Pages

Showing posts with label Remove Trojans. Show all posts
Showing posts with label Remove Trojans. Show all posts

Friday, December 4, 2009

Trojan.Vb.AQT - Malware Type

Name alias Trojan.Win32.VB.aqt, Trojan.Recycle, W32.Fakerecy. Presence of this malware may be indicated by :
* a "Recycled" folder on each drive, which has the icon of the Recycle Bin

* presence of a file "autorun.inf" in the drive root, containing:
[autorun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0)

Upon execution malware creates on all fixed and removable drives:
[DRIVE]:\autorun.inf
[DRIVE]:\Recycled\desktop.ini
[DRIVE]:\Recycled\INFO2,
, which are used to execute the malware when the drive is accessed.

Tuesday, November 24, 2009

Win32:Banker - Trojan horse

Win32:Banker is a family of Trojans capable of monitoring user activity and stealing private information. Win32:Banker monitors user’s internet access. If certain websites (banking, payment system) are visited, Win32:Banker will log user’s activity. Win32:Banker will than send all the stolen details to the attacker.

Description

Win32:Banker is a family of Trojans capable of stealing private information such as account numbers, passwords and banking credentials. Many variants can wait in the background and monitor user's internet activity. A logging procedure starts when a certain website is accessed, or if the address of an accessed website contains certain words. Many variants may supplement legitimate banking or payment system websites to get user details.

Tuesday, November 3, 2009

Trojan.Lopad.K - Trojans Horse

The exact path to "Internet Explorer" browser is retrieved from registry. A check is made to see if the virus code is executing from within iexplorer's address space. If it is not then a new instance of iexplore.exe is infected with the viral code and executed. The code injected into iexplorer does the following: If the command line arguments does not include the string "923CCB1F" then a message box with title "Bad Elmo" and text "

You must install this software as part of the parent program. Press OK to exit." appears before exiting. If the command line argument "-newkEm" is present then it searches for a window of class "wwBYAwnd" and name "windWWAA" and sends it a message with id 0x533 then exits. If the window cannot be found the a file named "cdromruleclose.exe" is looked for in "%app_data%/play view/"and executed if it is found.