Trojan-Spy.Win32.Dks.131.b

tag:Trojan   Spy  

The Trojan intercepts information entered via the keyboard, determines the language it has been entered in, tracks window operations and then writes this information to the following file:

%System%\kslog.dat

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Use Task Manager to terminate the Trojan process.
  2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  3. Delete the files created by the Trojan: %System%\SYSTEMKS.EXE
    %System%\systemks.dll
    %System%\sysadks.dll
    %System%\kslog.dat
  4. Delete the following registry key value:

    [HKCR\CLSID\

    This Trojan logs the user’s keystrokes. It is a Windows PE EXE file. It is written in Visual C . The file is 6,144 bytes in size. The file is packed using UPX. The unpacked file is approximately 31KB in size.

    Installation

    Once launched, the Trojan copies itself to the Windows system directory as "SYSTEMEKS.EXE":

    %System%\SYSTEMKS.EXE

    The Trojan also creates a file called "systemks.dll" in the Windows system registry:

    %System%\systemks.dll (11,776 bytes)

    This file intercepts information entered via the keyboard and writes it to a log file.

    The Trojan also creates a file called "sysadks.dll" in the Windows system registry:

    %System%\sysadks.dll (4,608 bytes)

    It registers this file in the system registry:

    [HKCR\CLSID\<randomly generated number>\InProcServer32]
    "default"="sysadks.dll"

    [HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "sysadks"="<randomly generated number>"

    The Trojan will also track its repeated launch by searching for a window titled “systemks”.

    Payload

©Virus-Encyclopedia.com All Rights Reserved.