TROJ_INJECT.BWZ
Trojan.Win32.Agent.tmhv (Kaspersky), Gen:Variant.Zusy.4398 (Bitdefender)
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
Dropped by other malware
This Trojan attempts to replace a system file with a copy of itself. This results to the crash of the affected computer.
This Trojan may be dropped by other malware.
It deletes itself after execution.
TECHNICAL DETAILS
29,696 bytes
Yes
24 Aug 2012
Modifies files
Arrival Details
This Trojan may be dropped by the following malware:
- TROJ_ARTIEF.BWZ
Installation
This Trojan drops the following copies of itself into the affected system and executes them:
- %System%\lsass.exe
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
lsass.exe = %System%\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\Session Manager
PendingFileRenameOperations = @\??\%System%\@%System%\lsass.exe.tmp
Other Details
This Trojan deletes itself after execution.
NOTES:
This Trojan attempts to replace the system file %System%\lsass.exe with a copy of itself. This results to the crash of the affected computer.
SOLUTION
9.200
9.346.08
24 Aug 2012
9.347.00
25 Aug 2012
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.
Step 2
Remove malware files dropped/downloaded by TROJ_INJECT.BWZ