Additional Details
When a JAR file containing the trojan is executed it uses
Microsoft Internet Explorer VerifierBug vulnerability to get
full privileges by escaping the Java security, and execute its
code. Then the trojan downloads the winshow.dll into windows
directory (default C:\Windows) and registers it with regsvr32.
To remove Ouch.A from your system apply the fix to the Java VM
vulnerability and clear temporary Internet files cache
Further information about the vulnerability in the Microsoft Java VM,
including a fix, is available at:
http://www.microsoft.com/technet/security/bulletin/ms03-011.asp
Write-up:
Jarno Niemela, September 2nd, 2003;
Description Updated:
Jarno Niemela, January 12th, 2004;