Content
Generic.dx!toj
- Type
- Trojan
- SubType
- Generic
- Discovery Date
- 08/28/2010
- Length
- Varies
- Minimum DAT
- 6088 (08/28/2010)
- Updated DAT
- 6545 (11/29/2011)
- Minimum Engine
- 5.3.00
- Description Added
- 08/28/2010
- Description Modified
- 09/03/2010 6:30 AM (PT)
Tab Navigation
Characteristics
When executed, the Trojan drops the following files:
- %Appdata%\lbisov.exe [Hidden] [Detected as Generic.dx!tqg]
- %Appdata%\ozzfhv.exe [Hidden] [Detected as W32/Rimecud]
- %Temp%\064.exe [Detected as W32/Rimecud]
- %Temp%\187.exe [Detected as Generic.dx!tqg]
- %Temp%\7961204.exe [Detected as Generic.dx!tqq]
- %Temp%\87249.exe [Detected as Generic.dx!tqj]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\8WEL7ODI\brent[1].exe [Detected as Generic.dx!tqj]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\24[1].exe [Detected as W32/Rimecud]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\kristijan[1].exe [Detected as Generic.dx!tqg]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\JWHQEFD2\icq600[1].exe [Detected as Generic.dx!tqq]
- [Removable Drive]:\MENINIKO\netreba.exe [ Detected as Generic.dx!tqg]
This trojan also attempts to create an autorun.inf file on the root any accessible disk volumes:
The file "AutoRun.inf" is pointing to the malware binary executable. When the removable or networked drive is accessed from a machine supporting the Autorun feature, the malware is launched automatically.
The following registry key has been added to the system.
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic\6.0
The following registry value has been added.
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\]
“Taskman” = "%Appdata%\ozzfhv.exe"
The above mentioned registry ensures that, the malware binary registers itself with the compromised system and execute itself upon every boot.
This Trojan injects itself into the explorer.exe and connects to the site sand[Removed]haonica.com through a remote port 49000.
Symptoms
- Presence of above mentioned files and registry keys.
- Presence unexpected network connection to the above mentioned IP Address.
Method of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Removal
All Users:
Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:
2.Update to current engine and DAT files for detection and removal.
3.Run a complete system scan.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
1. Please go to the Microsoft Recovery Console and restore a clean MBR.
On windows XP:
Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
On Windows Vista and 7:
Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
Variants
Variants
N/A
All Information
Overview -
This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
File Information
- MD5 - 7B5E472033CA5E0BE4370F7CA63A6123
- SHA - 342BBFE9E4559F9874F0C3522D8FDE5576156C5A
Aliases
- Kaspersky - P2P-Worm.Win32.Palevo.fuc
- Microsoft - Trojan:Win32/Malagent
- NOD32 - a variant of Win32/Peerfrag.HD
- Symantec - W32.Pilleuz!gen5
Characteristics
Characteristics -
When executed, the Trojan drops the following files:
- %Appdata%\lbisov.exe [Hidden] [Detected as Generic.dx!tqg]
- %Appdata%\ozzfhv.exe [Hidden] [Detected as W32/Rimecud]
- %Temp%\064.exe [Detected as W32/Rimecud]
- %Temp%\187.exe [Detected as Generic.dx!tqg]
- %Temp%\7961204.exe [Detected as Generic.dx!tqq]
- %Temp%\87249.exe [Detected as Generic.dx!tqj]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\8WEL7ODI\brent[1].exe [Detected as Generic.dx!tqj]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\24[1].exe [Detected as W32/Rimecud]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\I65VJICG\kristijan[1].exe [Detected as Generic.dx!tqg]
- %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\JWHQEFD2\icq600[1].exe [Detected as Generic.dx!tqq]
- [Removable Drive]:\MENINIKO\netreba.exe [ Detected as Generic.dx!tqg]
This trojan also attempts to create an autorun.inf file on the root any accessible disk volumes:
The file "AutoRun.inf" is pointing to the malware binary executable. When the removable or networked drive is accessed from a machine supporting the Autorun feature, the malware is launched automatically.
The following registry key has been added to the system.
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Visual Basic\6.0
The following registry value has been added.
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\]
“Taskman” = "%Appdata%\ozzfhv.exe"
The above mentioned registry ensures that, the malware binary registers itself with the compromised system and execute itself upon every boot.
This Trojan injects itself into the explorer.exe and connects to the site sand[Removed]haonica.com through a remote port 49000.
Symptoms
Symptoms -
- Presence of above mentioned files and registry keys.
- Presence unexpected network connection to the above mentioned IP Address.
Method of Infection
Method of Infection -
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Removal -
Removal -
All Users:
Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:
2.Update to current engine and DAT files for detection and removal.
3.Run a complete system scan.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
1. Please go to the Microsoft Recovery Console and restore a clean MBR.
On windows XP:
Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
On Windows Vista and 7:
Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
Variants
Variants -
N/A