All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog



 
Malware Description Search

 

  Home / Viruses / Virus Encyclopedia / Malware Descriptions / Trojan Programs / Trojan Droppers

Trojan-Dropper.MSWord.Lafool.v

Other versions: .h

Detection added Oct 31 2006 08:22 GMT
Description added Nov 01 2006
Behavior TrojanDropper

Technical details

This Trojan is designed to install other Trojan programs to the victim machine without the knowledge or consent of the user. It is a Microsoft Word document contains a macro. The size of the infected Microsoft Word document known to Kaspersky Lab is 205 825 bytes.

Payload

Each time Microsoft Word is launched (AutoExec) and a Microsoft Word format document is opened (AutoOpen and Document_Open), functions from the main Trojan module will be launched.

The Trojan deencrypts strings from the function text, and then saves the resulting file body to the C: root directory to a file called "LS060E5.eXE":

C:\LS060E5.eXE (27 648 bytes)

This file will be detected by Kaspersky Anti-Virus as Trojan-PSW.Win32.LdPinch.bbg.

The file will then be launched for execution.

Removal instructions
  1. Check the C: root directory for a file called “LS060E.eXE” and delete it:
    C:\LS060E5.eXE
  2. Close all Microsoft Office applications.
  3. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com