Trojan.Win32.Berok

Class Trojan
Platform Win32
Description

Technical Details

The Trojan installs a new desktop background. The Trojan itself is a Windows PE EXE file 45056 bytes in size.

Payload

The Trojan file contains a bmp file 40150 bytes in size.

When launched, the Trojan drops this file to the Windows root directory:

%WinDir%desktop.bmp

The desktop background will then be changed to the image contained in this file.

Removal instructions

  1. Delete the following files:
    • %WinDir%desktop.bmp;
    • the original Trojan file
  2. Perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus)