TROJ_STUXNET.DX
October 08, 2012
PLATFORM:
Windows 98, ME, NT, 2000, XP, Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may arrive bundled with malware packages as a malware component. It may be dropped by other malware.
TECHNICAL DETAILS
File Size:
40,960 bytes
File Type:
DLL
Memory Resident:
Yes
Initial Samples Received Date:
21 Jul 2010
Arrival Details
This Trojan may arrive bundled with malware packages as a malware component.
It may be dropped by other malware.
Other Details
Based on analysis of the codes, it has the following capabilities:
- This .DLL file is loaded by its component file suckme.lnk, a specially crafted link file that takes advantage of a Vulnerability in Windows Shell. Upon successful exploitation of the said vulnerability, this .DLL file sends the following message to the Windows Debugger:
- "SUCKM3 FROM EXPLORER.EXE MOTH4FUCKA #@!"
SOLUTION
Minimum Scan Engine:
8.900
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Scan your computer with your Trend Micro product and note files detected as TROJ_STUXNET.DX
Step 3
Restart in Safe Mode
[ Learn More ]
Did this description help? Tell us how we did.