live casino online

TROJ_INJECT.BWZ

October 09, 2012
 Modified by: Jasen Sumalapao

 ALIASES:

Trojan.Win32.Agent.tmhv (Kaspersky), Gen:Variant.Zusy.4398 (Bitdefender)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Dropped by other malware

This Trojan attempts to replace a system file with a copy of itself. This results to the crash of the affected computer.

This Trojan may be dropped by other malware.

It deletes itself after execution.

  TECHNICAL DETAILS

File Size:

29,696 bytes

Memory Resident:

Yes

Initial Samples Received Date:

24 Aug 2012

Payload:

Modifies files

Arrival Details

This Trojan may be dropped by the following malware:

  • TROJ_ARTIEF.BWZ

Installation

This Trojan drops the following copies of itself into the affected system and executes them:

  • %System%\lsass.exe

(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)

Autostart Technique

This Trojan adds the following registry entries to enable its automatic execution at every system startup:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
lsass.exe = %System%\lsass.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\Session Manager
PendingFileRenameOperations = @\??\%System%\@%System%\lsass.exe.tmp

Other Details

This Trojan deletes itself after execution.

NOTES:

This Trojan attempts to replace the system file %System%\lsass.exe with a copy of itself. This results to the crash of the affected computer.

  SOLUTION

Minimum Scan Engine:

9.200

FIRST VSAPI PATTERN FILE:

9.346.08

FIRST VSAPI PATTERN DATE:

24 Aug 2012

VSAPI OPR PATTERN File:

9.347.00

VSAPI OPR PATTERN Date:

25 Aug 2012

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.

Step 2

Remove malware files dropped/downloaded by TROJ_INJECT.BWZ