TROJ_FACKED.SM1
Mcafee : W32/Bamital.e; Microsoft : Trojan:Win32/Bamital.I
Windows 2000, XP, Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan uses common file icons to trick a user into thinking that the files are legitimate.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
It deletes itself after execution.
TECHNICAL DETAILS
Installation
This Trojan drops the following files:
- %System%\kb.dll - detected as TROJ_SHUTDWNR.DZ
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Its DLL component is injected to the following process(es):
- explorer.exe
It uses common file icons to trick a user into thinking that the files are legitimate.
Dropping Routine
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Other Details
This Trojan deletes itself after execution.