Analysis by: adel

 PLATFORM:

Windows 98, Windows ME, Windows NT, Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Trojan has received attention from independent media sources and/or other security firms.

To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be downloaded by other malware/grayware/spyware from remote sites. It may be unknowingly downloaded by a user while visiting malicious websites.

It executes downloaded files whose malicious routines are exhibited by the affected system.

  TECHNICAL DETAILS

File Size: 189,440 bytes
File Type: PE
Memory Resident: No
Initial Samples Received Date: 16 Feb 2010
Payload: Downloads files

Arrival Details

This Trojan may be downloaded by other malware/grayware/spyware from remote sites.

It may be unknowingly downloaded by a user while visiting malicious websites.

Download Routine

This Trojan accesses the following websites to download files:

  • http://{BLOCKED}system.in/index.php?controller=microinstaller&abbr=SAV&setupType=xp&ttl=21105299546&pid=
  • http://{BLOCKED}dsystem.in/index.php?controller=mic oinstaller&abbr=SAV&setupType=xp&ttl=21105189b9a&pid=

live casino online detects the dowloaded file as:

  • TROJ_FAKEAL.SMDP

It executes downloaded files :

    whose malicious routines are exhibited by the affected system.

      SOLUTION

    Minimum Scan Engine: 9.200
    FIRST VSAPI PATTERN FILE: 6.852.06
    FIRST VSAPI PATTERN DATE: 16 Feb 2010
    VSAPI OPR PATTERN File: 6.853.00
    VSAPI OPR PATTERN Date: 16 Feb 2010

    Step 1

    For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

    Step 2

    Remove malware files dropped/downloaded by TROJ_FAKEVIME.AB