending out spam messages. It is distributed using a dropper. Once the dropper is launched, it extracts a malicious driver and a dynamic library (DLL) from its body. The driver is planted with the %rnd%.sys name (where %rnd% is a name containing from 5 to 15 random characters) into the %SYSTEM%\drivers\ directory and is registered as the “Boot Bus Extender” service. The library, in turn, is injected into the svchost.exe and explorer.exe running processes. If the attempt to load the malicious driver fails, the dropper copies itself to the %TEMP% folder and modifies the system registry to ensure its autorun on system startup.
Once the system becomes infected, BackDoor.BlackEnergy.36 connects to a command and control center and receives from it an XML file. Based on the contents of this file, the Trojan downloads additional modules.