Spam trojan that actually downloads and runs AV software (!)

Spam trojan that actually downloads and runs AV software (!)

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Spam trojan that actually downloads and runs AV software (!) Virus Guy 10-21-2006
Posted by Virus Guy on October 21, 2006, 12:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
http://www.secureworks.com/analysis/spamthru/

"Like many viruses and trojans, SpamThru attempts to prevent
installed anti-virus software from downloading updates by
adding entries into the %sysdir%\drivers\etc\hosts file
pointing the AV update sites to the localhost address.

In the past, we've also seen malware which tries to uproot
other competing malware on an infected system by killing
its processes, removing its registry keys, or setting up
mutexes which fool the other malware into thinking it is
already running and then exiting at start.

SpamThru takes the game to a new level, actually using an
antivirus engine against potential rivals. At startup, SpamThru
requests and loads a DLL from the control server. This DLL in
turn downloads a pirated copy of Kaspersky AntiVirus for WinGate
from the control server into a concealed directory on the
infected system. It patches the license signature check in-memory
in the Kaspersky DLL in order to avoid having Kaspersky refuse
to run due to an invalid or expired license. Ten minutes after
the download of the DLL, it begins to scan the system for malware,
skipping files which it detects are part of its own installation.
Any other malware found on the system is then set up to be deleted
by Windows at the next reboot."

Similar ThreadsPosted
Virus Scanning during downloads August 14, 2005, 4:21 pm
trial KAV downloads inaccessable July 18, 2007, 8:27 pm
What antivirus runs with nav 2005 ????? August 4, 2005, 12:05 pm
anti( MBR) rootkit that runs on win 98? April 18, 2008, 8:57 am
Wanted: antivirus that runs on Win2000 March 1, 2008, 4:49 pm
Mac Hardware Successfully Runs Windows XP (NewsFactor) March 16, 2006, 7:35 pm
Trojan from using VNC Viewer Software March 30, 2007, 11:55 am
Anti Trojan Software For Home Network August 9, 2005, 9:31 pm
Re: Great resource site with anti-spyware/virus/trojan software and tweaks etc June 21, 2007, 12:25 pm
Rolex & ED-Drug spam, why can't Norton anti-spam get rid of them. September 23, 2005, 4:02 pm

The site map in XML format XML site map

Contact Us | Privacy Policy