XP Entertainments - New AV Killer Trojan
XP Entertainments is probably a new variant of AvKiller trojan. As of now, only few AV's detect the malicious files.
The dropper - named
U.exe- drops following files/folders:
Registry entries created by the trojan:
Above-mentioned files contain references to following malicious websites (Do NOT visit these sites):
Last two links listed above redirect to
www.expertantivirus.com, which is the home of rogue software - ExpertAntivirus.
The trojan also adds an
Add/Remove Programsentry called
XP Entertainments, as shown in below screen shot:
Following screen shot shows that
SoUI.dllis injected into
Explorer.exe's address space:
This trojan does not allow various AntiVirus and Firewall software - like ZoneAlarm, Outpost, Microsoft AntiSpyware - to run properly. These programs crash as soon as they are started! Following screen shot shows the fate of ZoneAlarm firewall:
More information about this trojan can be found here.