Analysis by: Christopher Daniel So

ALIASES:

Trojan:WinNT/Derusbi.A (Microsoft)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This spyware may be dropped by other malware.

It requires its main component to successfully perform its intended routine.

  TECHNICAL DETAILS

File Size: 10,752 bytes
File Type: SYS
Memory Resident: Yes
Initial Samples Received Date: 26 Aug 2011

Arrival Details

This spyware may be dropped by the following malware:

  • TSPY_DERUSBI.A

Other Details

This spyware requires its main component to successfully perform its intended routine.

NOTES:
This malware has keylogging capabilities.

  SOLUTION

Minimum Scan Engine: 9.200
FIRST VSAPI PATTERN FILE: 8.380.11
FIRST VSAPI PATTERN DATE: 27 Aug 2011

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

Step 2

Remove the malware/grayware file that dropped/downloaded TSPY_DERUSBI.E

Step 3

Restart in Safe Mode

[ Learn More ]

Step 4

To delete the random service key this malware/grayware created:

  1. Scan your computer with your Trend Micro product and take note of the name of the malware/grayware/spyware detected.
  2. Open Registry Editor. To do this, click Start>Run, type regedit in the text box provided, then press Enter.
  3. Press CTRL+F.
  4. In the Find dialog box, type the file name of the malware detected earlier.
    (Note: Make sure that only the data checkbox is selected, then click Find Next.)
  5. find.

  6. Once found, in the right panel, check if the result is the following value-data pair:
    ImagePath = {malware/grayware path and file name}
  7. If yes, in the left panel, locate the service where the data is under.
  8. Right-click on the located service in the left panel and choose Delete.
  9. Repeat steps 2 to 6 until the Finished searching through the registry dialog box appears.
  10. Close Registry Editor.

Step 5

Restart in normal mode and scan your computer with your Trend Micro product for files detected as TSPY_DERUSBI.E. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.

Related Malware