English
Deutsch
Français
Español
Italiano
Home
Virus Info
TR/PSW.Lmir.art
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
TechBlog
TR/PSW.Lmir.art - Trojan
See also
Summary
Full description
Statistics
How would you rate this information?
Worthless
Excellent
Virus:
TR/PSW.Lmir.art
Date discovered:
20/02/2006
Type:
Trojan
In the wild:
No
Reported Infections:
Low
Distribution Potential:
Low
Damage Potential:
Medium
Static file:
Yes
File size:
17.721 Bytes
MD5 checksum:
67f583cb9d699b581fde383c48af46bc
VDF version:
6.33.01.07
- Mon, 20 Feb 2006 08:28 (GMT+1)
General
Method of propagation:
• No own spreading routine
Alias:
• Kaspersky: Trojan-PSW.Win32.Lmir.art
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003
Side effects:
• Disable security applications
• Lowers security settings
• Registry modification
• Steals information
Files
It copies itself to the following location:
•
%SYSDIR%
\winser.exe
It deletes the initially executed copy of itself.
The following files are created:
–
%WINDIR%
\vbarun.dll This is a non malicious text file with the following content:
• [Shutdown]
T=
M=
D=
W=
–
%SYSDIR%
\GroupPolicy\Machine\Scripts\scripts.ini This is a non malicious text file with the following content:
• [Shutdown]
0CmdLine=
%SYSDIR%
\winser.exe
0Parameters=AVP
Registry
The following registry key is added in order to run the process after reboot:
– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
Run]
• KernelCheck =
%SYSDIR%
\winser.exe
The following registry key is added:
– [HKLM\SOFTWARE\wSkysoft]
Process termination
List of processes that are terminated:
• assistse.exe; kregex.exe; trojdie.kxp; kvsrvxp.exe; kvmonxp.kxp;
frogagent.exe; kvxp.kxp; ccenter.exe; ravmond.exe; ravmon.exe;
rfwmain.exe; rfwsrv.exe; kpfwsvc.exe; kavpfw.exe; kavstart.exe;
kmailmon.exe; kwatch.exe; avp.exe; kav.exe; kavsvc.exe; rtvscan.exe;
ccsetmgr.exe; defwatch.exe; ccevtmgr.exe; ccapp.exe; mcshield.exe;
mcvsescn.exe; mcdetect.exe; mcmnhdlr.exe; trojanwall.exe;
fygtcleaner.exe; mantispm.exe; vsmon.exe; isafe.exe; zlclient.exe;
pcclient.exe; pcctlcom.exe; tmpfw.exe; tmntsrv.exe; tmproxy.exe;
pccguide.exe; iparmor.exe; xfilter.exe; filmsg.exe; avengine.exe;
pavsrv51.exe; psimsvc.exe; pavprsrv.exe; tpsrv.exe; pavprsrv.exe;
apvxdwin.exe; srvload.exe; webproxy.exe
List of services that are disabled:
• KVSrvXP; KVWSC; RsCCenter; RsRavMon; RfwService; KWatchSvc; KPfwSvc;
AVP; kavsvc; McTskshd.exe; McDetect.exe; CAISafe; vsmon; Tmntsrv;
PcCtlCom; TmPfw; tmproxy; pmshellsrv; PAVSRV; PAVFNSVR; PSIMSVC;
PNMSRV; PavPrSrv; TPSrv
Backdoor
Sends information about:
• Cached passwords
• Computer name
• Users' local activity
• Information about the Windows operating system
File details
Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
• FSG
See a brief description
here
.
Description inserted by Andrei Gherman on Fri, 24 Feb 2006 14:29 (GMT+1)
Description updated by Andrei Gherman on Mon, 27 Feb 2006 08:36 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
TR/Crypt.XPACK.Gen
HEUR/HTML.Malware
HTML/Infected.WebPage.Gen
ADSPY/AdSpy.Gen
HTML/Crypted.Gen
W32/Induc.Gen
TR/ATRAPS.Gen2
TR/Click.Yabector.8857.2
TR/PSW.Magania.auv
TR/Dldr.Bredolab.AX
Get comfortable up to the minute info from Avira as
Detects and removes distinct malware and its variants.
Download here
Click
here
to get the panel...
© 2009 Avira GmbH
Copyright
|
Privacy
|
Sitemap
|
Feedback
|
Imprint
|
FAQ
|
Contact