Bird_banner_small4
Trojan.Win32.Dulom.A
TSL ID TSL20120221-04
Severity Moderate
Description

Trojan.Win32.Dulom.A is a Trojan that targets the Windows platform. This malware installs Rootkits on a victim's system to disable security software "Gbuster". Furthermore, it sends system information to a remote attacker. It modifies the proxy configuration of web browsers to use a remote proxy auto-config file for the purpose of redirecting a user's online banking activities to a remote proxy host. This is used to steal a user's credentials. More over, it renames the "hosts" file on infected systems to disable local domain name resolution queries.

Affected Products
  • Microsoft Windows All Versions
File Hashes
MD5:
  • 81B4C1712AEE9F662445D09D6D071512
SHA1:
  • 8B7A66458CA9426EC24CAA607F1904110DB62679
Identifiers
Microsoft Malware Protection Center
DrWeb
  • TROJAN.NTROOTKIT.12901
ESET
  • WIN32/PROXYCHANGER.BK
References http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3aWinNT%2fDulom.A
Related Threats