| Detection added |
Sep 25 2007 23:29 GMT |
| Update released |
Sep 26 2007 01:00 GMT |
| Description added |
Oct 20 2008 |
| Behavior |
TrojanDownloader |
This Trojan downloads another malicious program via the Internet and launches
it on the victim machine without the user’s knowledge or consent. It
is a Windows PE EXE file. It is 133120 bytes in size.
Installation
When launched, the Trojan copies its executable file to the Windows root directory:
%WinDir%\iexplorer.exe
In order to ensure that the Trojan is launched automatically each time the
system is booted, the Trojan adds a link to its executable file in the system
registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IE" = "%WinDir%\iexplorer.exe"
The Trojan adds a rule to Windows Firewall which permits any network activity
caused by the malicious process.
The Trojan downloads files from the following URLs:
http://www.site*****.com/top7_1.gif
http://www.site*****.com/top7_2.gif
http://www.sugo*****.kr/bbs/icon/private_name/top7_1.gif
http://www.sugo*****.kr/bbs/icon/private_name/top7_2.gif
At the moment of writing, these links were not working.
Downloaded files will be saved as:
C:\Documents and Settings\All Users\winsql.dat
C:\Documents and Settings\All Users\DirectX.aud
C:\Documents and Settings\All Users\services.exe
C:\Documents and Settings\All Users\comctl64.dll
Once successfully downloaded, the files will be launched for execution.
The Trojan also opens the following link without the user’s knowledge
or consent.
http://pag*****.terra.com.br/arte/sonhosepoemas/paixao/cartao059.htm
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Use Task
Manager to terminate the malicious program’s process.
- Delete the original Trojan file (the location will depend on
how the program originally penetrated the victim machine).
- Delete the following system
registry key parameter:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IE" = "%WinDir%\iexplorer.exe"
- Delete the following files:
%WinDir%\iexplorer.exe
C:\Documents and Settings\All Users\winsql.dat
C:\Documents and Settings\All Users\DirectX.aud
C:\Documents and Settings\All Users\services.exe
C:\Documents and Settings\All Users\comctl64.dll
- Update your antivirus databases and perform a full scan of the
computer (download a trial version of Kaspersky Anti-Virus).