Dasmin is a simple UPX-packed trojan that installs itself to Windows System folder as 2 separate files:
It should be noted that the trojan uses the 'jdbgmrg.exe' name that is quite close to the name of a common Windows component: 'jdbgmgr.exe' (Java Debug Manager). Also one Jdbgmgr hoax variant that was widespread in May 2002 had a typo - there was 'jdbgmrg.exe' file name mentioned there while it should have been 'jdbgmgr.exe' name. Also please note that the Dasmin trojan uses the same 'teddy bear' icon that looks exactly like the icon of JDBGMBR.EXE file.
The trojan creates autostartup keys for itself in the Registry. It also changes startup and search pages of Internet Explorer.
Disinfection & Removal
To disinfect a system from this trojan it's enough to kill trojan's tasks from Task Manager and to delete both trojan's files from a hard drive.
In the beginning of January 2003 there also appeared a new variant of Dasmin trojan. It also installed itself twice, but with different names:
Like its ancestor, the trojan created startup keys for its files in System Registry.
Variant:Dasmin.C (Trojan.Win32.Virgilio, Trojan.Win32.Dasmin.C)
Almost at the same time with Dasmin.B there appeared a bit modified variant of the trojan. It installed itself to system once and with a different name:
It also created a startup key for its file in the Registry.
F-Secure Anti-Virus detects all these trojan variants with the latest updates.
Technical Details: F-Secure Corporation; January 13th-20th, 2003