BitDefender Antivirus
Go

Trojan.Obfuscated.LA

( Trojan.Win32.Obfuscated.ddk, TR/Obfuscated.ddk )
Spreading: low
Damage: low
Size: ~300 kB
Discovered: 2008 Jun 29

SYMPTOMS:

Symptoms are not easily visible for the user.

 

An instance of iexplorer.exe can be seen in Task Manager but only for a small period of time. This instance is not associated with any Internet Explorer windows.

TECHNICAL DESCRIPTION:

Trojan.Obfuscated.LA is a trojan downloader. It tries to download a file from 

hxxp://upd.host-domain-look.com/upd/check?version=0.1unk&fxp=9025<hex chars>

 

In order not to be detected by the firewall the program injects a part of it's code into a new process (iexplorer.exe) that it previously created. After the new malware is downloaded and put into execution Trojan.Obfuscated.LA exits.

 

Currently at the above URL address the program encounters an HTTP error (304 Not Modified).

This domain is associated with Trojan.Swizzor.

Removal instructions:

Please let BitDefender disinfect your files.

ANALYZED BY:

Andrei DAMIAN-FEKETE, virus researcher
Internet Security 2009
Protects 3PCs, 2 years
Only $89.95

Intelligence Report Archives