Malware Information

Malware nameTrojan.PSW.OnLin.aklo.2
TypeTrojan
Affected platformWin32
Media-Typeapplication/executable
MD5 checksum56F4E7F769904BCB7E7705570BF8C880
Static fileno
Filesize11,264 Bytes
Alias names
(also known as)
SophosMal/Generic-A
McAfeePWS-OnlineGames.bp
CA ETrustWin32/Treemz!generic
Side effects
  • Drops a malicious file
  • Registry modification
  • Steals information
PropagationNo own spreading routine

Description:

Files

It copies itself to the following location:
• %SYSDIR%\tmdkcok.exe



It deletes the initially executed copy of itself.



The following file is created:

– %SYSDIR%\tmdkco.dll Further investigation pointed out that this file is malware, too. Detected as: Trojan.PSW.OnLin.aklo.2

Registry

The following registry key is changed:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
New value:
• AppInit_DLLs = tmdkco.dll

Stealing

It tries to steal the following information:

– The password from the following program:
%chinese text%

File details

Programming language:
The malware program was written in MS Visual C++.


Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
• UPX