| Detection added |
Oct 04 2007 21:04 GMT |
| Update released |
Oct 04 2007 21:45 GMT |
| Description added |
Oct 06 2008 |
| Behavior |
Trojan |
This Trojan has a malicious payload. The program itself is a Windows PE DLL
file. It is approximately 100KB in size.
Installation
The Trojan copies its executable file to the Windows system directory:
%System%\mstmdm.dll
In order to ensure that the Trojan is launched automatically each time the
system is booted, the Trojan adds a link to its executable file in the system
registry:
[HKLM\Software\Classes\CLSID\{E4D629C3-78D3-4597-AE36-CC394E39F934}\InprocServer32]
"default" = "%System%\mstmdm.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"UpdateCheck" = {E4D629C3-78D3-4597-AE36-CC394E39F934}
The Trojan also creates the following registry key, and save its configuration
to this key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\StrtdCfg]
The Trojan also creates the following files:
%WinDir%\1.txt
%System%\__1.dat
%WinDir%\system32\mswmpdat.tlb
%WinDir%\system32\winview.ocx
The Trojan gets network configuration via the following link:
http://livenews.*****.cx/update
It then modifies the DNS addresses of the current active connection to those
it received from the network.
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Use Task
Manager to terminate the malicious program’s process.
- Delete the original Trojan file (the location will depend on how the program
originally penetrated the victim machine).
- Delete the following system
registry key parameter values:
[HKLM\Software\Classes\CLSID\{E4D629C3-78D3-4597-AE36-CC394E39F934}\InprocServer32]
"default" = "%System%\mstmdm.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"UpdateCheck" = {E4D629C3-78D3-4597-AE36-CC394E39F934}
- Delete the following registry key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\StrtdCfg]
- Delete the following files:
%WinDir%\1.txt
%System%\__1.dat
%WinDir%\system32\mswmpdat.tlb
%WinDir%\system32\winview.ocx
%System%\mstmdm.dll
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).