Analysis by: Christopher Daniel So

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 398,560 bytes
File Type: DLL
Initial Samples Received Date: 06 Mar 2009

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Other Details

This Trojan connects to the following possibly malicious URL:

  • {BLOCKED}-c.net
  • {BLOCKED}eateawebsite.com
  • {BLOCKED}8.cn
  • {BLOCKED}com
  • {BLOCKED}avel.jp
  • {BLOCKED}ng.com
  • {BLOCKED}r7.be
  • {BLOCKED}mic.com
  • {BLOCKED}abels.com
  • {BLOCKED}.com
  • {BLOCKED}g.com
  • {BLOCKED}enture.com
  • {BLOCKED}esstrade.net
  • {BLOCKED}orhotels.com
  • {BLOCKED}see.com
  • {BLOCKED}ive.com
  • {BLOCKED}nn.com
  • {BLOCKED}itz.com
  • {BLOCKED}e.ru
  • {BLOCKED}ost.com
  • {BLOCKED}ltbay.org
  • {BLOCKED}eek.com
  • {BLOCKED}na.com
  • {BLOCKED}ilorama.com
  • {BLOCKED}ru
  • {BLOCKED}.ru
  • {BLOCKED}titcool.com
  • {BLOCKED}china.com.cn
  • {BLOCKED}uality.sk
  • {BLOCKED}aniti.net
  • {BLOCKED}ilal.com
  • {BLOCKED}bris.com
  • {BLOCKED}xixi.com
  • {BLOCKED}yun.com
  • {BLOCKED}iance-networking.com
  • {BLOCKED}over30.com
  • {BLOCKED}uc.org
  • {BLOCKED}y.com
  • {BLOCKED}ari.ru
  • {BLOCKED}erde.net
  • {BLOCKED}teurs-gone-wild.com
  • {BLOCKED}tv.com
  • {BLOCKED}ricangirl.com
  • {BLOCKED}roidadvices.com
  • {BLOCKED}menewsnetwork.com
  • {BLOCKED}ap.info
  • {BLOCKED}com
  • {BLOCKED}wan.com
  • {BLOCKED}mdt.com
  • {BLOCKED}wards.com
  • {BLOCKED}agana.net
  • {BLOCKED}dao.cn
  • {BLOCKED}kier.pl
  • {BLOCKED}.com.cn
  • {BLOCKED}oreitsnews.com
  • {BLOCKED}boon.com
  • {BLOCKED}pegrillo.it
  • {BLOCKED}niaga.com
  • {BLOCKED}camera.com
  • {BLOCKED}ibili.tv
  • {BLOCKED}torrent.com
  • {BLOCKED}goo.com
  • {BLOCKED}gcatalog.com
  • {BLOCKED}gchina.com
  • {BLOCKED}gsome.com
  • {BLOCKED}.co.id
  • {BLOCKED}anza.com
  • {BLOCKED}kingbuddy.com
  • {BLOCKED}langer.fr
  • {BLOCKED}yguestelecom.com
  • {BLOCKED}votv.com
  • {BLOCKED}nto.com
  • {BLOCKED}ther.com
  • {BLOCKED}falo.jp
  • {BLOCKED}ferapp.com
  • {BLOCKED}ldhr.com
  • {BLOCKED}ltwith.com
  • {BLOCKED}ningcamel.com
  • {BLOCKED}-matrix.com
  • {BLOCKED}sub.com
  • {BLOCKED}enaser.com
  • {BLOCKED}paign-archive1.com
  • {BLOCKED}paign-archive2.com
  • {BLOCKED}pediem.fr
  • {BLOCKED}adellibro.com
  • {BLOCKED}top.com
  • {BLOCKED}sus.gov
  • {BLOCKED}on.jp
  • {BLOCKED}tango.com
  • {BLOCKED}apflights.co.uk
  • {BLOCKED}na-sss.com
  • {BLOCKED}codias.com
  • {BLOCKED}epolis.com
  • {BLOCKED}ysex.com
  • {BLOCKED}turk.com
  • {BLOCKED}est.com
  • {BLOCKED}hes.net
  • {BLOCKED}legeboard.org
  • {BLOCKED}-org.biz
  • {BLOCKED}icbookresources.com
  • {BLOCKED}tco.ca
  • {BLOCKED}tcophotocenter.com
  • {BLOCKED}ponmom.com
  • {BLOCKED}lead.com
  • {BLOCKED}veonline.com
  • {BLOCKED}oz.jp
  • {BLOCKED}sschannelmojo.com
  • {BLOCKED}nchyroll.com
  • {BLOCKED}mania.com
  • {BLOCKED}v.com
  • {BLOCKED}erlink.com
  • {BLOCKED}erport.de
  • {BLOCKED}lybooth.com
  • {BLOCKED}ealplay.com
  • {BLOCKED}idicke.com
  • {BLOCKED}idwalsh.name
  • {BLOCKED}og.jp
  • {BLOCKED}inebabe.com
  • {BLOCKED}racaemaisgostoso.org
  • {BLOCKED}irulez.net
  • {BLOCKED}itvforum.net
  • {BLOCKED}motivaciones.es
  • {BLOCKED}tructoid.com
  • {BLOCKED}news.com
  • {BLOCKED}italdesire.com
  • {BLOCKED}ectlyrics.com
  • {BLOCKED}xplanet.com
  • {BLOCKED}ihd.com
  • {BLOCKED}ki.com
  • {BLOCKED}larade.com
  • {BLOCKED}ya-e-eqtesad.com
  • {BLOCKED}para.co.jp
  • {BLOCKED}bledaybookclub.com
  • {BLOCKED}macrazy.net
  • {BLOCKED}co.kr
  • {BLOCKED}y.nl
  • {BLOCKED}osign.com
  • {BLOCKED}llege.com
  • {BLOCKED}hop.com
  • {BLOCKED}.net
  • {BLOCKED}ine.net
  • {BLOCKED}shi.com
  • {BLOCKED}headcafe.com
  • {BLOCKED}althforum.com
  • {BLOCKED}ph.com
  • {BLOCKED}ctions2011.eg
  • {BLOCKED}ch.net
  • {BLOCKED}alatenetwork.net
  • {BLOCKED}ews.com
  • {BLOCKED}.org
  • {BLOCKED}ntful.com
  • {BLOCKED}ang.com
  • {BLOCKED}er.ru
  • {BLOCKED}ert-offers.com
  • {BLOCKED}ilysearch.org
  • {BLOCKED}cy7.com
  • {BLOCKED}tshop.com.br
  • {BLOCKED}tspring.com
  • {BLOCKED}tweb.it
  • {BLOCKED}dage.com
  • {BLOCKED}dblitz.com
  • {BLOCKED}durbrain.com
  • {BLOCKED}esonic.pk
  • {BLOCKED}esonic.pl
  • {BLOCKED}esonic.tw
  • {BLOCKED}dlaw.com
  • {BLOCKED}eartamerica.com
  • {BLOCKED}gerhut.com
  • {BLOCKED}viz.com
  • {BLOCKED}my.cz
  • {BLOCKED}lottery.com
  • {BLOCKED}shgot.net
  • {BLOCKED}xster.com
  • {BLOCKED}xya.com
  • {BLOCKED}ege.de
  • {BLOCKED}erservices.com
  • {BLOCKED}tball365.com
  • {BLOCKED}umophilia.com
  • {BLOCKED}edownload.ir
  • {BLOCKED}nchweb.fr
  • {BLOCKED}shwap.com
  • {BLOCKED}endorfollow.com
  • {BLOCKED}cash.com
  • {BLOCKED}na.com
  • {BLOCKED}jar.com
  • {BLOCKED}uploader.com
  • {BLOCKED}cks.net
  • {BLOCKED}epark.ru
  • {BLOCKED}msham.com
  • {BLOCKED}balgrind.com
  • {BLOCKED}dsearch.com
  • {BLOCKED}gle.com.kh
  • {BLOCKED}gle.ge
  • {BLOCKED}gle.org
  • {BLOCKED}tato.eu
  • {BLOCKED}tisprogramas.org
  • {BLOCKED}tka.pl
  • {BLOCKED}enderszene.de
  • {BLOCKED}.pl
  • {BLOCKED}anglagu.com
  • {BLOCKED}nstiger.de
  • {BLOCKED}s.ru
  • {BLOCKED}shahrionline.ir
  • {BLOCKED}.com
  • {BLOCKED}vy.com
  • {BLOCKED}pserve.com
  • {BLOCKED}tz.com
  • {BLOCKED}eml.jp
  • {BLOCKED}24.hu
  • {BLOCKED}s4pay.com
  • {BLOCKED}evv.com
  • {BLOCKED}tiesindahous.com
  • {BLOCKED}se.gov
  • {BLOCKED}c.com.br
  • {BLOCKED}edomains.com
  • {BLOCKED}oron.com
  • {BLOCKED}antv.com
  • {BLOCKED}che.com.cn
  • {BLOCKED}.jp
  • {BLOCKED}ria.com
  • {BLOCKED}spy.com
  • {BLOCKED}l-blog.com
  • {BLOCKED}allery.com
  • {BLOCKED}a.tv
  • {BLOCKED}okup.com
  • {BLOCKED}obiliare.it
  • {BLOCKED}oral.jp
  • {BLOCKED}ressrd.jp
  • {BLOCKED}iastudychannel.com
  • {BLOCKED}oplease.com
  • {BLOCKED}orme.com
  • {BLOCKED}otop.jp
  • {BLOCKED}uisitr.com
  • {BLOCKED}one-dev.org
  • {BLOCKED}onedevsdk.com
  • {BLOCKED}osinteractive.com
  • {BLOCKED}njava.net
  • {BLOCKED}ub.net
  • {BLOCKED}edu
  • {BLOCKED}b.com
  • {BLOCKED}n.com
  • {BLOCKED}annews.com
  • {BLOCKED}dan.net
  • {BLOCKED}wnloader.org
  • {BLOCKED}berman.com
  • {BLOCKED}ns.com
  • {BLOCKED}mlaos.de
  • {BLOCKED}form.com
  • {BLOCKED}rnaldugeek.com
  • {BLOCKED}erymobile.com
  • {BLOCKED}nline.com
  • {BLOCKED}.net
  • {BLOCKED}23.cn
  • {BLOCKED}tate.edu
  • {BLOCKED}an.cn
  • {BLOCKED}serpermanente.org
  • {BLOCKED}maloop.com
  • {BLOCKED}server.com
  • {BLOCKED}.co.kr
  • {BLOCKED}rockwell.com
  • {BLOCKED}chainserver.net
  • {BLOCKED}unzhan.com
  • {BLOCKED}eloco.com.br
  • {BLOCKED}ami.jp
  • {BLOCKED}esi.at
  • {BLOCKED}ipan.cn
  • {BLOCKED}aso.com
  • {BLOCKED}kapivithuru.info
  • {BLOCKED}rosorium.ru
  • {BLOCKED}kshit.com
  • {BLOCKED}e365.com
  • {BLOCKED}escience.com
  • {BLOCKED}tfy.com
  • {BLOCKED}bimbo.com
  • {BLOCKED}-forums.com
  • {BLOCKED}amenoire.com
  • {BLOCKED}icjack.com
  • {BLOCKED}lorama.fr
  • {BLOCKED}nlink.ru
  • {BLOCKED}eshop.jp
  • {BLOCKED}warebytes.org
  • {BLOCKED}ager-magazin.de
  • {BLOCKED}y.cz
  • {BLOCKED}candangel.com
  • {BLOCKED}kettaiwan.com.tw
  • {BLOCKED}tercard.com
  • {BLOCKED}tercard.com.au
  • {BLOCKED}k.jp
  • {BLOCKED}aindex.ru
  • {BLOCKED}shij.net
  • {BLOCKED}higan.gov
  • {BLOCKED}phase.com
  • {BLOCKED}dbodyonline.com
  • {BLOCKED}ter-wong.de
  • {BLOCKED}traderumors.com
  • {BLOCKED}ame.fr
  • {BLOCKED}leadsystempro.com
  • {BLOCKED}.com
  • {BLOCKED}pi.net
  • {BLOCKED}ile-review.com
  • {BLOCKED}ilecashempires.com
  • {BLOCKED}ilejmp.com
  • {BLOCKED}ileread.com
  • {BLOCKED}ilism.org
  • {BLOCKED}myi.com
  • {BLOCKED}o.cc
  • {BLOCKED}eysavingmom.com
  • {BLOCKED}.com
  • {BLOCKED}illa.jp
  • {BLOCKED}zi.biz
  • {BLOCKED}labs.org
  • {BLOCKED}lima.com
  • {BLOCKED}b.co.za
  • {BLOCKED}b.com
  • {BLOCKED}ot.com
  • {BLOCKED}eviewsnow.net
  • {BLOCKED}hopping.com.au
  • {BLOCKED}oju.com
  • {BLOCKED}oys.de
  • {BLOCKED}ed.com
  • {BLOCKED}acast.com
  • {BLOCKED}o.com
  • {BLOCKED}keiba.com
  • {BLOCKED}tavisen.no
  • {BLOCKED}look.com
  • {BLOCKED}sday.com
  • {BLOCKED}wpthemes.com
  • {BLOCKED}onrumors.com
  • {BLOCKED}t.ir
  • {BLOCKED}spor.net
  • {BLOCKED}.ny.us
  • {BLOCKED}ee.com
  • {BLOCKED}.ne.jp
  • {BLOCKED}.com.ar
  • {BLOCKED}pic.com
  • {BLOCKED}nx.org
  • {BLOCKED}imizepress.com
  • {BLOCKED}imusid.com
  • {BLOCKED}ir.com
  • {BLOCKED}.edu
  • {BLOCKED}daily.com
  • {BLOCKED}st-france.fr
  • {BLOCKED}ac.uk
  • {BLOCKED}ktpub.com
  • {BLOCKED}emodo.com
  • {BLOCKED}salive.com
  • {BLOCKED}moon.net
  • {BLOCKED}talk.com
  • {BLOCKED}theranetwork.com
  • {BLOCKED}entsconnect.com
  • {BLOCKED}typoker.it
  • {BLOCKED}sion.ru
  • {BLOCKED}dotcom.com
  • {BLOCKED}pal.it
  • {BLOCKED}ames.de
  • {BLOCKED}npact.com
  • {BLOCKED}ools.com
  • {BLOCKED}sonal.com.ar
  • {BLOCKED}freaks.com
  • {BLOCKED}lsbury.com
  • {BLOCKED}goat.com
  • {BLOCKED}grush.com
  • {BLOCKED}sci.com
  • {BLOCKED}notube.com
  • {BLOCKED}sche.com
  • {BLOCKED}talnet.cl
  • {BLOCKED}arenok.ru
  • {BLOCKED}v.tv
  • {BLOCKED}isroboter.de
  • {BLOCKED}miumpass.com
  • {BLOCKED}sonplanet.com
  • {BLOCKED}xmoinscher.com
  • {BLOCKED}pertyguru.com.sg
  • {BLOCKED}sieben.de
  • {BLOCKED}.com
  • {BLOCKED}articles.com
  • {BLOCKED}m.com
  • {BLOCKED}nyan.biz
  • {BLOCKED}.gov.au
  • {BLOCKED}14.com
  • {BLOCKED}ness.com
  • {BLOCKED}ne.com
  • {BLOCKED}ota.ru
  • {BLOCKED}kspacecloud.com
  • {BLOCKED}id4all.org
  • {BLOCKED}eyourmusic.com
  • {BLOCKED}file.com
  • {BLOCKED}.co.uk
  • {BLOCKED}lage.com
  • {BLOCKED}ord.com.mx
  • {BLOCKED}hat.com
  • {BLOCKED}inery29.com
  • {BLOCKED}fe.es
  • {BLOCKED}se.com
  • {BLOCKED}ell-rights-weekly.com
  • {BLOCKED}identadvisor.net
  • {BLOCKED}olvermaps.com
  • {BLOCKED}psody.com
  • {BLOCKED}.ua
  • {BLOCKED}n.ru
  • {BLOCKED}oxchange.com
  • {BLOCKED}now.com
  • {BLOCKED}f.be
  • {BLOCKED}r.ru
  • {BLOCKED}czpospolita.pl
  • {BLOCKED}vn.com
  • {BLOCKED}eway.com
  • {BLOCKED}amnews.org
  • {BLOCKED}.gob.mx
  • {BLOCKED}ellitedirect.com
  • {BLOCKED}yac.com
  • {BLOCKED}4.com
  • {BLOCKED}per.eu
  • {BLOCKED}rch.com
  • {BLOCKED}ye.com
  • {BLOCKED}tenreport.de
  • {BLOCKED}uke.com
  • {BLOCKED}vicemagic.com
  • {BLOCKED}hgodin.typepad.com
  • {BLOCKED}lunch.com
  • {BLOCKED}bdkosh.com
  • {BLOCKED}renxs.com
  • {BLOCKED}ringcentre.net
  • {BLOCKED}pserve.jp
  • {BLOCKED}angtv.net
  • {BLOCKED}edu
  • {BLOCKED}a.com.hk
  • {BLOCKED}piec.pl
  • {BLOCKED}.de
  • {BLOCKED}rtsource.com
  • {BLOCKED}vongesternnacht.de
  • {BLOCKED}ialmediatoday.com
  • {BLOCKED}ialoomph.com
  • {BLOCKED}tonic.com.br
  • {BLOCKED}tportal.com
  • {BLOCKED}a.vn
  • {BLOCKED}rcle.com
  • {BLOCKED}x.com
  • {BLOCKED}ftung-warentest.de
  • {BLOCKED}scribe.wordpress.com
  • {BLOCKED}aneseonline.com
  • {BLOCKED}mify.com
  • {BLOCKED}erdownloads.com.br
  • {BLOCKED}ergoodmovies.com
  • {BLOCKED}lif.net
  • {BLOCKED}rovski.com
  • {BLOCKED}acor.com
  • {BLOCKED}setu.com
  • {BLOCKED}uz.co.il
  • {BLOCKED}te.com.au
  • {BLOCKED}mbeachbody.com
  • {BLOCKED}sernet.com
  • {BLOCKED}nnick.com
  • {BLOCKED}ekom.com
  • {BLOCKED}elistas.net
  • {BLOCKED}tsrv.com
  • {BLOCKED}bump.com
  • {BLOCKED}frisky.com
  • {BLOCKED}marker.com
  • {BLOCKED}me-junkie.com
  • {BLOCKED}nest.com
  • {BLOCKED}news.com.pk
  • {BLOCKED}ync.com
  • {BLOCKED}sav.com
  • {BLOCKED}you.com
  • {BLOCKED}fany.com
  • {BLOCKED}ychat.com
  • {BLOCKED}b.com
  • {BLOCKED}adserv.com
  • {BLOCKED}.com
  • {BLOCKED}yotosho.info
  • {BLOCKED}pda.com
  • {BLOCKED}dledo.com
  • {BLOCKED}allynsfw.com
  • {BLOCKED}alping.com
  • {BLOCKED}cn
  • {BLOCKED}decarview.com
  • {BLOCKED}fficjunky.net
  • {BLOCKED}vian.ae
  • {BLOCKED}vian.jp
  • {BLOCKED}vian.ru
  • {BLOCKED}berr.com
  • {BLOCKED}-ma-ktiko.blogspot.com
  • {BLOCKED}einternet.co.th
  • {BLOCKED}etwit.com
  • {BLOCKED}te.jp
  • {BLOCKED}w.com
  • {BLOCKED}e2011.com
  • {BLOCKED}ewolf.com
  • {BLOCKED}u.ru
  • {BLOCKED}.ca
  • {BLOCKED}ranchise.com.tw
  • {BLOCKED}gc.org
  • {BLOCKED}ourts.gov
  • {BLOCKED}gov
  • {BLOCKED}ue-domain.com
  • {BLOCKED}uecommerce.com
  • {BLOCKED}.com
  • {BLOCKED}michelin.fr
  • {BLOCKED}tomp3.com
  • {BLOCKED}pers.jp
  • {BLOCKED}edu
  • {BLOCKED}.vn
  • {BLOCKED}wak.com
  • {BLOCKED}fangdata.com.cn
  • {BLOCKED}chtower.com
  • {BLOCKED}.de
  • {BLOCKED}opedia.com
  • {BLOCKED}sitetonight.com
  • {BLOCKED}wiki.de
  • {BLOCKED}kamp.nl
  • {BLOCKED}kedpictures.com
  • {BLOCKED}yun.org
  • {BLOCKED}ldadult-videos.info
  • {BLOCKED}hao.com
  • {BLOCKED}.net.ru
  • {BLOCKED}hosting.com
  • {BLOCKED}all.nl
  • {BLOCKED}2.co.il
  • {BLOCKED}izhu.com
  • {BLOCKED}gou.com
  • {BLOCKED}saytoo.com
  • {BLOCKED}g.com
  • {BLOCKED}o10.net
  • {BLOCKED}g.es
  • {BLOCKED}sb.ru
  • {BLOCKED}2.cn
  • {BLOCKED}a.com.cn
  • {BLOCKED}a.hr
  • {BLOCKED}u.net
  • {BLOCKED}x.com

  SOLUTION

Minimum Scan Engine: 9.200
VSAPI OPR PATTERN File: 5.883.00
VSAPI OPR PATTERN Date: 06 Mar 2009

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

Step 2

Scan your computer with your Trend Micro product to delete files detected as TROJ_AGENT.DMP. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.