TROJ_LAMEWAR.VTG
Windows 98, ME, NT, 2000, XP, Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as a file that exports the functions of other malware/grayware. It arrives as a component bundled with malware/grayware packages.
It requires its main component to successfully perform its intended routine.
TECHNICAL DETAILS
36,864 bytes
DLL
Yes
Arrival Details
This Trojan arrives as a file that exports the functions of other malware/grayware.
It arrives as a component bundled with malware/grayware packages.
Other Details
Based on analysis of the codes, it has the following capabilities:
- It terminates the following processes if found running in the affected system's memory: BatMgr.exe, BKHost.exe, BKTask.exe, cmd.exe, CreDecod.exe, Decod.lst, DfrgFat.exe, DfrgNtfs.exe, DogsRun.exe, EcAuto.exe, EmgDecod.exe, EmgSeP.exe, EmgSePs.exe, F-agntnt.exe, F-protnt.exe, Findfast.exe, fixmapi.exe, FM1_lc.exe, FM1_sc.exe, FM1_ss.exe, FM1l.exe, FM1s.exe, FM1SSt.exe, FMReset.exe, FMSETSC.exe, FMUninst.exe, FMWatch.exe, Fpwm32.dll, Gather.exe, HkStrtr.exe, Kernel32.dll, mapisp32.exe, McShield.exe, MSASCui.exe, MSGSRV32.EXE, msiexec.exe, navw32.exe, navwnt.exe, nbagnt95.exe, NDETECT.exe, nhldaemn.exe, NTVDM.EXE, Prosp.dll, rds.exe, Regsvr32.exe, RmvSrvce.exe, RunDll.exe, RunDll32.exe, SCAtCode.exe, SCAuto.exe, SCCapcel.exe, SCMState.exe, SCMUnist.exe, SCOutPut.exe, SD32.exe, sep_c.exe, sep_s.exe, SePUnist.exe, SePVerup.exe, SetAdmin.exe, setup.exe, setup_wm.exe, Supdate.exe, SysTray.exe, talkback.exe, taskeng.exe, update.exe, userinit.exe, WinMgmt.exe, WLPtlFil.exe, WLTlsPxy.exe, WSCCapsl.exe.
It requires its main component to successfully perform its intended routine.
SOLUTION
Step 1
Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.
Step 2
Scan your computer with your Trend Micro product and note files detected as TROJ_LAMEWAR.VTG
Step 3
Restart in Safe Mode
Did this description help? Tell us how we did.