Home » Spyware Protection » Hijacked Browser Analysis » Re: HijackThisLog Analysis - Nkoffroth » 

mstaskss.exe

Troj/Lamedon-D is a downloader Trojan which tries to download files from a remote location to the Windows folder and run them.  The Trojan typically tries to download the following files to the Windows folder: secure.html securea.html secureb.html reg32.exe dl.exe dl.html dlm.exe dlm.html mstasks.exe mstaskss.exe sherlok2.exe kemuri32.exe mssys.exe.  The Trojan then executes: dl.exe, dlm.exe, mstasks.exe, mstaskss.exe, sherlok2.exe, kemuri32.exe and mssys.exe. The files secure.html, securea.html, secureb.html, dl.html, dlm.html and mstaskss.exe are harmless HTML files. dl.exe and dlm.exe are detected as Troj/lamedon-A. reg32.exe is detected as Troj/Lamedon-E and the file mstasks.exe is detected as Troj/Downldr-DE.


Mail this pageMail this page