Virus Encyclopedia

Computer Virus Encyclopedia

Trojan-Spy.Win32.Dks.11.a

Alert Level : Medium
Discovered: Nov 03 2006
Tag:
Discoverer and Source: http://www.kaspersky.com/

Malware Behavior and Technical Description

This Trojan logs the user’s keystrokes. It is a Windows PE EXE file. It is written in Visual C . The file is 12,288 bytes in size. It is packed using ASPack. The unpacked file is approximately 40KB in size.

Installation

Once launched, the Trojan copies itself to the Windows system directory as "ks001.exe":

%System%\ks001.exe

It then registers itself in the system registry:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"systemks" = "ks001.exe"

This ensures that the Trojan will be launched each time Windows is booted on the victim machine.

The Trojan also creates a file called "ks001.dll" in the Windows system registry:

%System%\ks001.dll (8 704 bytes)

This file intercepts information entered via the keyboard and writes it to a log file.

The Trojan will also track its repeated launch by search for a window with the heading “systemks”.

Payload

The Trojan intercepts information entered via the keyboard, determines the language it has been entered in, tracks window operations and then writes this information to the following file:

%System%\ks000log.txt

Removal Trojan-Spy.Win32.Dks.11.a instructions:

  1. Delete the Trojan process.
  2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  3. Delete the files created by the Trojan: %System%\ks001.exe
    %System%\ks001.dll
    %System%\ks000log.txt
  4. Delete the following registry key value: [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "systemks" = "ks001.exe"
  5. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

Need help? Live computer support via remote at SupportSpace.Help with printer problems, windows, hardware, software, spyware removal and more. - Go Now!

Site Map
About Us