TROJ_FACKED.SM1
Mcafee : W32/Bamital.e; Microsoft : Trojan:Win32/Bamital.I
Windows 2000, XP, Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan uses common file icons to trick a user into thinking that the files are legitimate.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
It deletes itself after execution.
TECHNICAL DETAILS
75,776 bytes
PE
No
24 Dec 2010
Installation
This Trojan drops the following files:
- %System%\kb.dll - detected as TROJ_SHUTDWNR.DZ
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Its DLL component is injected to the following process(es):
- explorer.exe
It uses common file icons to trick a user into thinking that the files are legitimate.
Dropping Routine
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Other Details
This Trojan deletes itself after execution.