Keylog-LMtry

This page shows details and results of our analysis on the malware Keylog-LMtry

Overview


Minimum DAT

5166 (2007-11-19)

Updated DAT

5166 (2007-11-19)

Minimum Engine

5.1.00

File Length

Complaint.scr (74240 bytes)

Description Added

2007-11-16

Description Modified

2007-11-20

Malware Proliferation

Characteristics

Symptoms

The infected system polls the remote php scripts occasionally to indicate its availability:

  • http://dc.dip.jp/[blocked]/setStatus.php
  • http://furystrikesback.com/[blocked]/setStatus.php

Method of Infection

Many of these mails are spammed by the author to entice people into opening them.

Removal

A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.

 

Variants