TROJ_DLOAD.ZQKA
TrojanDownloader:Win32/Harnig.S (Microsoft); Packed.Win32.Krap.ao (Kaspersky)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan may be downloaded from remote sites by other malware.
It uses common file icons to trick a user into thinking that the files are legitimate.
It connects to a website to send and receive information.
It deletes itself after execution.
TECHNICAL DETAILS
Arrival Details
This Trojan may be downloaded from remote site(s) by the following malware:
- WORM_AUTORUN.GKD
It may be downloaded from the following remote sites:
- http://www.{BLOCKED}btown.com/dohk/dope.exe
Installation
This Trojan uses common file icons to trick a user into thinking that the files are legitimate.
It stays memory-resident by injecting codes into the following processes:
- svchost.exe
Backdoor Routine
This Trojan connects to the following websites to send and receive information:
- http://{BLOCKED}.{BLOCKED}.252.245
As of this writing, the said sites are inaccessible.
Other Details
This Trojan deletes itself after execution.
SOLUTION
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 3
Scan your computer with your Trend Micro product and note files detected as TROJ_DLOAD.ZQKA
Step 4
Restart in Safe Mode
Step 5
Search and delete the file detected as TROJ_DLOAD.ZQKA
Did this description help? Tell us how we did.