Pages

Showing posts with label Trojans Type. Show all posts
Showing posts with label Trojans Type. Show all posts

Tuesday, December 29, 2009

Trojan.TDss.ZR - complex malware

This is a complex malware that performs the following actions upon execution:

- creates a copy of itself in “%windir%\System32\spool\PRTPROCS\W32X86\” directory under the name “[random-number].tmp” and modifies the headers of the copy by setting the attributes related to a dll;
- creates a driver file in “%windir%\Temp\" directory under the name “[random-number].tmp”
- creates a copy of itself in “%Temp%” directory under the name “[random-number].tmp”
- Injects code in “spoolsv.exe” process in order to run with higher privileges, code which will load the dropped driver.
- The injected code will also communicate with different servers as: https://h4356***.cn, https://h9237***.cn, https://212.117.174.***, making the computer part of a botnet network and from now on it can download files, execute them and do many other malware related actions.

Tuesday, December 22, 2009

Trojan.PWS.Onlinegames.KDBI - Trojans Inject

In order to hide his actions, when is first run, the trojan will inject its code into the memory of Explorer.exe using low-level methods and a remote thread pointing to this zone will be started. This code (executed by Explorer) will be responsible to inject into all running processes a dll dropped by the trojan (%USERPROFILE%\Local Setings\Temp\cvasd0.dll).

The injected DLL contains two components. An online games password stealer (with the targets: KnightOnline, Metin2, AgeOfConan,TheLordOfTheRings,Maple...). Another embedded DLL (ANTIVM.dll) will try to disable some known security solutions usually by stopping the update services modules (Liveserv.exe, vsupdate.exe, Update.exe, AVP.exe, avgupd.exe).

Friday, December 4, 2009

Autorun-Based Malware Tops BitDefender’s November Top Ten Threat Report

BUCHAREST, Romania – December 1, 2009 – BitDefender’s Top Ten Threat Report for November is topped by Trojan.AutorunInf.Gen. Trojan.AutorunInf.Gen, which came in second place on October’s list, is a generic family of malware abusing the Autorun feature in Microsoft Windows operating systems. By default, every removable storage device features an autorun.ini script that instructs the computer which file to execute when the medium is plugged in. Malware authors frequently tamper with the file to make it launch miscellaneous malicious applications.

Trojan.Clicker.CM moves down a spot, ranking second with nearly eight percent of total infections. Trojan.Clicker.CM is found on websites hosting illegal applications such as cracks, keygens and serial numbers for popular commercial software applications. Clicker.CM is used to force advertisements inside a user’s browser in order to boost advertisement revenue.

Tuesday, November 24, 2009

Win32:Banker - Trojan horse

Win32:Banker is a family of Trojans capable of monitoring user activity and stealing private information. Win32:Banker monitors user’s internet access. If certain websites (banking, payment system) are visited, Win32:Banker will log user’s activity. Win32:Banker will than send all the stolen details to the attacker.

Description

Win32:Banker is a family of Trojans capable of stealing private information such as account numbers, passwords and banking credentials. Many variants can wait in the background and monitor user's internet activity. A logging procedure starts when a certain website is accessed, or if the address of an accessed website contains certain words. Many variants may supplement legitimate banking or payment system websites to get user details.

Monday, November 23, 2009

Trojan Vundo - Trojan Virus

Trojan Vundo is a extremely dangerous Trojan virus and you want to make sure your pc never gets it, and if your pc is infected with Trojan Vundo, this article will help you remove it quickly & easily.

Trojan Vundo was discovered on a friend of mines desktop after running the popular Windows Defender program, a free spyware and Vundo removal tool (it detected Trojan vundo, but wouldn't remove it). How the desktop got infected with this ungly virus I'm not sure, but I spent hours researching and looking for any information I could find about Trojan Vundo and ended up with nothing. Actually, there's tons and tons of useless articles and content out there on how to fix the issue, but none one of them worked for me and your probably in the same situation as well.!

Tuesday, November 3, 2009

Trojan.Lopad.K - Trojans Horse

The exact path to "Internet Explorer" browser is retrieved from registry. A check is made to see if the virus code is executing from within iexplorer's address space. If it is not then a new instance of iexplore.exe is infected with the viral code and executed. The code injected into iexplorer does the following: If the command line arguments does not include the string "923CCB1F" then a message box with title "Bad Elmo" and text "

You must install this software as part of the parent program. Press OK to exit." appears before exiting. If the command line argument "-newkEm" is present then it searches for a window of class "wwBYAwnd" and name "windWWAA" and sends it a message with id 0x533 then exits. If the window cannot be found the a file named "cdromruleclose.exe" is looked for in "%app_data%/play view/"and executed if it is found.

Sunday, November 1, 2009

Trojan.Clicker.CM - Trojans Horse

Display of popups containing advertises when accessing infected internet sites.

Spreading: very high
Damage: low
Size: about 4000 bytes
Discovered: 2007 Mar 07

In order to successfully display the pop-ups containing advertises, the trojan has functions to bypass the Norton Internet Security Pop-up Blocker. (Dan Lutas, virus researcher)