Content

Generic.dx!toj

Type
Trojan
SubType
Generic
Discovery Date
08/28/2010
Length
Varies
Minimum DAT
6088 (08/28/2010)
Updated DAT
6545 (11/29/2011)
Minimum Engine
5.3.00
Description Added
08/28/2010
Description Modified
09/03/2010 6:30 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

When executed, the Trojan drops the following files:

  • %Appdata%\lbisov.exe [Hidden] [Detected as Generic.dx!tqg]
  • %Appdata%\ozzfhv.exe [Hidden] [Detected as W32/Rimecud]
  • %Temp%\064.exe [Detected as W32/Rimecud]
  • %Temp%\187.exe [Detected as Generic.dx!tqg]
  • %Temp%\7961204.exe [Detected as Generic.dx!tqq]
  • %Temp%\87249.exe [Detected as Generic.dx!tqj]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\8WEL7ODI\brent[1].exe [Detected as Generic.dx!tqj]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\24[1].exe [Detected as W32/Rimecud]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\kristijan[1].exe [Detected as Generic.dx!tqg]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\JWHQEFD2\icq600[1].exe [Detected as Generic.dx!tqq]
  • [Removable Drive]:\MENINIKO\netreba.exe [ Detected as Generic.dx!tqg]

This trojan also attempts to create an autorun.inf file on the root any accessible disk volumes:

The file "AutoRun.inf" is pointing to the malware binary executable. When the removable or networked drive is accessed from a machine supporting the Autorun feature, the malware is launched automatically.

The following registry key has been added to the system.

  • HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic
  • HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic\6.0

The following registry value has been added.

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\]
    “Taskman” = "%Appdata%\ozzfhv.exe"

The above mentioned registry ensures that, the malware binary registers itself with the compromised system and execute itself upon every boot.

This Trojan injects itself into the explorer.exe and connects to the site sand[Removed]haonica.com through a remote port 49000.

Symptoms

  • Presence of above mentioned files and registry keys.
  • Presence unexpected network connection to the above mentioned IP Address.

Method of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

Removal

All Users:

Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:

1.Disable System Restore .

2.Update to current engine and DAT files for detection and removal.

3.Run a complete system scan.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

1. Please go to the Microsoft Recovery Console and restore a clean MBR.

On windows XP:

Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.


On Windows Vista and 7:

Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.

Variants

Variants

    N/A

All Information

Overview -

This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

File Information

  • MD5  -  7B5E472033CA5E0BE4370F7CA63A6123
  • SHA  - 342BBFE9E4559F9874F0C3522D8FDE5576156C5A

Aliases

  • Kaspersky - P2P-Worm.Win32.Palevo.fuc
  • Microsoft  - Trojan:Win32/Malagent
  • NOD32    - a variant of Win32/Peerfrag.HD
  • Symantec - W32.Pilleuz!gen5

Characteristics

Characteristics -

When executed, the Trojan drops the following files:

  • %Appdata%\lbisov.exe [Hidden] [Detected as Generic.dx!tqg]
  • %Appdata%\ozzfhv.exe [Hidden] [Detected as W32/Rimecud]
  • %Temp%\064.exe [Detected as W32/Rimecud]
  • %Temp%\187.exe [Detected as Generic.dx!tqg]
  • %Temp%\7961204.exe [Detected as Generic.dx!tqq]
  • %Temp%\87249.exe [Detected as Generic.dx!tqj]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\8WEL7ODI\brent[1].exe [Detected as Generic.dx!tqj]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\24[1].exe [Detected as W32/Rimecud]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\kristijan[1].exe [Detected as Generic.dx!tqg]
  • %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\JWHQEFD2\icq600[1].exe [Detected as Generic.dx!tqq]
  • [Removable Drive]:\MENINIKO\netreba.exe [ Detected as Generic.dx!tqg]

This trojan also attempts to create an autorun.inf file on the root any accessible disk volumes:

The file "AutoRun.inf" is pointing to the malware binary executable. When the removable or networked drive is accessed from a machine supporting the Autorun feature, the malware is launched automatically.

The following registry key has been added to the system.

  • HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic
  • HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic\6.0

The following registry value has been added.

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\]
    “Taskman” = "%Appdata%\ozzfhv.exe"

The above mentioned registry ensures that, the malware binary registers itself with the compromised system and execute itself upon every boot.

This Trojan injects itself into the explorer.exe and connects to the site sand[Removed]haonica.com through a remote port 49000.

Symptoms

Symptoms -

  • Presence of above mentioned files and registry keys.
  • Presence unexpected network connection to the above mentioned IP Address.

Method of Infection

Method of Infection -

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

Removal -

Removal -

All Users:

Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:

1.Disable System Restore .

2.Update to current engine and DAT files for detection and removal.

3.Run a complete system scan.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

1. Please go to the Microsoft Recovery Console and restore a clean MBR.

On windows XP:

Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.


On Windows Vista and 7:

Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.

Variants

Variants -

    N/A