This is yet another variant of one of the most prolific online-games password stealer malware "families" out-there.
Upon execution, the first thing it does is to create autorun.inf files pointing to copies of itself, making sure it can survive after a system restart. These files will be located on root of the local drives of an affected system.
It creates another copy of itself into the temporary folder of the current user, where it also drops a new dll file which implements all the functionality required for stealing passwords related to MapleStory, The Lord Of The Rings Online, Knight Online, Dekaron or other games.
Showing posts with label Autorun inf. Show all posts
Showing posts with label Autorun inf. Show all posts
Thursday, February 11, 2010
Friday, December 4, 2009
Autorun-Based Malware Tops BitDefender’s November Top Ten Threat Report
BUCHAREST, Romania – December 1, 2009 – BitDefender’s Top Ten Threat Report for November is topped by Trojan.AutorunInf.Gen. Trojan.AutorunInf.Gen, which came in second place on October’s list, is a generic family of malware abusing the Autorun feature in Microsoft Windows operating systems. By default, every removable storage device features an autorun.ini script that instructs the computer which file to execute when the medium is plugged in. Malware authors frequently tamper with the file to make it launch miscellaneous malicious applications.
Trojan.Clicker.CM moves down a spot, ranking second with nearly eight percent of total infections. Trojan.Clicker.CM is found on websites hosting illegal applications such as cracks, keygens and serial numbers for popular commercial software applications. Clicker.CM is used to force advertisements inside a user’s browser in order to boost advertisement revenue.
Trojan.Clicker.CM moves down a spot, ranking second with nearly eight percent of total infections. Trojan.Clicker.CM is found on websites hosting illegal applications such as cracks, keygens and serial numbers for popular commercial software applications. Clicker.CM is used to force advertisements inside a user’s browser in order to boost advertisement revenue.
Trojan.Vb.AQT - Malware Type
Name alias Trojan.Win32.VB.aqt, Trojan.Recycle, W32.Fakerecy. Presence of this malware may be indicated by :* a "Recycled" folder on each drive, which has the icon of the Recycle Bin
* presence of a file "autorun.inf" in the drive root, containing:
[autorun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0)
Upon execution malware creates on all fixed and removable drives:
[DRIVE]:\autorun.inf
[DRIVE]:\Recycled\desktop.ini
[DRIVE]:\Recycled\INFO2,
, which are used to execute the malware when the drive is accessed.
Labels:
Autorun inf,
Clean Malware,
Recycle Bin,
Remove Trojans
Thursday, November 19, 2009
Autorun.inf - Virus USB FLASH DRIVES
Autorun can pose a security threat, when the user does not expect or intend to run the software, such as in the case of some viruses, which take advantage of this feature to propagate, especially on USB FLASH DRIVES.For instance, an attacker with brief and casual physical access to a computer can surreptitiously insert a disc and cause software to run. Alternately, malicious software can be distributed with a disc that the user doesn't expect to contain software at all -- such as an audio compact disc. Even music CDs from well known name-brand labels have not always been safe.
Labels:
Autorun inf,
Malicious Programs,
USB Flash,
Virus On Disk
Subscribe to:
Posts (Atom)