Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Dasmin


Aliases:


Dasmin
Trojan.Win32.Dasmin, Trojan.Dasmin, TROJ_DASMIN, Poldo

Malware
Trojan
W32

Summary

Dasmin is a simple UPX-packed trojan that installs itself to Windows System folder as 2 separate files:

jdbgmrg.exe
 avirchk.exe

It should be noted that the trojan uses the 'jdbgmrg.exe' name that is quite close to the name of a common Windows component: 'jdbgmgr.exe' (Java Debug Manager). Also one Jdbgmgr hoax variant that was widespread in May 2002 had a typo - there was 'jdbgmrg.exe' file name mentioned there while it should have been 'jdbgmgr.exe' name. Also please note that the Dasmin trojan uses the same 'teddy bear' icon that looks exactly like the icon of JDBGMBR.EXE file.

The trojan creates autostartup keys for itself in the Registry. It also changes startup and search pages of Internet Explorer.



Disinfection & Removal

To disinfect a system from this trojan it's enough to kill trojan's tasks from Task Manager and to delete both trojan's files from a hard drive.



Technical Details


Variant:Dasmin.B (Trojan.Win32.Dasmin.B)

In the beginning of January 2003 there also appeared a new variant of Dasmin trojan. It also installed itself twice, but with different names:

REGCPM32.EXE
 IEXPRES.EXE

Like its ancestor, the trojan created startup keys for its files in System Registry.


Variant:Dasmin.C (Trojan.Win32.Virgilio, Trojan.Win32.Dasmin.C)

Almost at the same time with Dasmin.B there appeared a bit modified variant of the trojan. It installed itself to system once and with a different name:

MSFINDOSA.EXE

It also created a startup key for its file in the Registry.



Detection

F-Secure Anti-Virus detects all these trojan variants with the latest updates.



Technical Details: F-Secure Corporation; January 13th-20th, 2003



Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Disinfect your PC




F-Secure Anti-Virus will disinfect your PC and remove all harmful files