TROJ_LAMEWAR.VTG

 Analysis by: Cris Nowell Pantanilla

 PLATFORM:

Windows 98, ME, NT, 2000, XP, Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives as a file that exports the functions of other malware/grayware. It arrives as a component bundled with malware/grayware packages.

It requires its main component to successfully perform its intended routine.

  TECHNICAL DETAILS

File Size:

36,864 bytes

File Type:

DLL

Memory Resident:

Yes

Arrival Details

This Trojan arrives as a file that exports the functions of other malware/grayware.

It arrives as a component bundled with malware/grayware packages.

Other Details

Based on analysis of the codes, it has the following capabilities:

  • It terminates the following processes if found running in the affected system's memory: BatMgr.exe, BKHost.exe, BKTask.exe, cmd.exe, CreDecod.exe, Decod.lst, DfrgFat.exe, DfrgNtfs.exe, DogsRun.exe, EcAuto.exe, EmgDecod.exe, EmgSeP.exe, EmgSePs.exe, F-agntnt.exe, F-protnt.exe, Findfast.exe, fixmapi.exe, FM1_lc.exe, FM1_sc.exe, FM1_ss.exe, FM1l.exe, FM1s.exe, FM1SSt.exe, FMReset.exe, FMSETSC.exe, FMUninst.exe, FMWatch.exe, Fpwm32.dll, Gather.exe, HkStrtr.exe, Kernel32.dll, mapisp32.exe, McShield.exe, MSASCui.exe, MSGSRV32.EXE, msiexec.exe, navw32.exe, navwnt.exe, nbagnt95.exe, NDETECT.exe, nhldaemn.exe, NTVDM.EXE, Prosp.dll, rds.exe, Regsvr32.exe, RmvSrvce.exe, RunDll.exe, RunDll32.exe, SCAtCode.exe, SCAuto.exe, SCCapcel.exe, SCMState.exe, SCMUnist.exe, SCOutPut.exe, SD32.exe, sep_c.exe, sep_s.exe, SePUnist.exe, SePVerup.exe, SetAdmin.exe, setup.exe, setup_wm.exe, Supdate.exe, SysTray.exe, talkback.exe, taskeng.exe, update.exe, userinit.exe, WinMgmt.exe, WLPtlFil.exe, WLTlsPxy.exe, WSCCapsl.exe.

It requires its main component to successfully perform its intended routine.

  SOLUTION

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product and note files detected as TROJ_LAMEWAR.VTG

Step 3

Restart in Safe Mode

[ Learn More ]


Did this description help? Tell us how we did.

Related Malware