Technical Details
This Trojan downloads files from the Internet and launches them without the user's knowledge. It is a Java class file. It is 6335 bytes in size.
Payload
The malware is a component of a Trojan downloader from the "Trojan-Downloader.Java.OpenConnection" family and includes a class file named "monoid", which downloads a file from the Internet, from a link sent to it, and launches the downloaded file for execution. The downloaded file is saved in the current user's temporary files directory as
%Temp%\<rnd>.exe
where
The Trojan constitutes a Java applet. It is launched from an infected HTML page using an "<APPLET>" tag, for which an encrypted link to a downloadable file is sent in parameter named "dskvnds".
As well as the above-mentioned class file, the Trojan contains "reverberator" and "partizano" class files. The "reverberator" class file includes "lopiyo" function, which is used to decrypt the link to a downloadable file. The "partizano" class file contains a code designed to exploit a vulnerability (CVE-2010-0840).
Removal instructions
If your computer does not have antivirus protection and has been infected by this malicious program, follow the instructions below to delete it:
- Update Sun Java JRE and JDK to the latest versions.
- Delete the following file:
%Temp%\<rnd>.exe
- Empty the Temporary Internet Files directory, which may contain infected files (see How to delete infected files from Temporary Internet Files folder?).
%Temporary Internet Files%
Žádné komentáře:
Okomentovat