live casino online

TROJ_FAKEVIME.AB

February 16, 2010
 Analysis by: adel

 PLATFORM:

Windows 98, Windows ME, Windows NT, Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW


This Trojan has received attention from independent media sources and/or other security firms.

To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be downloaded by other malware/grayware/spyware from remote sites. It may be unknowingly downloaded by a user while visiting malicious websites.

It executes downloaded files whose malicious routines are exhibited by the affected system.

  TECHNICAL DETAILS

File Size:

189,440 bytes

File Type:

PE

Memory Resident:

No

Initial Samples Received Date:

16 Feb 2010

Payload:

Downloads files

Arrival Details

This Trojan may be downloaded by other malware/grayware/spyware from remote sites.

It may be unknowingly downloaded by a user while visiting malicious websites.

Download Routine

This Trojan accesses the following websites to download files:

  • http://{BLOCKED}system.in/index.php?controller=microinstaller&abbr=SAV&setupType=xp&ttl=21105299546&pid=
  • http://{BLOCKED}dsystem.in/index.php?controller=mic oinstaller&abbr=SAV&setupType=xp&ttl=21105189b9a&pid=

live casino online detects the dowloaded file as:

  • TROJ_FAKEAL.SMDP

It executes downloaded files :

    whose malicious routines are exhibited by the affected system.

      SOLUTION

    Minimum Scan Engine:

    9.200

    FIRST VSAPI PATTERN FILE:

    6.852.06

    FIRST VSAPI PATTERN DATE:

    16 Feb 2010

    VSAPI OPR PATTERN File:

    6.853.00

    VSAPI OPR PATTERN Date:

    16 Feb 2010

    Step 1

    For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.

    Step 2

    Remove malware files dropped/downloaded by TROJ_FAKEVIME.AB